Please enable JavaScript.
Coggle requires JavaScript to display documents.
Chapter 1: Cyber Security And Operations Centre - Coggle Diagram
Chapter 1: Cyber Security And Operations Centre
1.1 The Dangers
Threat Actors: The Amateurs
Known as script kiddies with some small skill or none. Basically just follow the instruction from internet.
Threat Actors: Hacktivitists
Do a protest against goverments. Such as post a videos or photos. Other information will be leaked by them.
Threat Actors: Financial Gain
Hack activity is motivated by get the financial gain. They generate the cash flows such as account banks, Personal Data and other information they can leverage.
Threat Actors:Trade Secrets And Global Politics
This is the Secret team form countries. They do hacking other countries and interfering with internal Politics
1.2 Fighters in the War
Against Cybercrime
Element of SOC
SOCs can be In-house, owned and operated by a business and Elements can be contracted out to security vendors.
The major elements of a SOC are processes, people, and technology
Security Operations Centers (SOCs) provide a monitoring, management, Comprehensive threat solutions, and hosted security
People in SOC
• Tier 1 Alert Analyst
• Tier 2 Incident Responder
• Tier 3 Subject Matter Expert (SME)/Hunter
• SOC Manager
Process in SOC
• Tier 1 Alert Analyst begins with monitoring security alert queues
• Tier 1 Alert Analyst verifies if an alert triggered in the ticketing software represents a true security incident.
• The incident can be forwarded to investigators, or resolved as a false alarm
Technology in SOC
•Security Information and Event Management (SIEM) systems:
• Collect and filter data.
• Detect and classify threats.
• Analyze and investigate threats.
• Implement preventive measures.
• Address future threats.