{
  "version": "Notebook/1.0",
  "items": [
    {
      "type": 1,
      "content": {
        "json": "# Security Operations is a Team Sport\n\nWhat is the strength of your Relationships between the following Pillars of your current Security Operations?\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/SOCTeamSport.png?raw=true)\n\n| Security Operations | Strength | Your Organizations Strength |\n| : | : | : |\n| Leadership | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Major Incident Management | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Threat Intelligence | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Triage | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Investigation | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Hunt | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n\n**Wondering where to start??** <br>\nWe recommend the Rapid Modernization Plan, or (**RaMP**) for short.\n\n### SOC Rapid Modernization Plan (RaMP)\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/RaMP.png?raw=true)\n\n### SOC Growth Path of Security Operations\n\nThis is a general growth path and may vary for your organization.\n\nAll of it may not be needed for the risk profile of your organization. You may use outsourcing as a substitute (i.e. MSSP) for all or part of this (or as an assisted build of an in house capability).\n\n**Note**: The team size you need should be based on certain considerations and can be found in the capacity planning section.\n\nThe goals and business integration of a SOC should be integrated as early as possible.\n\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/SOCGrowthPath.png?raw=true)\n\n### Building a SOC Team - Step 3\n\nStep 3 moves your organization to a fully Operational SOC. Moving from part-time staff to full time staff, your organiztion now has the ability to focus on **Triage**, **Investigation**, and **Hunting**. As your staff improve in skill and grow, your Org can now consider separating out the Duties and Responsibilities of your Analysts. By now you should be considering the following Support Functions:\n\n- Dedicated Facility\n- Major Incident Management\n- Threat Intelligence\n- Business Intelligence/Reporting\n\nYour list of tools should also increase as you identify Gaps in Monitoring, Data, and Services that need to be onboarded. Should include the following from the list below:\n\n- EDR\n- Email\n- Identity\n- SIEM\n- Case Management\n- Networking\n- Application Security Broker\n- Cloud Defense for IAAS, SAAS, PAAS and IOT Devices\n\nIn Addition to the Tools highlighted, your processes and procedures should start to be managed while you incorporate some Reporting for KPI's and Metrics to measure how your Staff are performing.\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/FullTimeStaff_mediumteam.png?raw=true)"
      },
      "name": "text - 2"
    }
  ],
  "fallbackResourceIds": [
    ""
  ],
  "fromTemplateId": "sentinel-Building_a_SOCMediumStaff",
  "$schema": "https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json"
}
