【24h】

Rethinking Security Operations Centre Onboarding

机译:重新思考安全运营中心

获取原文

摘要

Cyber security operations centres (CSOC) are an essential business differentiator for digital services. They perform the challenging tasks of monitoring digital services such that when an attack is detected against the monitored digital services, they can respond swiftly ensuring cyber incidents are appropriately managed through to recovery. To monitor business services, the CSOC must first on-board those business services onto their security monitoring and incident management platforms. This process of onboarding business services to CSOC’s security monitoring and incident management platform is described as Cybersecurity Onboarding. Cybersecurity Onboarding is a specialist technical process of setting up and configuring digital business services to generate appropriate interaction telemetry, such as events, logs, messages, metrics, and observables. These telemetric indicators when correlated and analysed reveal whether the business service may have been compromised or not.In this paper we rethink the approach to onboarding services to CSOC. A new approach of cybersecurity onboarding that is cyclic, simpler, quicker, efficient, and cost optimised by leveraging cloud-native and cloud-enabled technologies is discussed.
机译:网络安全运营中心(CSOC)是数字服务的基本企业差异化因素。它们执行监控数字服务的具有挑战性任务,使得当针对受监控的数字服务检测到攻击时,它们可以迅速响应网络事件来恢复到恢复。要监控业务服务,CSOC必须首先将这些商业服务携带在其安全监控和事件管理平台上。在CSOC的安全监测和事件管理平台上将业务服务的这种过程被描述为onboarding的网络安全。 onboarding的网络安全是设置和配置数字商业服务的专业技术过程,以生成适当的交互遥测,例如事件,日志,消息,指标和可观察。这些遥测指标在相关和分析时揭示了业务服务是否可能受到损害。在本文中,我们重新思考在CSOC上的船上服务方法。讨论了一种新的网络安全方法,即通过利用云原生和云的技术优化的循环,更简单,更快,高效,高效,优化的功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号