This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Which extensions should be done to the technology domain?

Thank you for the input. I agree that TI and vulnerability management are relevant to most SOCs. This is why they are part of the services domain, and the capabilities mentioned there also include the technical side of these solutions. TI as a separate domain is an interesting thought, because it is not 'self-contained' but has a broad function within the SOC and even outside the SOC in the organisation. Within the SOC-CMM, it is 'just' a service. Note that this does not make it less important. In my opinion, the importance does not come from its place in the SOC-CMM, but its place in the organisation. I will have a look on how well the SOC-CMM covers the broader function of TI within the organisation. (will go on the todo list)

EDR is not yet in place in the technology domain. I have plans to transform the technology domain into the visibility triad, augmented with SOAR. The visibility triad will include EDR as well, but I'm also looking into XDR at the moment.


Messages In This Thread
RE: Which extensions should be done to the technology domain? - by robvanos - 02-16-2022, 09:10 AM

Forum Jump:

Users browsing this thread: 1 Guest(s)