Cyber Strategy & Transformation
Security Operations Center (SOC)
We help our clients analyse areas for improvement in order to take the SOC to the next level of maturity. We provide a comprehensive overview of SOC operations for a future strategic roadmap.
Challenges
How do we ensure the right processes and governance to fully implement and operationalise a SOC?
A SOC is more than just installation of a log management solution. It requires significant process and governance enhancement to fully operationalise the SOC. Some of the process and governance challenges associated with the implementation of a SOC may include:
- Defining threat scenarios and logs required to monitor against the organisation’s threat landscape;
- Defining key performance metrics (as well as risk indicators) that aligns with the organisation’s risk appetite;
- Defining and updating a playbook with clearly defined roles and responsibilities to avoid confusion in the event of an incedent;Understanding the capacity of the SIEM solution, supporting architecture and the minimisation of ‘noise’ (false positives); and
- Recruiting skills and offering relevant training to subject matter expertise to improve the overall quality of the SOC capabilities.
Our approach
Our approach provides our clients with a strategic roadmap combined with a TCO analysis (total cost of ownership) with prioritised recommendations for future transformation to full ownership of the SOC.
Our approach consists of five phases:
-
Initiation and Information gathering
We tailor the assessment framework and agree on a project plan.
-
Target State
We understand the current-state maturity of the SOC capabilities to provide a baseline for future improvement.
-
Current-State Assessment
We define the target-state maturity for the SOC and identify recommendations for how to address the gap.
-
Reporting
We generate reports that capture the assessment throughout the phases.
-
Strategic Roadmap
We develop a roadmap including the target operating model and the prioritised roadmap combined with the TCO analysis.
- Initiation and Information gathering
- Target State
- Current-State Assessment
- Reporting
- Strategic Roadmap
We tailor the assessment framework and agree on a project plan.
We understand the current-state maturity of the SOC capabilities to provide a baseline for future improvement.
We define the target-state maturity for the SOC and identify recommendations for how to address the gap.
We generate reports that capture the assessment throughout the phases.
We develop a roadmap including the target operating model and the prioritised roadmap combined with the TCO analysis.
Why Deloitte?
Reach out
If you recognise some of these challenges, or if you would like to know more about how we can help your company, please do not hesitate to contact us.