Skip to main content
Guidance

Building a Security Operations Centre (SOC)

Designing a security monitoring capability proportionate to the threats faced (and resources available).

Page 4 of 14

Designing an Operating Model

Having developed a picture of the threats that your organisation is trying to defend itself against and a picture of the assets you need to monitor, you can now start to consider what your operating model should include.

The diagram below sketches the various typical capabilities of a SOC in the context of sophistication and volume of attacks. Though this is quite difficult to illustrate and predict, this diagram can be used as a rough guide to help you reason about the level of capability you should be aiming for.


SOC capability matrix

SOC capability matrix

You may not have any real idea about the volume of attack but at this stage it is not so important, the main outcome needs to be defining what level of capability is proportionate for your organisation, given the potential sophistication of attacks in your threat profile.

Remember that this is cumulative, so if you perceive that your organisation would be targeted by highly sophisticated adversaries, you will need to ensure that your SOC has all of the preceding capabilities. In this example, in support to threat hunting you would need to ensure that you have a mature use-case development capability and so on.

The details about what these functions actually include are covered in the Detection section of this guidance.







Published

Reviewed

Version

1.0