Summary
Poor metrics can render a well-intentioned security operation centre entirely ineffective. Security operation centres (SOCs) are a key defence in organisations, where skilled analysts use tools to hunt for attacks in the haystacks of logs. Unsurprisingly, SOCs are usually expensive to run, with costs that include staff, licenses and storage. As both an important defence and a pricey one, organisations are understandably keen to measure and assess SOC performance, whether the SOC is internal or outsourced. As SOCs typically use ticketing processes to track the handling of detections and incidents, a common approach is to evaluate a SOC's effectiveness by using the same key performance indicators (KPIs) or service level agreements (SLAs) used by other ticket-centric IT departments, such as IT service desks, customer support, or development teams. This will typically include measures like ‘number of tickets processed’ and ‘time taken to close a ticket’.