Processes and procedures
The key component to an effectively-run SOC is well-thought-out processes and procedures. An SOC must be able to implement effective identification and remediation activities the same way all the time. Effective processes and procedures ensure that this is carried out in a repeatable and reliable fashion.
Key process and procedure categories are needed to ensure an effectively managed and operating SOC mirror the incident response life cycle and include:
- Identification:
- Detection
- Analysis
- Remediation:
- Containment
- Eradication
- Recovery
The following is a sample process that identifies the parties and their duties if confronted with cross-site scripting vulnerability being identified on an organizational web application:
Process steps | Role |
| SOC analyst |
|