
#165 - Modernizing Our SOC Ingest (with JP Bourget)
CISO Tradecraft®
00:00
Automating Playbooks in a SOC
This chapter discusses the process of automating playbooks in a SOC (Security Operations Center), emphasizing the importance of well-documented processes and identifying micro-decisions to be automated. It mentions the challenges of the 'last mile problem' in automated incident response and the need to invest in automating the right use cases. The chapter also touches on the modernization of SOC ingest, focusing on efficiency, engineering, source control, and secure data pipeline modernization.
Transcript
Play full episode