Strategy 2: Give the SOC the Authority to Do Its Job

Strategy 2: Give the SOC the Authority to Do Its Job

Author: SANS Institute May 15, 2023 Duration: 36:51
Though a SOC is responsible for protecting your organization's assets, it is not the owner of those systems. If the SOC is not established with a clear charter and authority to act, it may quickly become difficult to be effective. Who should the SOC report to, what should be in a SOC charter, and how can we make these tough decisions? Those are the questions covered in this episode of our special "11 Strategies" season. This episode covers chapter 2 of the book - "Give the SOC the Authority t...

For security professionals tasked with defending networks, the daily challenge isn't just about responding to alerts-it's about building a resilient, intelligent defense from the ground up. Blueprint: Build the Best in Cyber Defense, from the SANS Institute, serves as an ongoing conversation for that exact purpose. This isn't a news recap; it's a deep, practical resource. Each episode connects you directly with the architects of modern security operations-those blue team leaders and seasoned experts who are actively protecting critical infrastructure and global enterprises. You'll hear candid discussions dissecting real-world defensive strategies, unpacking the nuances of emerging protocols, and evaluating new tools before they hit the mainstream. The focus is relentlessly on applied knowledge: how concepts translate into action at the console. Whether it's an interview breaking down a complex incident response or a technical deep dive explaining the mechanics of a novel attack vector, this podcast provides the substantive content needed to refine your craft. Think of it as a continuous learning feed, offering the detailed explanations and practitioner insights that help you construct a more effective security posture, one informed decision at a time. Tune in to Blueprint for the kind of forward-looking, foundational knowledge that defines a career in cyber defense.
Author: Language: en-us Episodes: 50

Blueprint: Build the Best in Cyber Defense
Podcast Episodes
AJ Yawn: Cloud, Compliance and Automating Security [not-audio_url] [/not-audio_url]

Duration: 55:59
Compliance and audit checks can be painful, and that's before you introduce additional cloud services and technology. In this episode featuring AJ Yawn we discuss some incredibly useful and actionable cloud security conc…
Jamie Williams: Adversary Emulation [not-audio_url] [/not-audio_url]

Duration: 49:01
There are numerous ways to test your SOC's detection and prevention capabilities, but not all are created equal. Each has their own strengths and weaknesses, and can be done on a different time scale.This week, we focus…
Josh Johnson: PowerShell and Defensive Automation for the Blue Team [not-audio_url] [/not-audio_url]

Duration: 48:39
PowerShell may seem intimidating, but it can be one of the most amazing and useful tools at your disposal...if you know how to use it. In this episode, we have Josh Johnson, author of the new SANS course "SEC586: Blue Te…
Chris Baker: Get A Handle On Your Vulnerabilities [not-audio_url] [/not-audio_url]

Duration: 39:47
This episode is all about vulnerability management - both the technical and human aspects. Looking to start up a new vulnerability management team? Drowning in vulnerabilities to fix and don't know where to start? Strugg…
Anton Chuvakin: The Current State and Future of Security Operations [not-audio_url] [/not-audio_url]

Duration: 47:07
In today’s episode, John is joined by Anton Chuvakin to discuss current and future security operations technology, which tools are the most important and which are becoming less important over time, the rules of automati…