This is the definitive, vendor-neutral guide to building, maintaining, and operating a modern Security Operations Center (SOC). Written by three leading security and networking experts, it brings together all the technical knowledge professionals need to deliver the right mix of security services to their organizations. The authors introduce the SOC as a service provider, and show how to use your SOC to integrate and transform existing security practices, making them far more effective. Writing for security and network professionals, managers, and other stakeholders, the authors cover:
- How SOCs have evolved, and todays key considerations in deploying them
- Key services SOCs can deliver, including organizational risk management, threat modeling, vulnerability assessment, incident response, investigation, forensics, and compliance
- People and process issues, including training, career development, job rotation, and hiring
- Centralizing and managing security data more effectively
- Threat intelligence and threat hunting
- Incident response, recovery, and vulnerability management
- Using data orchestration and playbooks to automate and control the response to any situation
- Advanced tools, including SIEM 2.0
- The future of SOCs, including AI-Assisted SOCs, machine learning, and training models
Note: This books lead author, Joseph Muñiz, was also lead author of Security Operations Center: Building, Operating, and Maintaining your SOC (Cisco Press). The Modern Security Operations Center is an entirely new and fully vendor-neutral book.
Joseph Muñiz, Technical Solutions Architect and researcher at Cisco, has extensive experience designing security solutions for Fortune® 500 corporations and the US Government. His current role gives him visibility into the latest cybersecurity trends from both leading vendors and customers. He runs thesecurityblogger.com, a popular resource for security and product implementation.
Aamir Lakhani is a leading senior security strategist. He is responsible for providing IT security solutions to major enterprises and government organizations. Mr. Lakhani creates technical security strategies and leads security implementation projects for Fortune 500 companies. Aamir has designed offensive counter-defense measures for the Department of Defense and national intelligence agencies. He has also assisted organizations with safeguarding IT and physical environments from attacks perpetrated by underground cybercriminal groups. Mr. Lakhani is considered an industry leader for creating detailed security architectures within complex computing environments. Writing under the pseudonym Dr. Chaos, Mr. Lakhani also operates the popular security social media blog, which is hosted at DrChaos.com. In its recent list of 46 Federal Technology Experts to Follow on Twitter, Forbes magazine described Aamir Lakhani as a blogger, InfoSec specialist, super hero…and all around good guy.