

EP73 Your SOC Is Dead? Evolve to Output-driven Detect and Respond!
11 snips Jul 5, 2022
AI Snips
Chapters
Transcript
Episode notes
Output-Driven Security
- Output-driven security leverages known, common cloud outputs.
- This allows for predefined outcomes, reducing the need for custom detections.
Endpoint Protection Analogy
- Erik Bloch uses an endpoint protection analogy.
- He trusts the software despite not knowing its inner workings, similar to trusting cloud providers.
Rethinking the SOC
- The traditional SOC model struggles with cloud environments' common outputs.
- A federated approach, routing outcomes directly to responsible teams, is more effective.