LDR551_Book1 Flashcards
(242 cards)
What are common goals of attackers?
Intellectual property theft, extortion, destruction
How might an attacker exploit key IT assets?
To damage or hijack value creation.
What are the main categories to break down a SOC?
Business Alignment, Technology, People, Process.
What is crucial for SOCs to avoid reliance on ‘tribal knowledge’?
Solid foundation of processes and procedures.
What has driven increased understanding of cyber risk by businesses?
Heightened awareness and impact of breaches.
What do most organizations focus on in their cyber defense programs?
Technology solutions and tools.
What functions are consolidated in security operations?
Hunt, threat intelligence, IR functions.
What has brought increased visibility to the cyber security function?
Better articulated requirements
What aspect of the maturity model saw the biggest single-year jump?
People
What happens to SOCs without solid processes and procedures?
Reliant on ‘tribal knowledge’
What cripples the capability of SOCs lacking good processes?
Turnover of individuals
What stands out in the most capable cyber defense programs?
Repeatability, continuous improvement, metrics
What is the average measured maturity score for security operations teams?
Between 1 and 2
What does a score between 1 and 2 indicate about SOCs?
Tools not well-integrated, lack of structured process
What makes the effectiveness of most cyber defense programs unpredictable?
Lack of repeatability, metrics, continuous improvement
What is the ideal maturity level for most enterprise SOCs?
Level 3
What is the ideal maturity level for most managed service provider SOCs?
Level 4
What is a key characteristic of level 5 maturity?
Processes are rigid and less flexible
What is a significant downside of rigid processes in SOC management?
Significant overhead outweighs benefits.
What can rigid processes and overhead lead to in SOCs?
They can become counter-productive.
How can rigid processes affect SOC workforce engagement?
They can create a less engaged workforce.
What is a potential consequence of a less engaged SOC workforce?
Higher turnover in the SOC.
What are the biggest challenges for SOCs according to the SANS SOC Survey?
Lack of context, skilled staff, visibility, and automation.
What is one of the goals for new SOCs in the course?
Building a solid starting foundation.