Abstract

Security Operation Center represents nowadays an indispensable component of the socio-technical system by supporting businesses to protect their security and ensure the confidentiality, integrity, and availability against cyberthreats and security attacks.The Security Operation Center provides various service levels and capabilities that need to be continuously assessed and tracked to ensure improvement of the main success factor of the SOC, which include technologies, processes, and SOC analysts. SOC analysts’ performance evaluation remains problematic due to the choice of the performance metrics and their inadequacy with the SOC socio-technical system. While we have some quantitative and qualitative measures to assess the performance of a SOC analyst, SOC capabilities, and SOC maturity levels, this evaluation is based on root cause analysis and independent evaluation of SOC elements, which is unrealistic, given the complex and evolving nature of SOC systems. However, the baselines of the performance metrics are the SOC challenges announced by the SOC analysts and their ability to face, reduce, and overcome them to provide and maintain a high detection rate of malicious and abnormal behaviors. We provide a comprehensive overview of the challenges faced by SOC analysts based on our previous study, and we provide a deep analysis of the challenges and the interconnexion of those challenges. Furthermore, we present the quantitative performance metrics and their weaknesses to assess the performance of the SOC analysts due to the SOC socio-technical system nature. Our study will enable SOC managers, analysts, and decision-makers to have clear visibility and details on the quantitative performance metrics and will provide a baseline for a new performance metrics model.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call