Operational tasks for SOC engineers
In this section, we will provide an initial list of tasks that have been identified as engineering tasks. You can use this list as a starting point, and then add your own tasks based on what works for your specific requirements. Each component that is added to the SOC architecture will have its own task requirements—for example, if you integrate a Cloud Access Security Broker (CASB) solution, you will need to carry out similar tasks within that platform to ensure it is well maintained and sending the appropriate information to Azure Sentinel.
Daily tasks
A list of daily tasks is as follows:
- Monitor the service health of all core components such as the Azure platform, Azure Active Directory (AD) for Identity and Access Management (IAM), and any data collection servers (syslog), ensuring dashboards are available and alerts are triggering as expected.
- Review the planned maintenance, service health, and availability monitoring...