August 27, 2019 Kumar Saurabh
If you’re a CISO who has invested in a SOAR (Security Orchestration, Automation and Response) platform, you might be wondering if you’ve actually made your organization safer. Sure, you’ve deployed the SOAR platform and integrated it with your key security tools like your firewall and your IDS system. The platform is running playbooks (scripts of commands to collect and act on alert data), and it’s providing the security analysts in your Security Operations Center (SOC) with information for alert triage and threat detection.
But is your SOAR platform really helping your SOC team detect and resolves threats more quickly? If so, how can you tell? Can you measure the improvement? If someone asks, can you provide hard numbers to demonstrate the platform’s effectiveness?
What I’d like to offer you here is a methodology for measuring outcomes of your use of SOAR platform. If the outcomes are great, this methodology will make that clear. And if they aren’t great yet, this methodology will give you guidelines for making incremental improvements that yield better results over time.
If you adopt this iterative methodology and use it to focus your SOAR platform on the right things, you should see improvements in Mean Time to Resolution (MTTR) and overall SOC productivity—goals that should be appreciated by almost any CISO.
Measuring the Results of Your SOAR Platform
Let’s begin.
This methodology requires a SOAR platform, which is going to receive alerts from security tools such as a SIEM system or IDS system, possibly enrich the data associated with alerts (for example, by checking the reputation of IP addresses mentioned in alerts), and signal to the SOC team that a case or trouble ticket should be opened.
The methodology also requires a case management system, which might be popular ticketing platform like Atlassian Jira or which might be system built into your SOAR platform. When the SOC team discovers as an issue to be investigated, they’re going to open a ticket and track the case in the case management platform. When the problem is resolved, they’ll note that in the case management system and close the ticket.
The key measurement here is MTTR, which we can measure by the length of time a ticket for a particular alert remains open.
Now, it’s true that in some complex threats may involve multiple alerts, multiple incidents being tracked, and hence multiple tickets. But it’s also true that security analysts can look at these alerts and tickets individually and identify the ticket that is taking the longest to resolve.
This recognition leads to the first step in our methodology.
Now, we are going to dive one level deeper. This is a recommended technique for the Tech Lead to deliver the target efficiencies.
Conclusion: Measurements Yield Results for SOAR
Much about the methodology above is common sense. But far too often, companies fail to collect metrics and focus on improving them, in spite of investing hundreds of thousands of dollars in a security automation initiative. Or they proceed in a more haphazard way that takes many months before showing any improvements. By following the steps listed above, a security team can leverage its SOAR platform to realize measurable improvements in MTTR, strengthening the security of the organization overall.
For more information about SOAR automation or the LogicHub SOAR+ security automation platform, please contact a LogicHub security expert today.
May 20, 2022 Willy Leichter
Demystifying the technology with case studies of AI security in action Many automation tools, such...
Learn MoreMay 17, 2022 Willy Leichter
While we’ve been talking about and imagining artificial intelligence for years, it only has...
Learn MoreMay 15, 2022 Tessa Mishoe
Hello, and welcome to the latest edition of the LogicHub Monthly Update! Each month we’ll be...
Learn MoreMay 9, 2022 Tessa Mishoe
Blackcat Ransomware On April 19th of 2022, the FBI Cyber Division released a flash bulletin...
Learn MoreMay 6, 2022 Kumar Saurabh
LogicHub’s unique decision automation technology can build clients the ultimate security playbook...
Learn MoreMay 3, 2022 Kumar Saurabh
Automating a threat-hunting playbook with the help of AI Many threat-hunting playbooks we build for...
Learn MoreApril 29, 2022 Tessa Mishoe
Introduction Within the realm of security, there are many different toolsets and opinions on what...
Learn MoreApril 27, 2022 Willy Leichter
SOAR Playbooks Outside of football, the term “playbook” is well understood by a relatively small...
Learn MoreApril 21, 2022 Willy Leichter
When updating your systems from a pure Security Information Event Management (SIEM), choosing the...
Learn MoreApril 15, 2022 Tessa Mishoe
Hello, and welcome to the latest edition of the LogicHub Monthly Update! Each month we’ll be...
Learn More© 2017-2022 LogicHub®
All Rights Reserved
Privacy Policy
Terms of Use
Sitemap
© 2017-2022 LogicHub®
All Rights Reserved
Privacy Policy
Terms of Use
Sitemap