Cyber Security Notes

SOC

SOC

SOC Primary Functions

Vulnerability Management

  1. Discover Vulnerabilities on Systems
  2. Prioritize Systems
  3. Assess (baed on asset criticality, vulnerability threat, and asset classification)
  4. Report (measure risk)
  5. Remediate (fix/patch/remove/etc.)
  6. Verify Remediation (make sure the fix you performed worked)
  7. Discover (loop)

Common SOC Tools

SOC Roles

SIEM

SIEM Components

SIEM Correlation Engine

Indicators of Compromise (IOCs)