IT Operations Management (ITOM)
Showing results for 
Search instead for 
Do you mean 

Is it time for Sec-Ops?

Aruna on ‎02-22-2012 05:56 PM ‎11-30-2016 02:40 PM kimlock

It’s time to demolish the divide between the Network Operations Center (NOC) and the Security Operations Center (SOC). Here’s how to get started.

 

Step 1: Prioritize

Start with what matters most:

  • Which apps or services are the most critical to your organization?
  • Which ones can’t afford to have a security problem remain undiagnosed for even a few minutes?

 

Step 2: Collaborate with the security team

Because you’ll be shifting some responsibility from one team to another, it’s important to ensure that everyone understands why.

  • Facilitate communication between the NOC and SOC teams about what they will gain by bringing security events into the NOC.
  • Ensure the NOC team understands the importance of giving the SOC team visibility into certain aspects of NOC monitoring tools.
  • Discuss the various tools you’ll need to accomplish this coordination and the processes you will need to create or modify.

 

Step 3: Identify the right monitoring tools

It’s important to look for a tool that won’t add new complexity to the NOC or its processes. The ideal tool would consolidate and correlate all events—security and operational—under a single pane of glass. It also should:

  • Provide real-time monitoring information.
  • Allow for customization, so that both the SOC and NOC teams can see the information they need to see.
  • Integrate security system events with the NOC's overall event management system.
  • Connect security-related events with the business services they affect so you can prioritize problems when they arise.
  • Identify a problem’s cause with little or no manual work.

 

 

This post is adapted from a longer article that appeared in the Discover Performance newsletter. Sign up today to receive more actionable insight that can help you turn IT performance into business success.

 

 

For more information about coordinating operations and security, read about HP’s BSM 9.1, integrated with ArcSight Logger for greater security visibility.

 

LABEL: Security and Operations

KEYWORDS: SOC, NOC, enterprise security, DevOps, BSM 9.1, Logger, ArcSight, Monitoring

0 Kudos
About the Author

Aruna

Events
June 6 - 8, 2017
Las Vegas, Nevada
Discover 2017 Las Vegas
Join us for HPE Discover 2017 in Las Vegas. The event will be held at the Venetian | Palazzo from June 6-8, 2017.
Read more
Apr 18, 2017
Houston, TX
HPE Tech Days - 2017
Follow a group of tech bloggers for a new HPE Tech Day, a full day of sessions about how to create a hybrid IT, from hyperconverged to Composable Infr...
Read more
View all
//Add this to "OnDomLoad" event