Is It Time for Sec-Ops?
February 23, 2012

Aruna Ravichandran
CA Technologies

If an attacker were bogging down your apps, how would you know? You wouldn't, unless you bridge the gap between ops and security.

Inspired by the teamwork that began with the Agile movement, IT organizations are tearing down walls in the service delivery process. DevOps is shortening release cycles by uniting development and delivery. But another wall stands in the way of an agile enterprise: the one between operations and security.

Most ops teams have no way of knowing when they’re dealing with an attack or a slow server. With the security and ops teams working separately, issues can take longer to identify, and longer to fix, compromising both operational performance and the security of the enterprise.

It’s time to demolish the divide between the Network Operations Center (NOC) and the Security Operations Center (SOC).

Here’s how to get started.

Step 1: Prioritize

Start with what matters most:

- Which apps or services are the most critical to your organization?

- Which ones can’t afford to have a security problem remain undiagnosed for even a few minutes?

Step 2: Collaborate with the security team

Because you’ll be shifting some responsibility from one team to another, it’s important to ensure that everyone understands why.

- Facilitate communication between the NOC and SOC teams about what they will gain by bringing security events into the NOC.

- Ensure the NOC team understands the importance of giving the SOC team visibility into certain aspects of NOC monitoring tools.

- Discuss the various tools you’ll need to accomplish this coordination and the processes you will need to create or modify.

Step 3: Identify the right monitoring tools

It’s important to look for a tool that won’t add new complexity to the NOC or its processes. The ideal tool would consolidate and correlate all events—security and operational—under a single pane of glass.

It also should:

- Provide real-time monitoring information.

- Allow for customization, so that both the SOC and NOC teams can see the information they need to see.

- Integrate security system events with the NOC's overall event management system.

- Connect security-related events with the business services they affect so you can prioritize problems when they arise.

- Identify a problem’s cause with little or no manual work.

This article is adapted from a longer article that appeared in the Discover Performance newsletter.

Aruna Ravichandran is VP, Product & Solutions Marketing, DevOps, CA Technologies
Share this

Industry News

March 29, 2023

Planview announced a new strategic collaboration with UiPath. The integration is designed to fuse the UiPath Business Automation Platform with the Planview Value Stream Management (VSM) solution Planview® Tasktop Hub.

March 29, 2023

Noname Security announced major enhancements to its API security platform to help organizations protect their API ecosystem, secure their applications, and increase cyber resilience.

March 28, 2023

Mirantis announced the latest version of Mirantis Container Cloud -- MCC 2.23 -- that simplifies operations with the ability to monitor applications performance with a new Grafana dashboard and to make updates to Kubernetes clusters with a one-click “upgrade” button from a web interface.

March 28, 2023

Pegasystems announced updates to Pega Cloud supported by an enhanced Global Operations Center to deliver a more scalable, reliable, and secure foundation for its suite of AI-powered decisioning and workflow automation solutions.

March 28, 2023

D2iQ announced the launch of DKP Gov, a new container-management solution optimized for deployment within the government sector.

March 28, 2023

StackHawk announced the availability of StackHawk Pro and StackHawk Enterprise for trial and purchase through the Amazon Web Services (AWS) Marketplace.

March 27, 2023

Octopus Deploy announced the results KinderSystems has seen working with Octopus. Through the use of Octopus, KinderSystems automates its software deployment processes to meet the complex needs of its customers and reduce the time to deploy software.

March 27, 2023

Elastic Path announced Integrations Hub, a library of instant-on, no-code integrations that are fully managed and hosted by Elastic Path.

March 27, 2023

Yugabyte announced key updates to YugabyteDB Managed, including the launch of the YugabyteDB Managed Command Line Interface (CLI).

March 23, 2023

Ambassador Labs released Telepresence for Docker, designed to make it easy for developer teams to build, test and deliver apps at scale across Kubernetes.

March 23, 2023

Fermyon Technologies introduced Spin 1.0, a major new release of the serverless functions framework based on WebAssembly.

March 23, 2023

Torc announced the acquisition of coding performance measurement application Codealike to empower software developers with even more data that increases skills, job opportunities and enterprise value.

March 23, 2023

Progress announced a free online training and certification program for Progress® OpenEdge®, the flagship Progress application development platform.

March 22, 2023

Opsera announced five patents have been issued to enable enterprise engineering leaders and teams to gain unprecedented end-to-end visibility into their software delivery and accelerate the speed and security of delivery, all while maximizing their investment.

March 22, 2023

DuploCloud announced the general availability of its on-prem solution built on top of Kubernetes, focusing on containerized workloads with near term plans to integrate with on-prem compute, storage and networking vendors.