首页> 外文会议>International Conference on Intelligent and Innovative Computing Applications >Integrating a Security Operations Centre with an Organization’s Existing Procedures, Policies and Information Technology Systems
【24h】

Integrating a Security Operations Centre with an Organization’s Existing Procedures, Policies and Information Technology Systems

机译:将安全运营中心与组织的现有程序,策略和信息技术系统集成

获取原文

摘要

A Cybersecurity Operation Centre (SOC) is a centralized hub for network event monitoring and incident response. SOCs are critical when determining an organization's cybersecurity posture because they can be used to detect, analyze and report on various malicious activities. For most organizations, a SOC is not part of the initial design and implementation of the Information Technology (IT) environment but rather an afterthought. As a result, it is not natively a plug and play component therefore there are integration challenges when a SOC is introduced into an organization. A SOC is an independent hub that needs to be integrated with existing procedures, policies and IT systems of an organization such as the service desk, ticket logging system, reporting, etc. This paper discussed the challenges of integrating a newly developed SOC to an organization's existing IT environment. Firstly, the paper begins by looking at what data sources should be incorporated into the Security Information and Event Management (SIEM) such as which host machines, servers, network end points, software, applications, webservers, etc. for security posture monitoring. That is, which systems need to be monitored first and the order by which the rest of the systems follow. Secondly the paper also describes how to integrate the organization's ticket logging system with the SOC SIEM. That is how the cybersecurity related incidents should be logged by both analysts and nontechnical employees of an organization. Also, the priority matrix for incident types and notifications of incidents. Thirdly the paper looks at how to communicate awareness campaigns from the SOC and also how to report on incidents that are found inside the SOC. Lastly the paper looks at how to show value for the large investments that are poured into designing, building and running an SOC.
机译:网络安全运营中心(SOC)是用于网络事件监视和事件响应的集中式中心。 SOC在确定组织的网络安全状况时至关重要,因为SOC可用于检测,分析和报告各种恶意活动。对于大多数组织而言,SOC并不是信息技术(IT)环境的初始设计和实施的一部分,而是事后的想法。结果,它本身不是即插即用的组件,因此在将SOC引入组织时会面临集成方面的挑战。 SOC是一个独立的枢纽,需要与组织的现有流程,策略和IT系统(例如服务台,票务记录系统,报告等)集成。本文讨论了将新开发的SOC集成到组织的SOC中所面临的挑战现有的IT环境。首先,本文开始研究应将哪些数据源合并到安全信息和事件管理(SIEM)中,例如哪些主机,服务器,网络端点,软件,应用程序,Web服务器等,用于安全状态监视。也就是说,首先需要监视哪些系统以及其余系统的监视顺序。其次,本文还描述了如何将组织的工单记录系统与SOC SIEM集成。这就是组织的分析师和非技术人员应如何记录与网络安全相关的事件。另外,是事件类型和事件通知的优先级矩阵。第三,本文着眼于如何传达来自SOC的意识运动,以及如何报告SOC内部发现的事件。最后,本文着眼于如何为投入到设计,构建和运行SOC的大型投资展示价值。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号