Security Operations Center (SOC) SIG

Mission

Security operations centers encounter a variety of challenges, yet there is not a framework or guideline that focuses on the challenges unique to SOCs. SOC challenges can stem from disparities between people’s skills and knowledge, inadequately developed processes, and misunderstood or lack of technology resources. SOC teams are inundated with data which can make it difficult to discover or decide on adequate toolsets to help reduce the over consumption of data and extract greater value from the tools in place. Left unaddressed, these challenges can lead to the SOC team being slower to detect and respond to potential incidents, getting distracted with false positive or negative alerts, and being subject to analyst over exposure and alert fatigue.

In the FIRST community, there is a heavy focus on CSIRT/PSIRT frameworks and issues that include some mention of SOC-related concerns. While there is no one, right way to configure the delineation between SOC and CSIRT services, it would help to have SOC-specific collateral and or models for addressing the challenges SOC teams face.

The mission of the Security Operations Center SIG is to help synthesize existing materials and create new collateral for an easier to access focus area within FIRST for SOC-specific challenges and recommendations.

Goals & Deliverables

Goals:

Deliverables:

Chair

Meetings

Mailing list

Any FIRST member may join, others are welcome as well, requests must be approved by the SIG chairs.

Request to Join