Chapter 13: Operational Tasks for Azure Sentinel
As with any service or solution, an ongoing maintenance routine is a critical process to ensure timely service improvements, maintain operational efficiency, control costs, and—most importantly—ensure the service remains highly effective in detecting and responding to security issues.
In general, Security Operations Center (SOC) operations are performed by two distinct roles: SOC engineers and SOC analysts. In a small organization, this may be a single person carrying out both roles; in larger organizations, these roles will span many teams and will be carried out by dedicated professionals. In this chapter, we will provide details of the daily, weekly, and monthly tasks required for each role, and any ad hoc tasks that should be carried out as required.
The information in this chapter is meant to provide a starting point for your own planning and ongoing improvement, so you can carry out the necessary processes to...