Skip to content

Latest commit

 

History

History
176 lines (145 loc) · 11 KB

hr_training.md

File metadata and controls

176 lines (145 loc) · 11 KB

SOC HR and training

This page deals with SOC HR and training topics.

ToC

Must read

  • MITRE, 11 strategies for a world-class SOC, Strategy 4, pages 101-123

image

HR roles and organization

As per what is explained on the management page, I would recommend to make sure the following roles are being assigned to people:

  • SOC analyst;
  • SOC analyst senior;
  • SOC detection engineer;
  • Threat intel analyst;
  • Threat intel lead (if several analysts)
  • SIEM expert and data scientist;
  • Pentester (offensive team);
  • Incident handler;
  • Incident manager;
  • SOC/CSIRT tools admin;
  • SecDevOps analyst;
  • SOC/CERT/CSIRT deputy manager.

They can be FTE or outsourced, it will depend on your needs and constraints. My recommendations are explained in the RACI template that I propose.

Recommended SOC trainings

Regular trainings

Certifications

Recommended CERT/CSIRT trainings

Regular trainings

Certifications

Recommended offensive security trainings

NB: this is for red/purpleteaming activities.

Regular trainings

Certifications

  • Offensive Securiy OSCP.
  • SANS, SEC565: Red Team Operations and Adversary Emulation.
  • SANS, SEC760: Advanced Exploit Development for Penetration Testers.
  • SANS, SEC699: Purple Team Tactics - Adversary Emulation for Breach Prevention & Detection.
  • SANS, SEC541: Cloud Security Attacker Techniques, Monitoring, and Threat Detection.

Recommended management trainings

Certifications

To go further

End

Go to main page.