Building a Better SOC: Towards the Ontology for Security Operations Center Assistance and Replication (OSCAR)
• Journal Article
Publisher
Association for Computing Machinery (ACM)
DOI (Digital Object Identifier)
10.1145/3722233Topic or Tag
Abstract
There are many methods for developing a Security Operations Center (SOC) or SOC capability. However, there currently exists no unified approach which comprehensively outlines the people, processes, and technology required for developing a SOC, or how an organization might implement those into an effective SOC capability. This article outlines a data gathering process used to compile knowledge necessary for a proposed Ontology for SOC Creation Assistance and Replication, which can serve as a solution to the gap in the current body of knowledge. An ontology such as the one proposed here would leverage the collective experience of a large cadre of cybersecurity experts with deep knowledge in fields related to Security Operations and the development of SOCs. Using interview methods and analysis, the knowledge of how these experts approach the problem of creating new SOC capabilities within a set of known constraints can be captured and codified. The result is a comprehensive body of structured knowledge outlining what critical decisions are made during the process, and how those decisions affect the implementation of People, Processes, and Technology which become part of a SOC. It is this body of knowledge which can be organized and presented as a formal ontology.
This work was published in the Journal Digital Threats: Research and Practice (Vol. 6, No.1, March 2025).