A SOC has many responsibilities, all structured around protecting an enterprise against cyber-attacks. SOC teams are made up of an extensive array of different specialists, from analysts and threat researchers to investigators and co-ordinators. They all work together to manage security, investigate, and remediate security incidents.
We have categorised these responsibilities into several different areas:
Alert management
One of the SOCs primary responsibilities is managing the alerts that are generated by the various cyber security tools, such as
the SIEM. These alerts have to be organised and prioritised, investigated, and remediated.
Analysts within the SOC team will often need to provide extra assistance in finding relevant data that can be attached to alert tickets to assist threat investigators.
This is a vital function of a SOC and one that can quickly become overwhelming if managed incorrectly. It’s common for enterprises to receive hundreds or even thousands of alerts a day, so proper alert management is critical.
Investigation of incidents
Some alerts generated by the system require more investigation than others. Every SOC team should employ several threat investigators. These are experts who specialise in looking deeper into alerts to determine if they pose a threat to the enterprise’s infrastructure or not.
Threat triaging and prioritisation
As we mentioned in alert management, every alert that is generated by the system needs to be accurately triaged and prioritised. Whilst modern solutions can automate aspects of this process, it still requires a dedicated and expansive team of SOC analysts to manually take over this process frequently.
Once threats have been triaged and prioritised, the SOC has to respond to them depending on the alert’s severity, whilst also ensuring that the SOCs resource utilisation is optimised and risk is minimised.
Incident response
One of the primary responsibilities of a SOC, incident response takes many different forms but involves accurately and appropriately responding to and remediating threats. This part of the SOCs processes can be difficult and requires engagement with a variety of internal and external stakeholders.
Different tools are utilised depending on the threat and a plan must be created and followed to ensure that nothing is missed, and remediation is completed properly.
Data monitoring & reporting
Well-run SOCs have complete visibility of the infrastructure they protect and manage. With this visibility comes a wealth of data, taken from every possible connector available to them within the infrastructure. This includes endpoints, networks, storage devices, the cloud, and much more.
A SOC is responsible for collecting, collating, and monitoring this data, as well as reporting to necessary stakeholders about the health and effectiveness of their cyber security.
Infrastructure management
A SOC must constantly adapt to the changing threat landscape. As new technologies and solutions are developed and new threats emerge, it’s the job of the SOC to investigate and utilise new cyber security solutions and technology to better protect the infrastructure they manage.