Chapter 3. Assessing Security Operations Capabilities

“Give me six hours to chop down a tree and I will spend the first four sharpening the axe.”—Abraham Lincoln

Establishing security operations center (SOC) capabilities requires careful planning. The planning phase helps you decide on and formalize the objectives that justify having a SOC, and to develop a roadmap that you can use to track your progress against those predefined objectives. Before you can do any planning, the existing SOC or anything that will be used for the SOC must first be assessed to understand the current capabilities for people, processes, and technology. You can compare this existing environment baseline against the objectives for the desired SOC to establish the level ...

Get Security Operations Center: Building, Operating and Maintaining your SOC now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.