07.07.2015 Views

Cyber-Security-Monitoring-Guide

Cyber-Security-Monitoring-Guide

Cyber-Security-Monitoring-Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Cyber</strong> <strong>Security</strong> <strong>Monitoring</strong> and Logging <strong>Guide</strong>Professional SOC qualificationsThere are many different professional qualifications available for a range of technical security services, such as penetrationtesting and cyber security incident response. However, there are few, if any, available for the provision of <strong>Security</strong>Operations Centres or the analysts they employ.Analysis of responses to the project survey showed strong support for suppliers of SOC (and NOC) services to be supportedby professional qualifications, accreditation and a code of conduct – as outlined by the high average responses shown inthe table below (scores are shown as a possible rating of 1 to 5).Requirement SOC-related NOC-relatedHolding a professional certification (similar to that used by CREST for theproviders of penetration testing and cyber security incident response services)3.73 3.41Employing individuals with professional qualifications 3.67 3.26Being supported by a professional code of conduct (eg. to gain assuranceover the quality and integrity of services provided and to administer anindependent problem resolution process)3.52 3.24In some cases, professional services companies are accredited to particular codes of conduct, but do not use qualifiedindividuals to conduct cyber security monitoring services, so the required quality of cyber security monitoring may not beachieved. In other cases, an individual may be qualified but not work for an accredited organisation, meaning that thereare fewer assurances about the protection of confidential information or the overall quality of the service provided - andany complaint may be difficult to resolve.The optimum combination is shown in the green box in Figure 10 below. This is the only combination that provides youwith a tangible level of protection should things go wrong – and also reduces the likelihood of a problem occurring in thefirst place.INDIVIDUALQualifiedindividualUnaccredittedorganisationUnqualifiedindividualUnaccredittedorganisationQualifiedindividualAccredittedorganisationUnqualifiedindividualAccreditted organisationORGANISATIONFigure 10: Combinations of accreditation for organisations and the individuals they employProject research identified that there are some existing qualifications and learning options available (eg. SANS) that willneed to be examined and contextualised.41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!