Building a Security Operations Centre (SOC)
Pages
Page 2 of 14
Operating Model
Designing an operating model will help you enumerate and understand the components required when building a SOC. It acts as the foundation for the various aspects of your design. By considering the threat you are faced with, and the assets you are monitoring, you will be in a position to design a target operating model (TOM) that is proportionate to your requirements.
A TOM architecture that considers your requirements and illustrates how the various components of a SOC are related and how they work together to deliver security to your organisation.
It’s important to be pragmatic and honest with your operating model, so that what you’re aiming for is proportionate and achievable. That said, it should be developed with growth in mind so that you can adapt your capability as your requirements and threat will change over time.
Like most architectures, it will evolve as you go, so don’t expect to stick to your original design, it’s a cumulative and iterative process. Remember what you’re designing is a target operating model and it may take years to implement it fully.
Finally, it’s important to remember that there isn’t a golden panacea, there is no one-size-fits all approach. This section will enable you to design a bespoke operating model that works for your organisation.
- Things to consider
It is important that the operating model you develop is proportionate to the threats you face and what you are trying to protect.
- Designing an Operating Model
Having developed a picture of the threats that your organisation is trying to defend itself against and a picture of the assets you need to monitor, you can now start to consider what your operating model should include.
- The target operating model
Having gone through the process of enumerating your threat profile, defining the SOC scope and evaluating what services would be proportionate for your SOC you should be in a position to put it all together.