{
  "version": "Notebook/1.0",
  "items": [
    {
      "type": 1,
      "content": {
        "json": "# Security Operations is a Team Sport\n\nWhat is the strength of your Relationships between the following Pillars of your current Security Operations?\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/SOCTeamSport.png?raw=true)\n\n| Security Operations | Strength | Your Organizations Strength |\n| : | : | : |\n| Leadership | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Major Incident Management | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Threat Intelligence | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Triage | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Investigation | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n| Hunt | 1. Strong Relationship <br> 2. Medium Relationship <br> 3. Light Relationship | [Your Answer Goes Here.] |\n\n**Wondering where to start??** <br>\nWe recommend the Rapid Modernization Plan, or (**RaMP**) for short.\n\n### SOC Rapid Modernization Plan (RaMP)\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/RaMP.png?raw=true)\n\n### SOC Growth Path of Security Operations\n\nThis is a general growth path and may vary for your organization.\n\nAll of it may not be needed for the risk profile of your organization. You may use outsourcing as a substitute (i.e. MSSP) for all or part of this (or as an assisted build of an in house capability).\n\n**Note**: The team size you need should be based on certain considerations and can be found in the capacity planning section.\n\nThe goals and business integration of a SOC should be integrated as early as possible.\n\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/SOCGrowthPath.png?raw=true)\n\n### Building a SOC Team - Step 1\n\nStart with Two Part-Time staff that will support multiple Security Operational Roles starting out. Below is a diagram outlined with **Triage** and **Investigation** where these (2) members of your Security Org will work towards improving Alert Quality and Efficiancy while using the following Tooling to start:\n\n- EDR\n- Email\n- Identity\n\n![](https://github.com/rinure-msft/Azure-Sentinel/blob/master/docs/PartTimeStaff.png?raw=true)\n"
      },
      "name": "text - 2"
    }
  ],
  "fallbackResourceIds": [
    ""
  ],
  "fromTemplateId": "sentinel-Building_a_SOCPartTimeStaff",
  "$schema": "https://github.com/Microsoft/Application-Insights-Workbooks/blob/master/schema/workbook.json"
}
