Exam Questions And Answers
A
R
U
LA
C
O
D
, Why do we need a Security Operations Center (SOC) - It helps identify:
- Who or what was targeted
- Was the adversary successful
- Who is the adversary and what is their motivation
- How do we continue with the business mission
A
SOC Mission - - A team that detects, analyzes, and responds to
incidents to minimize damage from security issues
R
- Known by a variety fo alternative names and terms
-- Cybersecurity Operations Center (CSOC)
-- Computer Incident Response Team (CIRT)
U
-- Computer Security Incident Response Team
(CSIRT)
-- Computer Emergency Response Team (CERT)
LA
-- Network Operations and Security Center (NOSC)
What does a SOC do - Detects, analyzes and responds to security incidents
Functional Components of a SOC - - Understand what it's supposed to do
- How it works; and what components are available to
C
support the desired function
- Roles people play and define the procedures for
those people to follow
- Permutations on how to arrange and staff the
O
functions
Steering Committee - - Provides a vehicle for discovery and planning; it focus
D
shifts to high-level implementation decisions, without
involving itself in the details of the actual build
- Provides ongoing operational oversight
-- Helps SOC adapt to changing business and
technology drivers
-- Supplies SOC with:
- Situational awareness of the business
- Legal requirements
- Cultural drivers