Skip to main content
Guidance

Building a Security Operations Centre (SOC)

Designing a security monitoring capability proportionate to the threats faced (and resources available).

Page 11 of 14

Detection approaches - pros and cons

You should choose the approach that is appropriate for your organisation.

This list provides you with some of the key benefits and limitations that can be used to help you decide.


BenefitsLimitations/Cost
Commercial tool detectionCommercial security vendors often have large teams of cyber analysts keeping the tools up to date with the latest attacker techniques.Commercial tools have to cater for a number of different customers. Therefore, the attack detection is biased towards techniques that benefit the widest range of customers.
Custom detection use-cases

Rules can be developed for your environment – covering specific technologies or threats.

Can be more reactive to new threats – you can develop techniques without waiting for your commercial suppliers.

Relies heavily on skilled analysts to develop alert rules.

Requires log analysis tools that can be configured with detection logic, which can often be expensive compared to less configurable toolsets.

Data miningBespoke rules can be developed for your environment, that can be applied to large datasets – covering specific technologies or threats in order to look for anomalies among large sets of data.

Requires log analysis tools that can handle large amounts of data.

Requires data science skill sets within the SOC.

Threat hunting

Helps detect unknown attacks.

Significant investment in skilled staff.

Published

Reviewed

Version

1.0