人是營運世界級 SOC 的最重要因素。透過培訓和招募確保擁有合格的員工是關鍵。
People are the most important aspect of operating a world-class SOC.
Ensuring you have qualified staff—through training and recruitment—is key.
尋找熱情、好奇心和對知識的渴望的人(沒有興趣很難做下去,有興趣什麼職業都可以轉SOC)
When it comes to cyber, look for enthusiasm, curiosity, and a thirst for knowledge
建議參考其他文章比較清楚,歐盟資安技能框架ECSF定義資安團隊12角色,揭露各職任務重點
https://www.ithome.com.tw/news/156746
資安範圍很廣,需要長時間培訓,團隊成員各有擅長的項目,內部相互訓練是個方式,而外部訓練是取得新技術的途徑。
Growing the SOC team requires a consistent investment of time and resources but leads to long term success
很重要所以重複三次(書上就是三次)
Unfortunately, it is one of the hardest to answer, because there are so many issues at play.
視環境成熟度、成員能力、自動化成度、外部威脅以及風險承擔能力而定
A SOC’s capacity to perform its entire mission is usually influenced more by its skill level, maturity, and automation that the number of analysts.
人力有限,不要給大量未經整理的資料(讓工具AI來協助吧)
Do not ask analysts to monitor an unfiltered feed
雲端SOC並不能減少分析師人力,但可以減少平台維護
Cloud-based SOC tools do not eliminate maintenance labor costs; but they do allow for more focus on tasks like use-case development rather than standard maintenance