A systematic method for measuring the performance of a cyber security operations centre analyst

A systematic method for measuring the performance of a cyber security operations centre analyst
复制标题

衡量网络安全运营中心分析师绩效的系统方法

DOI:
10.1016/j.cose.2022.102959
复制
发表时间:
2023
影响因子:
5.6
通讯作者:
Agyepong E
Agyepong E
中科院分区:
计算机科学3区
文献类型:
--
作者:
Agyepong E

文献摘要

参考文献

被引文献

相似文献

在安全运营中心 (SOC) 工作的分析师在支持企业保护其计算机网络免受网络攻击方面发挥着重要作用。为了高效、有效地管理分析师,SOC 经理和利益相关者使用关键绩效指标 (KPI) 来评估他们的绩效。然而,现有文献表明缺乏评估分析师绩效的系统方法。尽管网络安全研究人员提倡对这一领域进行研究,但研究人员几乎没有为解决这一差距做出任何努力。本文借鉴行业专家德尔福小组的结果以及层次分析法 (AHP) 的原理,探讨了这个问题,并提出了一种系统加权方法来衡量 SOC 分析师的绩效。所提出的方法称为 SOC 分析师评估方法 (SOC-AAM),作为实验案例研究的一部分在两个 SOC 中进行了评估。实证评估结果表明,SOC-AAM 使 SOC 管理者和利益相关者能够系统地量化和评估分析师的绩效。 SOC-AAM 还提供了评估事件分析质量和事件报告质量的新颖指南。寻求了解 SOC 分析师操作的从业者和网络安全研究人员会对这项研究感兴趣。
Analysts who work in a Security Operations Centre (SOC) play an essential role in supporting businesses to protect their computer networks against cyber attacks. To manage analysts efficiently and effectively, SOC managers and stakeholders use Key Performance Indicators (KPIs) to evaluate their performance. However, existing literature suggests a lack of a systematic approach for assessing analysts’ performance. Even though cyber security researchers advocate for research into this area, little effort has been made by researchers to address this gap. Drawing on the results of a Delphi panel with industry experts and the principles of the Analytic Hierarchy Process (AHP), this paper interrogates the problem and proposes a systematic weighted approach for measuring the performance of an analyst in a SOC. The proposed method, referred to as a SOC Analyst Assessment Method (SOC-AAM), was evaluated in two SOCs as a part of an experimental case study. The results of the empirical evaluation show that the SOC-AAM enables SOC managers and stakeholders to quantify and assess analysts’ performance in a systematic manner. The SOC-AAM also provides a novel guideline for assessing the quality of incident analysis and the quality of incident reports. This study will be of interest to practitioners and cyber security researchers seeking to understand the operations of a SOC analyst.
设计用于网络安全监控的语音系统的形式化方法
DOI: --
发表时间: 2017
期刊:
影响因子: --
作者:
Louise Axon;Jason R. C. Nurse
通讯作者: Jason R. C. Nurse
基于层次分析法的计算机风险管理有效安全意识新评价标准
DOI: --
发表时间: 2012
期刊:
影响因子: --
作者:
Nasrin Badie;Arash Habibi Lashkari
通讯作者: Arash Habibi Lashkari
关于可配置参考流程模型的用户感知 - 初步见解
DOI: --
发表时间: 2005
期刊: ACIS
影响因子: --
作者:
J. Recker;M. Rosemann;Wil M.P. van der Aalst
通讯作者: Wil M.P. van der Aalst
DOI: --
发表时间: 2018
影响因子: 2
作者:
N. Miloslavskaya
通讯作者: N. Miloslavskaya
安全运营中心 (SOC) 中的人为因素能力
DOI: --
发表时间: 2021
期刊: EDPACS: The EDP Audit, Control, and Security Newsletter
影响因子: --
作者:
Samir Achraf Chamkar;Yassine Maleh;Noreddine Gherabi
通讯作者: Noreddine Gherabi