The metrics killing your SOC, and what to use instead
Security operations centres risk being rendered entirely ineffective if organizations measure them using the wrong performance indicators, according to Dave Chismon, CTO for Architecture at UK’s National Cyber Security Centre. Ticket-based metrics miss the point Evaluating ones’ SOC using the same ticket-based metrics applied to IT service desks can actively work against its core purpose: detecting and responding to real attacks. The problem, Chismon explains, is one of perverse incentives: When SOC analysts are measured … More
The post The metrics killing your SOC, and what to use instead appeared first on Help Net Security.