Im involved in a project to deploy a SIEM (Security Information Event Management) / SOC (Security Operation Center) for a customer. The current approach is to outsource the services to an external company also called a MSSP (Managed Security Services Provider). We had an interesting chat about the pro con to have an internal or external SOC. The main arguments from the company are:
- We dont have experience on board and we should hire people. And keep them on board!
- We dont know how to deploy the SIEM / SOC
- We have a limited budget (which is the 1st argument for many organizations)
Often, if not always conceded, the deployment of a SIEM is part of a long list of compliance requirements (from the business or the group the company belongs to).
Here is a small recap of the points we discussed:
| SOC | Pro | Con |
| Internal |
|
|
| External |
|
|
And you? What is your point of view? Feel free to share.
Xavier Mertens (@xme)
ISC Handler – Freelance Security Consultant
PGP Key
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.