Outsourcing security management has gained traction among numerous organizations, often serving as the sole viable option in the absence of internal proficiency and infrastructure. The implementation of modern systems alone is no longer adequate for robust cybersecurity threat management. Managed security service providers now offer a comprehensive set of mature security monitoring and management capabilities, including security information and event management, strategic oversight of organizational governance, enterprise risk, and compliance with regulatory standards, making them a favored choice for a multitude of organizations. In an era of escalating cyber threats and data flood, the critical role of Security Operations Centers (SOCs) in safeguarding organizations' digital assets cannot be overstated. This work investigates how cybersecurity capabilities can be improved by creating and deploying a scaled-down version of Security Orchestration, Automation, and Response (SOAR) within Security Information and Event Management (SIEM) systems in Microsoft Azure environments. This setup would enable monitoring of various aspects including Network Security Group "firewall," endpoints, networks, and cloud resources. Acknowledging the mounting challenges faced by traditional security operation centers (SOC), they are overwhelmed with the ever-increasing volumes of data/alerts, while cyberattacks grow more sophisticated, often eluding conventional detection methods.
SOC, SIEM, SOAR, Logic App, Incident Response, Azure
IRE Journals:
Taofeek Olayinka Agboola , Pushkar Ogale
"A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure" Iconic Research And Engineering Journals Volume 8 Issue 5 2024 Page 1232-1239
IEEE:
Taofeek Olayinka Agboola , Pushkar Ogale
"A Mini SIEM/SOAR System for Comprehensive Cybersecurity Monitoring of Microsoft Azure" Iconic Research And Engineering Journals, 8(5)