Chapter 14
- The two roles are SOC engineer and SOC analyst.
- Both roles need to be involved in carrying out the scenario mapping exercise.
- The log ingestion rate and pricing tier should be checked at least once per month by the SOC engineer.
- The SOC analyst should check the Incidents page every day.
- You should look at ingesting logs the first moment the instance is created. This will provide maximum visibility of security events.
Assessments
Assessments
Assessments