02-20-2019, 02:09 PM
The SOC-CMM survey has indicated that some users are looking for additions to the SOC-CMM technology domain. Which additions should be considered?
Keep calm and share knowledge
Which extensions should be done to the technology domain?
|
02-20-2019, 02:09 PM
The SOC-CMM survey has indicated that some users are looking for additions to the SOC-CMM technology domain. Which additions should be considered?
Keep calm and share knowledge
06-02-2020, 07:36 PM
Endpoint Detection and response ?
02-08-2022, 12:01 PM
Hi Rob,
There are a number of technologies that I think would be useful to be included in this document, below are the key ones: EDR: This is being used more and more by SOCs for monitoring endpoints in piticular. Threat Intelligence (TI) platforms: TI is critical to all mature SOCs. TIPs in vendorland have become a massive thing, there is also a wide range of open source tools covering this space. I personally would include TI as its own domain, but I would love at least see it included as a tool on the next SOC-CMM. Vulnerability Management: again something that is becoming more prevalent in SOCs, at least as log source, but often being managed from the SOC as well. Cheers TJP
02-16-2022, 09:10 AM
Hi TJP,
Thank you for the input. I agree that TI and vulnerability management are relevant to most SOCs. This is why they are part of the services domain, and the capabilities mentioned there also include the technical side of these solutions. TI as a separate domain is an interesting thought, because it is not 'self-contained' but has a broad function within the SOC and even outside the SOC in the organisation. Within the SOC-CMM, it is 'just' a service. Note that this does not make it less important. In my opinion, the importance does not come from its place in the SOC-CMM, but its place in the organisation. I will have a look on how well the SOC-CMM covers the broader function of TI within the organisation. (will go on the todo list) EDR is not yet in place in the technology domain. I have plans to transform the technology domain into the visibility triad, augmented with SOAR. The visibility triad will include EDR as well, but I'm also looking into XDR at the moment. Regards, Rob. |
« Next Oldest | Next Newest »
|