Google發表一系列文章提到了,讓SOC安全營運中心學習SRE可靠性工程的做法。
Achieving Autonomic Security Operations: Reducing toil
https://cloud.google.com/blog/products/identity-security/achieving-autonomic-security-operations-reducing-toil
Achieving Autonomic Security Operations: Automation as a Force Multiplier
https://cloud.google.com/blog/products/identity-security/security-automation-lessons-from-site-reliability-engineering-for-security-operations-center
[Infographic] Achieving Autonomic Security Operations: Why metrics matter (but not how you think)
https://cloud.google.com/blog/products/identity-security/mind-your-metrics-to-achieve-better-autonomic-security-operations
成熟度不外乎 可重複> 被定義 > 可管理 > 持續優化
將處理的流程寫成SOP,接著讓程式自動化處理減少人工問題,將自動化產生的資料量化成可管理的數據,有了這些數據就能持續優化進步
Autonomic Approach to SOC: Applying SRE Lessons to Security Operations