2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security) 2020
DOI: 10.1109/cybersecurity49315.2020.9138872
|View full text |Cite
|
Sign up to set email alerts
|

Towards a Framework for Measuring the Performance of a Security Operations Center Analyst

Abstract: The past few years have seen several studies reporting on the role of a Security Operations Center (SOC) analyst and metrics for assessing the performance of analysts. However, research suggests that analysts are dissatisfied with existing metrics as they fail to take into consideration several aspects of their tasks. Existing works advocate for research into this area. A major challenge to devising adequate metrics is that the real work of analysts that needs to be taken into consideration to assess their hol… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
8
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
5
1
1

Relationship

1
6

Authors

Journals

citations
Cited by 10 publications
(8 citation statements)
references
References 18 publications
0
8
0
Order By: Relevance
“…The 2016 Global Information Security Survey notes that SOC is available in 56% of the organizations surveyed [15]. The importance of unified, consolidated cybersecurity incident prevention, detection, and response [16] [17] will grow as more companies understand [18].…”
Section: Methodsmentioning
confidence: 99%
See 1 more Smart Citation
“…The 2016 Global Information Security Survey notes that SOC is available in 56% of the organizations surveyed [15]. The importance of unified, consolidated cybersecurity incident prevention, detection, and response [16] [17] will grow as more companies understand [18].…”
Section: Methodsmentioning
confidence: 99%
“…However, security organizations are increasingly aware of the importance and significance of integrating persons, methods, and technology as an integral component of SIEM. As a result, the SOC has grown to a new level of functionality, combining people, mechanisms, and technology [15], [16]. Now SOCs can manage longer and more complex initiatives, manage thousands of warnings and incidents daily, record and track violations, and transnational coordinate practices, resolving the issue of IT harmonization.…”
Section: Methodsmentioning
confidence: 99%
“…The initial proposal and analysis of mathematical definitions of security indicators, such as «number of attacks», «minimum cost of attack», «maximum probability of attack» and even «attack surface» are given in [31]. The paper [32] proposes an initial framework for assessing system security by decomposing the system into security-sensitive components and assigning security ratings to each component. Summation of the scores of the components allows an assessment of system reliability.…”
Section: Literature Review and Problem Statementmentioning
confidence: 99%
“…Standards & Guidelines [3], [30], [36], [60], [179] Security Audits & Maturity Assessments [2], [5], [63] Metrics [23], [30], [46], [57], [68], [81], [85], [163], [180]- [186] regulations. Additionally, the SOC team can help determine the IT risks for the company.…”
Section: Governance and Compliance Referencesmentioning
confidence: 99%
“…Historical performance metrics enable comparability between work-shifts or longer time periods [68]. Agyepong et al [85] conducted an extensive survey about performance metrics for SOCs and proposed a consecutive framework [186]. Examples: False positive rate [30], [68], average analysis time [68], readiness level [81], [181], Mean Time to Detect [185] • People metrics: To improve the performance of security analysts inside a SOC it is necessary to measure human activities and workflows [68].…”
Section: ) Metricsmentioning
confidence: 99%