テーマ:ブログ 貴組織のための正しいSOCモデルの選択(20) Reduction in Time to Detect Incidents付随事件を検出する時間の低減Integrated security event monitoring gives the security operations team better visibility and enables them to correlate patterns and surface suspicious activities. Effective detection and escalation of incidents, and close coordination between the individual teams within the organization improve response outcomes.統合された機密保持イベント監視は機密保持オペレーションチームにもっと良い可視性を与えて、そして彼らにパターンを関連づけて、怪しい活動を表面に出すことを可能にします。 効果的な探知と付随事件の段階的拡大と組織内の個々のチーム間の緊密な連携が反応結果を改善します。Centralization and Consolidation of Security Functions機密保持機能の中央集権化と統合Consolidating security functions in a SOC can provide cost-efficiencies, enable cost sharing and leverage economies of scale while maximizing the available expertise, skills and resources. The need for centralization can also be from a purely geographical perspective. When an organization operates in multiple locations, it may benefit from a centralized view of what is happening.SOCで機密保持機能を強固にすることは費用効率を提供して、コスト共用を可能にして、利用可能な専門知識、技能と資源を最大にする一方で、規模の経済をてこ入れすることができます。 中央集権化のための要求は同じく純粋に地理的な観点からでもあり得ます。 組織が複数の場所で営業するとき、起きていることの集中型観点から利益を得るかもしれません。Regulatory Compliance規制準拠A SOC is often the operational model of choice for large and some midsize enterprises to meet regulatory requirements mandating security event monitoring, vulnerability management and incident response functions. Furthermore, a SOC can improve compliance auditing and reporting across the organization; however, it is not typically built for compliance-only use cases.SOCはしばしば、大企業やいくらか中規模の企業が機密保持イベント監視、脆弱性管理と付随事件対応機能を義務づけて規制上の要求事項を満たすための選択運用モデルです。 さらに、SOCは、組織にまたがり、法令準拠監視や報告を改善することができます;しかしながら、それは典型的に単に法令準拠のユースケースのために構築はされません。==================================================