テーマ:ブログ 貴組織のための正しいSOCモデルの選択(26) To ensure your organization has the most appropriate security metrics, start with the end in mind and first develop tightly defined goals and metrics the SOC needs to deliver against that align to the business outcomes. Also, make sure that a sustainable budget is secured for the first two to three years of the SOC operation. It will often take this amount of time for people, processes and technology to be integrated into your organization and delivering at a reasonable level of proficiency.あなたの組織が最も適切な機密保持メトリックスを持っていることを保証するために、終わりを念頭に始めて、そして最初にしっかり明確なゴールとビジネス結果に連携する SOC が実現する必要があるメトリックスを開発してください。 同じく、持続可能な予算が SOC運用の最初の2から3年間確保されることを確認してください。 それはしばしば合理的レベルの熟達に実現して、あなたの組織に統合される人々や、プロセスと技術のためにこのくらいの時間がかかるでしょう。IT Infrastructure VisibilityITインフラの可視性Since its inception, a SIEM tool has generally been the center of an enterprise SOC. Depending on the size of the organization, a modern SOC may not be built entirely on top of its SIEM tool. A small SOC, for example, could manage and succeed with just a SIEM solution implemented. However, as the size and complexity of the IT environment increase, additional tools — especially those providing further visibility — become essential for the SOC to operate effectively. Organizations that have a large SOC, a unique IT infrastructure and a complex set of use cases on the other hand, are encouraged to expand their SOC arsenal beyond just the SIEM tool. They can accomplish this by investing in other advanced threat detection solutions and/or workflow and automation tools. Integrating these additional tools into the SOC can help increase threat detection accuracy as well as speed up existing SOC operations.その発端から、 SIEM ツールは、一般に(今まで)企業SOCのセンターでした。 組織の規模によって、近代的なSOCは、その SIEM ツール上に完全に築かれないかもしれません。 例えば、小さいSOCが管理して、そして実装されるSIEM ソリューションを引き継ぐ可能性もあります。 しかしながら、 IT 状況の大きさと複雑度が増加するにつれて、追加の手段(特にさらなる可視性を提供しているもの)は、効果的に稼働するためにSOC にとって必須になります。 他方大規模SOCや、ユニークな IT インフラスとユースケースの複雑なセットを持っている組織は、単なる SIEM ツールを越えて(彼・それ)らの SOC 兵器庫を拡大するよう奨励されます。 彼らは、他の先進的脅威検知解決そして/あるいはワークフローと自動化ツールに投資することによって、これを達成することができます。 これらの追加のツールを SOC に統合することは、既存の SOC 運用を速めることと同様、脅威検知の正確さを増やす助けとなる可能性があります。==================================================