Building a large scale Security Operations Centre

Liviu Valsan (CERN)


The HEP community is facing an ever increasing wave of computer security threats, with more and more recent attacks showing a very high level of complexity. Having a centralised Security Operations Centre (SOC) in place is paramount for the early detection and remediation of such threats. Key components and recommendations to build an appropriate monitoring and detection Security Operation Centre will be presented, as well as means to obtain and share relevant and accurate threat intelligence information. The presentation concludes that the key to achieve an appropriate response is to both build an efficient security infrastructure and a tight international collaboration, enabling information to be shared globally with trusted partners, and in particular between the various HEP sites.
