Security Operations Analysis and Design

This service provides a broad-based analysis of security operations requirements and current state capabilities and recommends a solution designed to meet specific security operations and incident management objectives. It also includes an incident handling framework and next steps for the development of appropriate operational and management policies and procedures. The Security Operations Analysis and Design Service establishes your baseline for advanced security operations and can also be the first step toward a more advanced security operations program or security operations center (SOC) set of capabilities.

Based on an analysis of the business and the operational and technical requirements for an overall incident handling and data loss prevention capability, this engagement includes four primary components:

  1. A high-level review of the business requirements to support a security operations function.
  2. A detailed review of the technical and operational requirements to support a security operations function, in particular the SIEM and DLP requirements, as the core security technologies within the SOC.
  3. Reference architectures for the enVision® platform and Data Loss Prevention solutions to meet the prescribed requirements.
  4. Incident handling framework and next steps for more comprehensive solution design and operations planning.