Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Solution Architect

previous version on gdrive

SOC & SIEM Strategy Framework

This document outlines anDREa's Security Operations Center (SOC) and Security Information and Event Management (SIEM) strategy. It leverages our cloud-native tools and decentralized monitoring architecture to fulfill ISO 27001 (A.5.24 - A.5.28, A.8.15 - A.8.17) and NIS 2 (Article 21 - Incident Handling & Supply Chain Security) compliance frameworks.


1. Security Operations Center (SOC) Framework

The SOC serves as the operational center for continuous monitoring and incident response. To maintain agility as a remote-first organization, anDREa integrates SOC responsibilities directly into the Management Team (MT) and Support & Assurance functions.

Evaluation & Implementation Matrix

SOC DomainanDREa ArchitectureMaturityAuditor Notes & Opportunities
People & RolesManaged by the MT (Director, Operations Manager, Business Manager) with first-line triage supported by External Researchers.7/10Status: Responsibilities explicitly mapped via RACI.
Gap: Relies on MT availability; no standalone 24/7 analyst squad.
Incident Handling24/7/365 telemetry monitoring coupled with rigorous post-incident Root Cause Analysis (RCA) and Corrective and Preventive Actions (CAP).9/10Status: Robust containment and recovery plans.
Target: Increase frequency of tabletop simulations for non-Azure outages.
Threat IntelligenceDirect ingestion of telemetry from Microsoft Defender, NCSC CERT feeds, and upstream vendor advisory bulletins.8/10Status: Active, contextual analysis of our tech stack.
Target: Automate telemetry mapping to specific internal threat vectors.
Vulnerability MgmtStrict Patch Management SLA (72-hour turnaround for Critical patches), annual independent penetration testing, and an active Coordinated Vulnerability Discosure Policy policy.9/10Status: Automatic enforcement via Google/Azure tooling.
Target: Embed automated DAST into all software release pipelines.

2. Security Information & Event Management (SIEM) Strategy

anDREa utilizes a decentralized SIEM topology to aggregate, safeguard, and analyze system telemetry across environments without introducing single points of failure.

Technical Implementation

SIEM ComponentTechnical StrategyMaturityStrategic Context
Log AggregationCentralized collection via Azure Log Analytics (for the myDRE platform) and Drive Log Events (for Google Workspace).9/10Ingests all Entra ID, cloud resource, and administrative activity logs. Keeping Google and Azure planes separate is an explicit architectural choice.
Log ProtectionLog Analytics Workspace repositories are strictly immutable. Modification or deletion privileges are completely restricted.10/10Guarantees data integrity for forensic investigations and compliance audits.
Alerting & CorrelationReal-time monitoring and custom rule logic tracking failed MFA attempts, PIM role activations, and resource degradation.8/10Managed via native cloud security dashboards. Next step is deploying "honeypot" alerts for unauthorized data access detection.
Forensic RetentionData retention policy enforces 2 years "hot" availability and 7+ years archived for system interaction logs.9/10Engineered to exceed baseline regulatory audits and long-term compliance mandates.

3. NIS 2 Alignment & Gap Analysis

The SOC/SIEM operational model is optimized to meet the stringent security management practices required by the NIS 2 directive (specifically mapped against SC-30).

Key Compliance Enablers

  • Significant Incident Reporting Timelines: Operational procedures are explicitly tuned to the NIS 2 staggered reporting timeline:
    • Within 24 Hours: Initial Early Warning submission.
    • Within 72 Hours: Formal Incident Notification with preliminary impact assessment.
  • Asset Management & Tracking: Provisioned virtual assets (VMs and specific Workspaces) are dynamically cataloged and tracked via myDRE Insights to guarantee that configuration baselines and patch status are systematically monitored.