Five SOC pitfalls to avoid

Feature
Mar 21, 20052 mins

Five SOC pitfalls to avoid

1. Technology tunnel vision. Getting caught up in the latest and greatest tools is tempting, but the core of your security operations center (SOC) should be based on sound risk assessment and security policies. Once you’ve hammered those out, you can focus on the products and technologies that will best support them.

2. Silo mentality . Don’t organize your SOC in a silo separate from your network operations. An efficient SOC depends on fully integrating security and network monitoring tools, as well as the staffing associated with them.

3. Staffing mistakes . Don’t use your veteran security staff to do low-level monitoring, and make sure you have the proper checks and balances in place so that no one person holds all the keys to your network kingdom.

4. Inflexible tool sets. Choose tools that will support not only your current security devices, ticketing systems and network monitoring suites, but also those that are easy to customize and offer a variety of templates and wizards. Be aware that even the best tool sets require a good deal of customization and integration.

5. Taking the cheap route. A SOC is no place to skimp. On average, large organizations should plan to invest $1 million or more to implement and maintain a truly enterprise-level SOC. And that investment will most likely grow over time.