貴組織のための正しいSOCモデルの選択(16) There are, however, both advantages and disadvantages to doing this. For example, fusing incident response as part of the SOC will allow tighter integration between detection and response, and is an essential factor needed for security operational success (see“Prepare for the Inevitable With an Effective Security Incident Response Plan”). On the other end of the spectrum, it can create separation of duties conflicts and/or pull the security event monitoring resources away from the incident response tasks, thus affecting the effectiveness of the monitoring during an actual incident (see“How to Plan, Design, Operate and Evolve a SOC”).しかしながら、これをすることに、利点と不利両方があります。 例えば、 SOC の一部として付随事件対応を融合することは検知と反応の間にもっとしっかりした統合を可能にするでしょう、そして機密保持運用成功(「有効な機密保持付随事件対応計画で避けられないもののために準備」参照)に必要な不可欠な要素です。スペクトラムの他方の端で、それは職掌分散対立を引き起こすことや、そして/あるいは、それで、実際の付随事件の間に監視の有効性に影響を及ぼして(「SOCを計画し、設計し、操作して、進化させる方法」参照)、機密保持イベント監視リソースを付随事件対応タスクから遠ざけることができます。Figure 1.Organization Chart for a Large SOCSource: Gartner (September 2018)図1.大規模SOCのため組織図出典:ガートナー(2018年9月)=====================================================================