Cloud Security Podcast by Google

EP73 Your SOC Is Dead? Evolve to Output-driven Detect and Respond!


Listen Later

Guest:

  • Erik Bloch,  Senior Director of Detection and Response at Sprinklr

Topics:

  • You recently coined a concept of “output-driven Detection and Response” and even perhaps broader “output-driven security.” What is it and how does it work?
  • Detection and response is alive (obviously), but sometimes you say SOC is dead, what do you mean by that?
  • You refer to a federated approach for Detection and Response”  (“route the outcomes to the teams that need them or can address them”), but is it workable for any organization? 
  • What about the separation of duty concerns that some raise in response to this? What about the organizations that don’t have any security talent in those teams?
  • Is the approach you advocate "cloud native"? Does it only work in the cloud? Can a traditional, on-premise focused organization use it?
  • The model of “security team as a decision-maker, not an implementer” has a bit of a painful history, as this is what led to “GRC-only teams” who lack any technical knowledge. Why will this approach work this time?

Resources:

  • “RIP SOC. Hello D-IR”
  • “Kill your SOC with a D-IR model”
  • “Security De-Engineering: Solving the Problems in Information Risk Management” book
  • “A SOCless Detection Team at Netflix” 
  • “Achieving Autonomic Security Operations: Automation as a Force Multiplier” 
  • “Start with Why: How Great Leaders Inspire Everyone to Take Action“ book
  • “Think Like a Monk: The Secret of how to Harness the Power of Positivity and be Happy Now” book
  • “On “Output-driven” SIEM”
  • “SOC is Not Dead: How to Grow and Develop Your SOC for Cloud and Beyond” (ep58)
...more
View all episodesView all episodes
Download on the App Store

Cloud Security Podcast by GoogleBy Anton Chuvakin

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

38 ratings


More shows like Cloud Security Podcast by Google

View all
Risky Business by Patrick Gray

Risky Business

363 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

633 Listeners

The Cloudcast by Massive Studios

The Cloudcast

154 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

371 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,008 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

199 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

314 Listeners

Click Here by Recorded Future News

Click Here

389 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

142 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

182 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Hacking Humans by N2K Networks

Hacking Humans

312 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

76 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

120 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners