惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
J
Java Code Geeks
雷峰网
雷峰网
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
云风的 BLOG
云风的 BLOG
V
Visual Studio Blog
V
Vulnerabilities – Threatpost
S
Securelist
The Hacker News
The Hacker News
The Register - Security
The Register - Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Help Net Security
Help Net Security
G
Google Developers Blog
Hugging Face - Blog
Hugging Face - Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
M
MIT News - Artificial intelligence
AI
AI
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Schneier on Security
Schneier on Security
N
Netflix TechBlog - Medium
T
The Blog of Author Tim Ferriss
Google DeepMind News
Google DeepMind News
Hacker News - Newest:
Hacker News - Newest: "LLM"
H
Hacker News: Front Page
博客园 - 司徒正美
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
B
Blog
Microsoft Azure Blog
Microsoft Azure Blog
大猫的无限游戏
大猫的无限游戏
Security Latest
Security Latest
Engineering at Meta
Engineering at Meta
N
News and Events Feed by Topic
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
酷 壳 – CoolShell
酷 壳 – CoolShell
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
T
Threat Research - Cisco Blogs
U
Unit 42
V
V2EX
V2EX - 技术
V2EX - 技术
L
LINUX DO - 最新话题
aimingoo的专栏
aimingoo的专栏
Microsoft Security Blog
Microsoft Security Blog
Recorded Future
Recorded Future
P
Privacy & Cybersecurity Law Blog
美团技术团队
小众软件
小众软件
F
Fortinet All Blogs

Insights

ChatGPT is the ultimate phishing tool, so why aren’t companies boosting security budgets? Absolute, Trellix team up to enhance endpoint security Top 3 trade-offs commonly encountered in identity security circles The linkages between privileged access management and zero trust Cyber security in the Pacific: How island nations are building their online defences State sanctioned (cyber) violence, Australia’s next security threat Drawing a line in the sand for cyber conflict Automation: The future of the combat vehicle? Billion-dollar cyber boost: A cash cow for defence SMEs?
Overcoming the challenges faced by a modern-day SOC
Michael Bovalino · 2022-06-27 · via Insights

Within most organisations, the volume of security alerts is constantly increasing. Every day, more alerts are being generated and the need to assess them is placing an ever-growing burden on the SOC team.

The challenge becomes one of finding ways to differentiate between low-level alerts that do not require follow up and more serious alerts that need closer inspection and action. If the SOC team is buried in large volumes of low-level alerts, it risks missing those that actually pose a real threat to the IT infrastructure.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

The SOC team is also under pressure because of the growing number of different tools they need to juggle. Everything from endpoint monitoring and SIEM tools to log management and behavioural analytics packages require constant attention.

Enlarged attack surface

Additional challenges are posed for the SOC by the fact that attack surfaces have increased. Rather than all IT resources being housed in an on-premise data centre and protected behind a firewall, components can now be located across multiple cloud platforms and remote-working locations.

This results in additional risks that must be managed, and SOC teams must find ways to ensure they have visibility of all resources at all times. They also need to ensure that all components within this distributed infrastructure are compliant and have the most up-to-date security measures in place.

Teams also need to remember that they are still responsible for the security of assets placed on a cloud platform. The cloud provider is responsible for their platform, but not for the security of applications that run on it.

Strategy and process

SOC teams also face challenges when it comes to the strategies and processes on which they rely on. In many cases there can be a lack of focus, or a sense of which activities should be given priority.

Some may also not be keeping abreast of the new threats and risks faced by their organisation. This could result in a new technique being used by cyber criminals going unnoticed until an attack is actually underway.

The processes within an SOC may have not been reviewed on a regular basis. With the threat landscape constantly changing, so too must the methods being used to identify and neutralise those threats.

Many SOCs are also not taking advantage of the increasing number of automation tools now on the market. These tools can free security analysts from mundane tasks and free them to focus on more value-adding activities.

Overcoming challenges

Dealing with these challenges requires a number of steps to be taken. The first is a review of the use cases currently being deployed within the SOC.

It is unrealistic to think that use cases developed some years ago will still be able to cope with new and emerging cyber threats. For this reason, each should be reviewed on a regular basis and tested to ensure that it is still relevant.

Undertaking this process will help to reduce the number of false positives that are being triggered, lowering the workload for the SOC team. It will also lessen the likelihood that significant events will go unnoticed.

Unified threat management

Another step that can be undertaken within an SOC is to adopt a unified threat management strategy. Rather than having a large number of specialised tools that must each be monitored separately, increasing numbers of SOCs are deploying new solutions that can handle multiple tasks.

These tools can collect security data from multiple locations across the IT infrastructure, assess whether observed activity is normal, and flag any seemingly abnormal activity for closer inspection by a team member.

Beyond the SOC

To ensure effective protection against cyber threats, it’s important for everyone within an organisation to be aware that responsibility for security extends well beyond the SOC. All staff must understand the role they play in reducing the change of a successful attack.

These responsibilities range from being aware of the dangers of phishing attacks to taking care when connecting to centralised resources from a remote location. Staff should also be encouraged to report any incidents that appear to be unauthorised or unusual.

By ensuring all staff are aware of the importance of IT security and their role in maintaining it, organisations can be best placed to withstand threats both now and in the future.

Michael Bovalino is the ANZ country manager at LogRhythm.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.