Secure Operations Centers (SOC’s) were designed in the early 1970 with an attempt to thwart minor malicious codes. Well, things have changed slightly in the past 50 years! Today’s SOC provides 24 hour a day, year-round protection for key government organizations.

Somehow, this initial design has not kept up with the profusion of threat vectors and many need to be upgraded to manage today’s threats.

This is an interview with several leaders who have decades of experience in optimizing the performance of a SOC. We have experts from the Cybersecurity and Infrastructure Agency (CISA), a couple of major research laboratories, and a subject matter expert from Palo Alto Networks.

During the interview they discussed topics like tool management, the importance of standards in automation, and some help that is offered by CISA.

Humans tend to be attracted to bright, shiny things. Companies like to dangle innovation in front of commercial and federal leaders, and they tend to jump on them. Some studies show that many only use 20% of a tool’s capability. Robert Roser suggests reviewing the capabilities of existing tools before adding tolls to mange threats.

Several participants indicated that every incident may not be a threat; one should prioritize where to go next. That concept is nice in theory, but in practicality, it needs standards that lead to automation to allow the threats to be prioritized.

A SOC can get hit with thousands of alerts a day, causing operators to misidentify threats due to alert fatigue. Michael Duffy from CISA understands and lists ways that CISA can assist. He refers to the Binding Operational Directive CISA 22-01 that is designed to cut down on alert fatigue.

The threat to federal SOCs is real and the response can help everyone involved make federal systems more secure.