Security operations center roles
To have an effective security operation center, it is critical that you implement the necessary personnel roles to properly operate and maintain the environment. In the following list, you will find the personnel roles needed to fully implement a security operations center. Do not get hung up on the names of the roles if they do not match those in your organization. Each organization will have its own naming convention derived from the organization's culture:
- Security operations center analysts:
- Tier one: More junior information security analyst with a couple of years' experience in the information security field. Possesses a basic knowledge of networking, systems, and applications:
- Conducts information security tool monitoring
- Conducts basic investigations and mitigations
- Opens tickets
- Tier two: Poses a stronger knowledge of the information security tools used by the SOC as well as a deeper understanding of networking, systems, and applications:
- Deeper investigative...
- Tier one: More junior information security analyst with a couple of years' experience in the information security field. Possesses a basic knowledge of networking, systems, and applications: