Showing posts with label SOC. Show all posts
Showing posts with label SOC. Show all posts

Wednesday, December 20, 2017

Smart Home / IoT, Threat & Vulnerability Management (TVM) & B2C Delineation for Vendors

As the smart home becomes a reality (https://www.theverge.com/2017/12/20/16799918/homekit-vulnerability-details) so does the need to monitor & patch said smart home.

But, who from a vendor standpoint will own that market / responsibility (ISPs, Utilities, Alarm / Physical Security, AV software vendors, separate vendors: Amazon / Apple / Google / Staples: Geek Squad, B2C MSSPs / SOCs)?

The answer will vary depending on the jurisdiction / age of the house, though this wrestling match is sure to come.

So, wait & see how this shakes out, because change is coming for sure.

Sunday, January 15, 2017

How Many Threat Intelligence (TI) Feeds Are Enough?

MSSPs aside (as they can more easily achieve economies of scale), how many TI feeds should an internal SOC leverage?

Well, that depends on the quality of information.  With that said, several open source & commercial / subscription feeds would not hurt for cross-reference purposes.

Here are some feeds worthy of consideration:

  • US-CERT
  • CTIN
  • Optiv
  • Facebook ThreatExchange
  • Crowstrike
  • AlienVault
  • SSLBL
  • ZeuS Tracker
  • Palevo Tracker
  • Malc0de
  • Binary Defense Systems
  • Carbon Black / Bit9
  • ThreatQuotient
  • Anomali / ThreatStream
  • ThreatConnect

Wednesday, August 31, 2016

Consolidate Internal Identity Stores BEFORE Focusing on Cloud-based SSO / IAM

There is a tendency to focus on the shiny objects, and many orgs have a cloud-first mentality, but there is no reason to ignore the multitude of internal identity stores that exist in most large enterprises.

SSO, SAML, etc. are great, but what about LDAP, AD, etc.?  How about de / provisioning, especially with your vendors (e.g., SOC / MSSP, NOC / MSP, ITO, BPO)?

Friday, August 26, 2016

Are open-source SIEMs worth it?

Between SIEMonster, ELK, & OSSIM, there are several options out there for open-source SIEMs.

But, is the juice worth the squeeze?

Between cloud first strategies for SMBs & enterprises (many CSPs / IaaS providers offer add-on SIEM / ATP services), as well as the prevalence of MSSPs / SOCs, one may wonder if open-source SIEMs will ever hit critical mass?

Regardless, someone keeps building these solutions.  So, there is demand.  Also, startups may want to crawl before they sprint regarding TVM & SecEng.