Now each ISPD needs to be connected to the SOC?

Probably, many of you saw in the media at the end of December 2020 headlines like "About 100 new laws signed" and perhaps even read compilations of new rules changes from various spheres of life, coming into force on January 1, 2021.





30.12.2020 №515- « - ». – - , ( ) SOC (Security Operation Center)?





, , , 6 2 19 №152- « » :





2. , :





6) , , ; ( ).





?

152- 18.02.2013 . №21, «.5»: (, ) .





, , , ( – ) ( ). «1-» , , . ( 100 000 ) ( , , ).





, , , .





, , excel- 10 20 SOC ? .





SOC?

, – , .





SOC? , .  () , (SIEM-) , , «» SIEM- .





, , SIEM-, , . 152- « », « (, ) ». « » ( ).





, - ( - WannaCry, ), - .





. , . , , . , . 6 . 13.12 .





, , .1 .2 ( ), , .





, « », :





  • ;





  • .





? «». - ? ! ? . ? , - . , , .





, , . , - , :





  • (Windows Event Log, Syslog);





  • (Windows Event Log);





  • ;





  • «» (NGFW, UTM, WAF);





  • .





SIEM-. – , , , ? , , SIEM+=SOC .





( )

, – , . 152-, , .





- , . , «» .





, . , , , . .








All Articles