Building a Security Operations Centre (SOC)
Pages
Page 3 of 14
Things to consider
It is important that the operating model you develop is proportionate to the threats you face and what you are trying to protect.
These aspects are explored in detail below, before moving on to a discussion of their impact on the design of your operating model.
Threat profile
The capabilities of your SOC should be proportionate to the threat faced by your organisation.
This means that the first task should be to define that threat profile.
Your threat profile will influence your approach to detecting attacks, and have implications for other SOC functions, such as the skills required by your SOC analysts.
Whilst some organisations with an extremely high threat profile may require a SOC that can detect and respond to even the most sophisticated attacks, most will not. For example, the threats facing a small retailer are likely to be different to the threats facing a large retail bank.
There are various ways of defining the threat profile of an organisation. However, it is advisable to consider the sophistication of attackers you are expecting might target your organisation.
STIX v2.1 is an extremely useful framework for this as it provides a scale of definitions for threat actor sophistication. These range from threat actors with little understanding and average computer skills to professional and state actors who can work with and develop new vulnerabilities and affect the supply chain.
It is important to conduct an honest and reasoned assessment of the sophistication of threat actor(s) that you suspect may target your organisation.
Detecting an attack conducted by an “Innovator” level actor is significantly more difficult than an “Expert” level actor, therefore this will have a significant impact on your SOC design. Finally, it's OK to start with a lower capability and then improve as the SOC matures, it's important to walk before you run.
Assets
It can be very difficult for a SOC to provide the same level of monitoring for an entire IT estate. For this reason, a SOC must understand what the organisation's most critical assets are, and the business context in which they operate. This allows resources to be prioritised. Where possible work with existing IT operations as they will be able to provide invaluable insight into the IT estate.
Understand the system and context
The more detail the better, as this will help in building a baseline of normal operation. This is essential if you want to detect when the system is operating abnormally and therefore, potentially under attack.
Your model of baseline activity should involve enumerating user and data flows, profiling user behaviour and understanding how security controls are intended to work. Where possible, include the system designers and developers in modelling a baseline, as they can provide valuable insight into the system, also highlighting any potential vulnerabilities.
Threat modelling
You should identify the most sensitive areas or targets within your system. What would an (appropriately sophisticated) adversary be interested in exploiting? How would they go about doing so?
This kind of exercise should also be closely tied to Threat Intelligence, so that the scenarios and hypotheses reflect real world scenarios and attacks. The Onboarding page discusses how this exercise can be used to ingest systems in the SOC.
Impact assessment
Understanding the impact of compromise of systems, service or assets will help you prioritise what you monitor, how you monitor it and what you will do to respond to a detected attack. This approach is important as the compromise of even the smallest systems can have a huge impact.


