Implementing and Integrating Security Monitoring
Enterprises adopt multi-cloud and use cloud services from different cloud providers. These solutions will be securee, but enterprises want an integrated view of the security status on all of their platforms and solutions. This is what solutions such as Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) do.
In this chapter, we will learn why these systems are a necessity in multi-cloud. First, we will discuss the differences between the various systems, and then we will explore the various solutions that are available on the market today. The big question we’re going to answer in this chapter is, how do we make a choice and, more importantly, how do we implement these complicated solutions?
We’re going to cover the following main topics in this chapter:
- Understanding SIEM and SOAR
- Setting up a Security Operations Center
- Setting up the...