Guidance
Building a Security Operations Centre (SOC)
Designing a security monitoring capability proportionate to the threats faced (and resources available).
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 11 of 14
This list provides you with some of the key benefits and limitations that can be used to help you decide.
| Benefits | Limitations/Cost | |
|---|---|---|
| Commercial tool detection | Commercial security vendors often have large teams of cyber analysts keeping the tools up to date with the latest attacker techniques. | Commercial tools have to cater for a number of different customers. Therefore, the attack detection is biased towards techniques that benefit the widest range of customers. |
| Custom detection use-cases | Rules can be developed for your environment – covering specific technologies or threats. Can be more reactive to new threats – you can develop techniques without waiting for your commercial suppliers. | Relies heavily on skilled analysts to develop alert rules. Requires log analysis tools that can be configured with detection logic, which can often be expensive compared to less configurable toolsets. |
| Data mining | Bespoke rules can be developed for your environment, that can be applied to large datasets – covering specific technologies or threats in order to look for anomalies among large sets of data. | Requires log analysis tools that can handle large amounts of data. Requires data science skill sets within the SOC. |
| Threat hunting | Helps detect unknown attacks. | Significant investment in skilled staff. |


