Mutemwa, MuyowaMtsweni, Jabu S2023-01-032023-01-032022-03Mutemwa, M. & Mtsweni, J.S. 2022. A cybersecurity architecture that supports effective incident response. <i>Journal of Information Warfare.</i> http://hdl.handle.net/10204/125661445-33121445-3347http://hdl.handle.net/10204/12566A Cybersecurity Operation Centre (SOC) is a centralized hub within an organisation that houses people, processes, and technologies aimed at continuous monitoring of the organization’s assets in order to prevent, detect, analyse, and respond to cybersecurity incidents against that organisation. SOCs are critical to the collection, analysis, and response to cybersecurity events and incidents faced by an organisation. This article discusses the architecture of an SOC that enables quick and timely responses to events and incidents. Firstly, the article describes an architecture of the SOC, the SOC’s processes, personnel, and technologies. Secondly, the article discusses what type of information and logs should be collected, analysed, and interpreted. Lastly the article discusses how to handle an incident through the six stages of incident response.AbstractenCybersecurityCyber threatsEvent LogsSecurity Operating CentreThreat ActorsA cybersecurity architecture that supports effective incident responseArticleMutemwa, M., & Mtsweni, J. S. (2022). A cybersecurity architecture that supports effective incident response. <i>Journal of Information Warfare</i>, http://hdl.handle.net/10204/12566Mutemwa, Muyowa, and Jabu S Mtsweni "A cybersecurity architecture that supports effective incident response." <i>Journal of Information Warfare</i> (2022) http://hdl.handle.net/10204/12566Mutemwa M, Mtsweni JS. A cybersecurity architecture that supports effective incident response. Journal of Information Warfare. 2022; http://hdl.handle.net/10204/12566.TY - Article AU - Mutemwa, Muyowa AU - Mtsweni, Jabu S AB - A Cybersecurity Operation Centre (SOC) is a centralized hub within an organisation that houses people, processes, and technologies aimed at continuous monitoring of the organization’s assets in order to prevent, detect, analyse, and respond to cybersecurity incidents against that organisation. SOCs are critical to the collection, analysis, and response to cybersecurity events and incidents faced by an organisation. This article discusses the architecture of an SOC that enables quick and timely responses to events and incidents. Firstly, the article describes an architecture of the SOC, the SOC’s processes, personnel, and technologies. Secondly, the article discusses what type of information and logs should be collected, analysed, and interpreted. Lastly the article discusses how to handle an incident through the six stages of incident response. DA - 2022-03 DB - ResearchSpace DP - CSIR J1 - Journal of Information Warfare KW - Cybersecurity KW - Cyber threats KW - Event Logs KW - Security Operating Centre KW - Threat Actors LK - https://researchspace.csir.co.za PY - 2022 SM - 1445-3312 SM - 1445-3347 T1 - A cybersecurity architecture that supports effective incident response TI - A cybersecurity architecture that supports effective incident response UR - http://hdl.handle.net/10204/12566 ER -26310