Intro Flashcards

(18 cards)

1
Q

What are the domains in the model?

A

Business
Process
People
Service
Technology

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the mission of the model?

A

To improve security operations globally by providing services tooling and other content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the difference between the basic processes? The advanced assessment model?

A

The advanced model at the concept of weight
It allows a more granular score and it enables practitioners to exclude questions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the licensing model?

A

It is based in creative common BYSA 4.0 license
BY implies that attribution
SA means share alike copy left

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the status of the soccmm4cert

A

It will probably be discontinued

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are typical use cases for the model?

A

Compliance
Current status ass asses
Target operating model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the main challenges of a modern soc in the business domain?

A

Alignment with the business
24 seven
Hybrid soc: in-house versus outsourced
Governance of outsourcing partners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the major challenges of a modern sock in the people domain?

A

Tiered versus untiered
Skill shortage
Engineering versus analyst capacity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the main challenges of a modern soc in the process domain

A

Layer detection
Detection focus
Gaps in monitoring
Increasing event flow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the main challenges of a modern stock in the technology domain?

A

Automation
Complexity
Cloud versus on prem monitoring
Monitoring and Saas first strategy
AI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What types of assessment in terms of scope are covered in the model?

A

Quick scan
A scoped assessment
Full assessment

Baseline versus progress assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What type of assessments are in the model based on who does the assessment?

A

Self assess
Guided self ass
Third-party assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What type of assessments are there considering the formal level of the assessment?

A

Informal
Formal
Audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What data collection strategies can be used

A

Workshops
Interview interviews
Desk research
Expert opinion

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the duration of a typical assessment in terms of effort?

A

5 to 10 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How can an ROI be established?

A

Quantitatively for example by hours saved by automation
Qualitatively for example by implementing a soar solution

17
Q

What is meant by the term rules of engagement for a soc analyst?

A

What can of sock analyst do?
Only passive analysis
Offensive analysis
Or into the grey zone: hunting