Intro Flashcards
(18 cards)
What are the domains in the model?
Business
Process
People
Service
Technology
What is the mission of the model?
To improve security operations globally by providing services tooling and other content
What is the difference between the basic processes? The advanced assessment model?
The advanced model at the concept of weight
It allows a more granular score and it enables practitioners to exclude questions
What is the licensing model?
It is based in creative common BYSA 4.0 license
BY implies that attribution
SA means share alike copy left
What is the status of the soccmm4cert
It will probably be discontinued
What are typical use cases for the model?
Compliance
Current status ass asses
Target operating model
What are the main challenges of a modern soc in the business domain?
Alignment with the business
24 seven
Hybrid soc: in-house versus outsourced
Governance of outsourcing partners
What are the major challenges of a modern sock in the people domain?
Tiered versus untiered
Skill shortage
Engineering versus analyst capacity
What are the main challenges of a modern soc in the process domain
Layer detection
Detection focus
Gaps in monitoring
Increasing event flow
What are the main challenges of a modern stock in the technology domain?
Automation
Complexity
Cloud versus on prem monitoring
Monitoring and Saas first strategy
AI
What types of assessment in terms of scope are covered in the model?
Quick scan
A scoped assessment
Full assessment
Baseline versus progress assessment
What type of assessments are in the model based on who does the assessment?
Self assess
Guided self ass
Third-party assessment
What type of assessments are there considering the formal level of the assessment?
Informal
Formal
Audit
What data collection strategies can be used
Workshops
Interview interviews
Desk research
Expert opinion
What is the duration of a typical assessment in terms of effort?
5 to 10 days
How can an ROI be established?
Quantitatively for example by hours saved by automation
Qualitatively for example by implementing a soar solution
What is meant by the term rules of engagement for a soc analyst?
What can of sock analyst do?
Only passive analysis
Offensive analysis
Or into the grey zone: hunting