Dedicated to my thoughts while learning cybersec
The SOC protects the company from security breaches by identifying, analyzing and reacting to cybersecurity threats. The core function of a CSIRT is to minimize and manage damage caused by an incident, the CSIRT also communicates with stakeholders. The SOC often oversees the CSIRT
The SOC protects an entire organization from security breaches. They are not help desk for internal employees or external customers. Creates the VPN / Doesn't help you connect to it
</li>
Without the appropriate tools and training a SOC is only an illusion of safety.
</li>
Security analysts and security engineers are supervised by an SOC manager. The SOC manager needs to have strong security expertise, management skills, and battle-tested crisis management experience.
</li>
It is not a question of if you will be attacked but rather when you will be attacked. Have a plan in place and ready to be executed.
</li>
Every point of entry or communcation between machines is a potential vulnerability. Never trust the client and assume every request is malicious.
</li> </ul> </details>
All attacks have three stages Pre-Attack, Attack, Post-Attack. All stages are equally important but only one can be addressed before an issue exists.
"It always does that" is not a good excuse to allow a problem to persist.
AAA (Arrange-Act-Assert), then Red, Green, Refactor.
Security information and event management
Governance, risk and compliance
Security information and event management
A tool to monitor systems, infrastructure, and networks to identify performance bottlenecks and send alerts.