Need help with a question Due 8/26 The security operations center (SOC) provides the foundation for a security operations program. The SOC brings

Need help with a question

Due 8/26

The security operations center (SOC) provides the foundation for a security operations program. The SOC brings together various isolated monitoring and response functions into a unified framework. The SOC is defined by the coordinated efforts of personnel, processes, and technology for identifying information security events and providing timely response and remediation.

 

Security information and event management (SIEM) is the primary tool used to support the security operations program in large enterprises. Organizations with the resources to support this type of tool can manage the SIEM as an activity within the SOC.

 

Part A: SOC Implementation Plan Presentation

Create a 12- to 14-slide, media-rich Microsoft® PowerPoint® presentation that documents the SOC implementation plan for the health care organization ’s senior leadership. The plan will also include the following requirements for implementing the SIEM portion of the SOC:

· Definition and purpose of an SOC and an SIEM (1 slide)

· Benefits of an integrated SOC and SIEM (1 slide)

· Diagram of the SOC organization illustrating each of the following 4 sections (1 slide):

· SOC Management

· Security Event & Incident Monitoring

· Event Analysis and Reporting

· Post-Incident Analysis

· Detailed information for the 4 sections listed above (8 to 10 slides); include the following for each:

· Description

· High-level functions and responsibilities

· Hardware and software required

· Resources required, including personnel for a 24/7 schedule, and security certificates required for each security position

· Recommended schedule for implementing all sections of the SOC (1 slide)

 

Note: Media-rich presentations in PowerPoint® should include such things as voiceover narration, graphics, pictures, video clips, or audio.

 

Part B: SIEM Maintenance Plan

A significant portion of SIEM is proper management of the hardware and software supporting SIEM processes and tasks.

 

Create a 3- to 4-page SIEM maintenance plan in Microsoft® Word that documents the processes for the maintenance task areas listed below. For each task or process include the following:

· Bulleted description

· Frequency in which the process must be competed

· SOC personnel required to complete the process (as defined in Part A)

 

Maintenance Task Areas:

· Process for patching operating systems for SIEM servers

· Servers are Windows Server® 2012

· Process for patching SIEM applications

· Tools that are available on the market for supporting security information and event management (SIEM) operations Process for archiving SIEM data for offline storage

· Assume 2 TBytes of data per month

· Estimate storage size required

· Estimate retention time

Share This Post

Email
WhatsApp
Facebook
Twitter
LinkedIn
Pinterest
Reddit

Order a Similar Paper and get 15% Discount on your First Order

Related Questions

follow the Instructions in the  attach Documents to complete this work. Follow the Rubric Research Report #1: Data Breach Incident Analysis and

follow the Instructions in the  attach Documents to complete this work. Follow the Rubric Research Report #1: Data Breach Incident Analysis and Report  Scenario  Padgett-Beale Inc.’s (PBI) insurance company, CyberOne Business and Casualty Insurance Ltd, sent an audit team to review the company’s security policies, processes, and plans. The auditors

Can someone complete this for me

Can someone complete this for me ? ID mSysRowId 1 ua06Ftxxo5DT29FEtU6s2GsIH4WBra7Vmm9mzoDmd4hFWmgWHD2q19Uh6gZgjcdYJD5KAfiSoqJNYPVYozboMdrWC5/boC+GqAv6ldlKwK76KrWnq6AoA9zoHkqnmH8kRWOuUZ6tXLQ=-~LyErwg/RbqxliP9sRDATWA==

  Public Key Infrastructure (PKI) is an encryption and cybersecurity architecture for managing digital certificates and communication encryption. PKI can

  Public Key Infrastructure (PKI) is an encryption and cybersecurity architecture for managing digital certificates and communication encryption. PKI can be used to ensure secure electronic transfer, provide authentication for communications requiring data integrity and stringent proof of identity. The public/private keys created as part of PKI digital certificates can