Building a Security Operations Centre (SOC)
Pages
Page 14 of 14
Incidents (Incident Management)
There is comprehensive incident management guidance over at NCSC Incident Management so this page will only highlight a few related areas that need to be considered when designing a SOC.
How the SOC responds to cyber attacks
As discussed on the Detection page, it is important to consider how to triage alerts when they fire. Making the triage process as efficient as possible will save time and enable analysts to spend more time improving the SOCs capabilities.
The blurry line between alerts and incidents
Not every alert will be an incident. This is why developing a consistent process that enables the SOC to efficiently determine the nature of an alert is vital. Below are some points that will help you:
- Ensure that analysts understand what the detection use-cases are designed to do.
- Design alerts to pull as much information from the log data as possible. Think of the 5W1H principles when designing alerts. The more information on the screen, the quicker something can be understood, triaged and escalated if appropriate.
- Reduce false positives by providing feedback on how to improve or consolidate use cases.
- Ensure that escalation paths are clear and customer records are up to date. Ensure that you have multiple points of contact for systems within the scope of the SOC.
Context
If the analysts triaging the system understand the context of the system, they will be better able to spot abnormal behaviour. Without a contextual grasp of the system, alerts will be difficult to triage.
Giving analysts the opportunity to work in various roles across the SOC does help to deal with this, as discussed in the Operating Model section. If this is not possible, steps should be taken to allow analysts to familiarise themselves with the systems they are monitoring.
Triage quality
The actions SOC operators take when triaging an alert or investigating an incident should be recorded. This simply ensures that the SOC is accountable for its actions but also enables the periodic quality assurance activities, ensuring that alerts (false positive or not) aren't being dismissed without good reason.
Exercises
As with the development of detection use-cases, incident handling is a process that can be tested and doing so will ensure that any issues with communication and capability are highlighted and fixed. Performing near real exercises are a valuable tool in any SOC and understanding how to react to a varied set of scenarios will enable the team to react more confidently to any real incidents.
The NCSC have developed an online resource, Exercise in a box, which helps organisations find out how resilient they are to cyber attacks and practise their response in a safe environment.