An Overview of Cybersecurity Operations
First, let’s take a high-level look at all the sub-functions that should be addressed as part of cybersecurity operations. The following image captures much of what the cybersecurity operations function entails.
Figure 7.1: Sub-functions of the cybersecurity operations function
Similar to your IT operations, which overlook the day-to-day IT activities of your organization, cybersecurity operations overlook the day-to-day operation of your cybersecurity program for the organization.
One of the primary responsibilities is managing cybersecurity incidents submitted through the ticketing system, whether they originate from automated alerts or users reporting them. As part of your cybersecurity operations, the focus of the structure will be around three primary areas: the SOC, threat detection, and incident management and response. In addition, with the recent advancement of Artificial Intelligence (AI) becoming more accessible...