Module 02 - Fighters in the War Against Cybercrime Flashcards
What is a SOC?
Security Operations Centre
What is a SIEM?
Security Information and Event Management
What does a tier 1 analyst do?
Monitors incoming alerts, verifies that it is a true incident
What does a tier 2 responder do?
deep investigation of incidents and advise action to be taken
What does a tier 3 threat hunter do?
experts in their field
How many metrics are used in a SOC?
5 Metrics
Dwell Time?
Length of time that threats have access to a network before they are detected
Mean Time to Detect (MTTD)
the average time it takes for the SOC to identify valid security incidents
Mean Time to Respond (MTTR)
The average time it takes to stop an incident
Mean TIme to Control (MTTC)
The time required to stop the incident from causing further damage.
Time to Control
The time required to stop the spread of malware in the network.