

Strategy 3: Build a SOC Structure to Match Your Organizational Needs
May 22, 2023
Chapters
Transcript
Episode notes
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30
Introduction
00:00 • 2min
How to Build a Sock Structure to Match Your Organizational Needs
02:28 • 2min
How to Organize a Socket Team
04:21 • 4min
The Evolution of Socks
08:32 • 2min
The Importance of Context in Reorganized Strategy
11:02 • 2min
The Importance of Context in a Large Organization
12:36 • 2min
How to Build the Strongest Security Operations Team
14:54 • 3min
The Importance of Having a Home for Your SOC
17:35 • 3min
How to Structure a SOC
20:12 • 3min
The Importance of Time in SOC Engineering
22:50 • 3min
The Flaws in Logic
25:26 • 3min
The Benefits of Having People With Scripting Skills in Your Sock
28:53 • 2min
The Benefits and Drawbacks of a Tier List Model
31:01 • 3min
How to Set Up a Tier List Environment for Your Organization
33:51 • 3min
How to Leverage Automation in All of This
37:02 • 2min
The Problem With Second Edition Alerts
38:40 • 1min
Tiered Socks: How to Avoid Complementary Contracts
40:09 • 2min
How to Outsource Your Analysis Force
42:07 • 3min
How to Outsource Incident Response to the MSSP
45:22 • 2min
How to Be Sure Your MSSP Is Doing What They Think They're Doing
46:54 • 4min
How to Make a Decision on How Much Coverage You Need
50:29 • 2min
How to Outsource Alert Triage and Investigation for 24 Hours
52:39 • 3min
How to Build a Socket Room
56:08 • 3min
How to Make Your Analysts Comfortable
58:57 • 2min
The Importance of Collaboration in a Physical Socket
01:01:15 • 3min
The Importance of Being Near Your Stakeholders
01:04:01 • 2min
The Effect of Remote Communication on Onboarding
01:05:38 • 2min
The Importance of a Sock Coming Together Physically
01:08:05 • 2min
The Importance of Team Cohesion
01:09:51 • 2min
The Importance of Human-Human Connection in Incident Response
01:11:35 • 3min