Security Operations Centers for Information Security Incident Management

被引:13
|
作者
Miloslayskaya, Natalia [1 ]
机构
[1] Natl Res Nucl Univ MEPhI, Moscow Engn Phys Inst, Moscow, Russia
来源
2016 IEEE 4TH INTERNATIONAL CONFERENCE ON FUTURE INTERNET OF THINGS AND CLOUD (FICLOUD 2016) | 2016年
关键词
information security; information security incidents; Internet of Things; information security monitoring; Security Operations Center;
D O I
10.1109/FiCloud.2016.26
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
At present information security (IS) incidents have become not only more numerous and diverse but also more damaging and disruptive. Preventive controls based on the IS risk assessment results decrease the majority but not all the IS incidents. Therefore, an IS incident management system is necessary for rapidly detecting IS incidents, minimizing loss and destruction, mitigating the vulnerabilities that were exploited and restoring the Internet of Things infrastructure (IoTI), including its IT services. These systems can be implemented on the basis of a Security Operations Center (SOC). Based on the related works a survey of the existing SOCs, their mission and main functions is given. The SOCs' classification as well as the key indicators of IS incidents in IoTI are proposed. Some serious first-generation SOCs' limitations are defined. This analysis leads to the main area of further research launched by the author.
引用
收藏
页码:131 / 138
页数:8
相关论文
共 50 条
  • [1] Security concerns towards Security Operations centers
    Janos, Feher David
    Nguyen Huu Phuoc Dai
    2018 IEEE 12TH INTERNATIONAL SYMPOSIUM ON APPLIED COMPUTATIONAL INTELLIGENCE AND INFORMATICS (SACI), 2018, : 273 - 278
  • [2] Information security incident management: Planning for failure
    Line, Maria B.
    Tondel, Inger Anne
    Jaatun, Martin G.
    2014 8TH INTERNATIONAL CONFERENCE ON IT SECURITY INCIDENT MANAGEMENT & IT FORENSICS (IMF 2014), 2014, : 47 - 61
  • [3] Operations Management of Information Security at Enterprise Levels
    Kuokkanen, Pertti
    PROCEEDINGS OF THE 9TH EUROPEAN CONFERENCE ON INFORMATION WARFARE AND SECURITY, 2010, : 160 - 167
  • [4] Shared Situational Awareness in Information Security Incident Management
    Padayachee, Keshnee
    Worku, Elias
    2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 479 - 483
  • [5] Information security incident response
    BSkyB
    Netw. Secur., 2007, 12 (10-13):
  • [6] Information Security Incident Forecasting
    Saurenko, T. N.
    Anisimov, V. G.
    Anisimov, E. G.
    Kasatkin, V. V.
    Los, V. P.
    AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2021, 55 (08) : 903 - 907
  • [7] Information Security Incident Forecasting
    T. N. Saurenko
    V. G. Anisimov
    E. G. Anisimov
    V. V. Kasatkin
    V. P. Los’
    Automatic Control and Computer Sciences, 2021, 55 : 903 - 907
  • [8] Enhancing Collaboration Between Security Analysts in Security Operations Centers
    Cremilleux, Damien
    Bidan, Christophe
    Majorczyk, Fredeic
    Prigent, Nicolas
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, 2019, 11391 : 136 - 142
  • [9] Security Operations Management
    Jim Calder
    Security Journal, 2002, 15 (4) : 75 - 76
  • [10] Information Security Considerations for Protecting NASA Mission Operations Centers (MOCs)
    Takamura, Eduardo
    Mangum, Kevin
    Wasiak, Fran
    Gomez-Rosa, Carlos
    2015 IEEE AEROSPACE CONFERENCE, 2015,