Best practices for running a SOC include: developing a strategy, creating enterprise-wide visibility, investing in the right tools, hiring and training the right people, maximizing efficiency, and designing your SOC to meet your specific needs and risks.
Develop a strategy: a SOC is a significant investment because so much depends on your security planning. When developing a strategy that meets your security needs, ask yourself the following questions:
- What needs to be secured? A single local network or a global one? Cloud or hybrid? How many endpoints? Do you need to protect highly confidential data or customer information? What data is most valuable and therefore most likely to be the target of attacks?
- Should the SOC be integrated into your NOC or should two separate departments be created? As a reminder, the functions differ significantly and integrating the two departments requires different tools and staff skills.
- Do your SOC staff need to be available 24/7, 365 days a year? This has implications for staffing issues, costs and logistics.
- Should all SOC tasks be performed in-house or do you want to outsource some or all functions to a third-party provider? A careful cost-benefit analysis will help you weigh the options.
Create visibility across your entire enterprise: Your SOC must have access to all elements that could impact security, even if they seem small and insignificant at first. In addition to the larger infrastructure, this includes device endpoints, systems controlled by third parties, and encrypted data.
Invest in appropriate tools and services: When building your SOC, focus on the tools first. Without proper automated tools to reduce the “noise” and bring the most important threats to the forefront, you will struggle to manage the flood of security events. Specifically, you should invest in the following tools:
- SIEM (Security Information and Event Management): This single security management system provides a complete view of activity within your network by collecting, parsing and categorizing machine data from a variety of sources across the network, then analyzing that data so you can respond in real time.
- Endpoint security systems: any device that connects to your network is vulnerable to attack. An endpoint security tool protects your network when said devices access it.
- Firewall: A firewall monitors incoming and outgoing network traffic and automatically blocks access based on security rules you create.
- Automated application security: Automates the testing process of all software applications and provides real-time vulnerability feedback to the security team.
- Asset discovery system: Tracks the active and inactive tools, devices, and applications used on your network, enabling risk assessment and vulnerability remediation.
- Data monitoring tool: Allows you to track and evaluate data to ensure its security and integrity.
- Governance, Risk and Compliance (GRC) system: Assists you with required compliance with various rules and regulations.
Vulnerability scanner and penetration testing: Enables your security analysts to search for vulnerabilities and identify hidden weaknesses in your network. - Log management system: Enables logging of the numerous messages from all software and hardware elements and endpoints running on your network.
Hire and train qualified professionals: Hiring qualified employees and providing them with ongoing training is a key component of success. The market for safety professionals is highly competitive. Once you have succeeded in hiring qualified employees, you should continuously invest in their further training. In doing so, you will ensure greater safety, higher motivation and strengthen employee loyalty. Your team needs to be knowledgeable in the following areas: Application and network security, firewalls, information assurance, Linux, UNIX, SIEM, and security engineering and architecture. For the highest level security analysts, the following qualifications are desirable:
- Ethical Hacking: you need someone who will attempt to hack your system to uncover vulnerabilities.
- Cyber forensics: analysts conduct investigations and apply certain analytical techniques to unearth and preserve evidence. Should a case go to trial, the security analyst must be able to provide a documented chain of evidence that can be used to understand what events occurred and why.
- Reverse engineering: this is the process of decompiling or deconstructing or rebuilding software to understand how it works and, more importantly, where it is vulnerable to attack so the team can take preventative measures.
- Expertise regarding intrusion prevention systems: Monitoring network traffic for threats would not be possible without proper tools. Your SOC personnel must be well versed in their proper use.
Review all of your options: The following are the most common types of SOCs.
- Internal SOCs, usually with full-time employees who all work on-site. The internal SOC is located in a physical space within the company where employees go about their business.
- Virtual SOCs are not on-site and are staffed by part-time employees or independent contractors who work together in concert to resolve issues as needed. The SOC and the business establish parameters and guidelines for the relationship. The support provided by the SOC can vary based on business needs.
- Outsourced SOCs, where some or all functions are managed by an external MSSP (managed security service provider) that specializes in security analysis and response. Sometimes these companies provide certain services to support an internal SOC, and sometimes they perform all tasks.