Don’t give staffing issues short shrift as you plan your enterprise security operations center, pioneers advise.
Staffing a security operations center can be almost as challenging as building it or paying for it, users and experts say.
The 24/7 monitoring necessary in a SOC presents one of the biggest hurdles. “For companies used to having security personnel working eight hours a day, five days a week, that dramatically increases their overall staffing requirements, since one 24-by-7 seat is equal to roughly five full-time employees,” says John Summers, global director of managed security services at Unisys.
Faced with such a prospect, many organizations look to cut corners.
For example, some make the mistake of staffing their SOC solely with their best security personnel. “Companies take seasoned security professionals, stick them in front of a screen and ask them to do a six-hour monitoring shift,” says Andreas Antonopoulos, senior vice president and founding partner at Nemertes Research. “You won’t retain those people too long because they will very quickly become bored.”
Beyond boring and overworking a valued staffer, this tactic also could create a huge security vulnerability.
“If one person is writing your security policy, implementing your policy, monitoring it and then checking for compliance, that person is basically one huge risk,” Antonopoulos says. “There’s no separation of duties, and absolutely no checks and balances.”Instead, a good SOC, like a good, traditional network operations center, should be staffed in tiers, with Tier 1 personnel receiving alerts and doing low-level troubleshooting, and Tier 2 and 3 people handling more complex alerts and problems. In the best of all worlds, Tier 1 personnel should provide the first line of response for both the security and network operations sides of the house.
That way, your more veteran security professionals can handle the more complex risk-management and policy-writing tasks, while putting lower-level staffers into the SOC for the primary monitoring. Then, when alerts come up and the Tier 1 staffers are unsure how to proceed, they can kick up the problem to a Tier 2- or 3-level person. Only then does your more expert, and expensive, staff get involved.




