Guidance
Building a Security Operations Centre (SOC)
Designing a security monitoring capability proportionate to the threats faced (and resources available).
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 7 of 14
Having followed the principles set out in the Operating Model page, you should have a fairly comprehensive understanding of your system and its architecture. You should also have an idea of the threat and sophistication of attack that you are trying to detect within your system.
The next step is to identify log sources within your organisation (or customer systems) that will provide you with information that would be useful when performing security monitoring. This is where threat modelling can be useful, as it will enable you to identify valuable log sources and provide a rationale as to why you should collect them.
In addition to being used for detection, log sources are also vital in performing incident response as they can provide valuable context around system behaviour in the event of an incident.
With the goal of staying technology agnostic, this guidance will not enumerate every type of log source. However, sources can be split into four broad categories that should be considered.
For more information on log types see the NCSC introduction to logging.
Before delving into the process of systematically identifying log sources, there are some quick wins for monitoring.


