テーマ:ブログ 貴組織のための正しいSOCモデルの選択(14) Hybrid SOCハイブリッドSOCA hybrid SOC consists of some dedicated staff and infrastructure, augmented by additional team members from other internal business units and/or external service providers. One or more dedicated people are responsible for ongoing SOC operations, involving semidedicated team members and third parties as required.ハイブリッドSOCは、他の内部ビジネスユニットそして/あるいは外部サービスプロバイダからの追加チームメンバーによって拡張されて、若干の専任スタッフとインフラストラクチャーから成り立ちます。 必要に応じ、準専任チームメンバーと第三者を巻き込んで、1人以上の専任の人々が進行中の SOC オペレーションに責任があります。If an organization cannot operate 24/7, the resulting gap can be covered by a number of providers, resulting in a hybrid SOC model. These providers might include an MSSP (see Magic Quadrant for Managed Security Services, Worldwide”), a managed detection and response (MDR) service provider (see Market Guide for Managed Detection and Response Services”), a co-managed SIEM service provider, or sometimes a special security consulting provider or system integrator (SI).もし組織が1日24時間・週7日を運用することができないなら、結果として生じている切目は、結果としてハイブリッドSOC モデルとなる、多くのプロバイダによってカバーすることが可能です。 これらのプロバイダは MSSP(「世界中の管理された機密保持サービスのためのマジック四区分」参照)や、管理された検知と反応(MDR)サービス プロバイダー(「管理された探知と反応サービスのためのマーケット案内」参照)や、共同管理SIEM サービス プロバイダー、あるいは時々特別機密保持相談プロバイダーあるいはシステムインテグレーター(SI)を含みます。Only large enterprises are able to afford and commit to dedicated, self-contained SOCs. But, many organizations desire some form of internal security operations capability (although limited), even if they are using an external provider for a majority of their security monitoring needs.ただ大企業だけが専任の、自制的なSOCを持つ余裕があって、委ねることが可能です。 けれども、(制限はあるが)、多くの組織は、たとえ彼らが外部のプロバイダー大多数の彼らの機密保持監視の必要のために使っているとしても何らかの形の内部機密保持運用能力を強く望んでいます。==================================================