Skip to main content
Guidance

Building a Security Operations Centre (SOC)

Designing a security monitoring capability proportionate to the threats faced (and resources available).

Page 6 of 14

Onboarding systems and log sources

Onboarding is a key part of SOC operation, particularly for new SOCs but also for established SOCs; no IT estate will perpetually stay the same.

Onboarding is the name given to the process of adding systems to the scope of a SOC. This means ensuring that the logs from those systems are collected by or sent to the SOC systems, so that they can be monitored.

Onboarding is a key part of SOC operation, particularly for new SOCs but also for established SOCs. This is because no IT estate will perpetually stay the same.

There are multiple ways to perform onboarding, from onboarding common log sources, using the output of risk assessments or just onboarding absolutely every log source available.

Threat modelling can also be used to support onboarding, and we will talk more about this here, as we will describe a threat-led approach to onboarding systems and log sources into your SOC.

The goal of this is to enable you to determine which log sources are most appropriate to your organisation and should be onboarded.

  • Log sources Identify log sources that will provide you with information that would be useful when performing security monitoring.

Reviewed

Version

1.0