As a commitmenttoclosingthecybersecurityworkforcegapbycreatingmulti-domaincybertechnicians, ECCouncilpledges $3.5 milliontowardsCCTeducationandcertificationscholarshiptocertifyapproximately 10,000 cyberprofessionalsreadytocontributetotheindustry.
Soanotherareathatyouwanttolookatas a securityoperationsleaderisatsomepointtocreate a charterandwritedownyourroles, yourresponsibilities, andreallythelimitsofwhattheSOCcando.
So, youleveragethisworkyoudoas a leaderputtingthistogethertoprioritizewhatyouworkon, whetherit's addingnewcapabilitiestotheSOC, suchasdetectionengineering, orhowyourespond.
Soandin a morematureorganization, notsaying a largerorganization, again, thiscouldjustbe a fewpeople, youneedtostartincorporatingthreatintelligencetofocusthelimitedresourcesthatwehaveonthelargestthreatprofiles.
Soyoushouldhave a processofdoingthreathuntingagainstthatthreatintelligencedatatobetterunderstandandbuild a threatproductsoyouknowwhatyourenvironmentisandoryourcustomers.
Perfectexample I alsogiveisbuild a dashboardand, youknow, it's foryourcustomer, thisfictitiouscustomer, andhave a VMfireoffsomethingthatisorlookslikePSExec.
Can I see a sampleSOCplaybookand a sampleofSOCrunbook?
SOCプレイブックのサンプルとSOCランブックのサンプルを見ることはできますか?
I unfortunatelydonothavethetimetoshowexamples.
残念ながら、例をお見せする時間がない。
Sothebasicdifferencebetween a playand a runbookandhowyouwouldwanttoconstructthemistheplaybookyouwanttobuildoutastheoverarchingresponsetohowyouhandle, let's say, just a campaign.