BKJIA's communication with the security management platform has ended. Many netizens have raised some good questions and helped me sort out our understanding of the security management platform. Here I will share some of my communication content with you.
BKJIA exchange excerpt 1): definition, applicability and composition of SOC
BKJIA exchange excerpt 2): Application Status of SOC
BKJIA exchange excerpt 3): application practices of SOC
User Voice 1: My Note: netizens: I have been in contact with many friends who are engaged in security O & M work. Some of them are in large companies, while others are in relatively small companies, I also asked them some questions about their work and listed them below.
1. Nothing can be done at ordinary times
Most of my friends who do security O & M tell me that their daily work is very easy, that is, they only do some basic work without any problems, for example, check the running status of the machine and perform routine maintenance on the server. However, once a problem occurs, his departure becomes very busy, and once the problem occurs, it is often related to many aspects, that is, a chain reaction. Why can't we adopt an effective early warning mechanism?
2. A wide range of devices
Some companies add devices from different manufacturers and middleware to their business needs. The management of these devices is a big problem because they come from different manufacturers, how can we quickly discover problems with these different devices and solve these problems quickly?
3. Personnel Arrangement
I think the enterprise's O & M arrangement is also a very important issue, and the O & M personnel are not arranged to handle the problem. After a problem occurs, it is difficult to quickly identify and solve the cause of the problem, or, the problem was solved on the surface, but the root problem was not solved. The result left a hidden danger for the next fault outbreak.
User VOICE 2:
For centralized network monitoring, I believe many large enterprises in China have rich experience. However, after the monitoring, the analysis, response, summary, response, and avoidance measures are provided, is there a good cycle? I'm afraid this is rare. In fact, SOC is more like a system, an architecture, and monitoring cycle management covering the network monitoring from the beginning to the implementation of countermeasures. Domestic enterprises may have every link, but they lack a platform to connect them. This is actually what SOC expresses.
It is easy to monitor, but there are reasonable and unreasonable monitoring points. We must keep reasonable monitoring, and we should discard unreasonable monitoring. Otherwise, it will seriously interfere with our judgment, it will also waste our time and energy. The same is true for the analysis. We hope that the analysis will greatly improve our monitoring efficiency. There are also solutions recommended for the analysis results, which should also be targeted and should not be given to five or six suggestions at once, which will cause interference to network O & M personnel.
My note: Netizens] The company is in the financial industry. As we all know, the financial industry's requirements for network security are almost abnormal. However, due to its demanding requirements, our network monitoring is very troublesome. For example, our network is divided into several regions, and different regions are physically isolated. Therefore, in order to achieve centralized monitoring, it is basically impossible to achieve only a small range of network monitoring in each region, but we have few employees in the financial industry), how can we maximize personnel efficiency, become our biggest problem. On the one hand, it is the demanding requirements of security, and on the other hand it is a serious shortage of manpower. Therefore, we hope that a better tool or platform can help us solve this conflict. Not only monitoring, but also analysis, suggestions, and measures, but also User-friendly interfaces and powerful report functions for the leaders to view monitoring reports ).
This article is from the "focus on security management platform" blog, please be sure to keep this source http://yepeng.blog.51cto.com/3101105/736214