SOC & SIEM Strategy Framework
This document outlines anDREa's Security Operations Center (SOC) and Security Information and Event Management (SIEM) strategy. It leverages our cloud-native tools and decentralized monitoring architecture to fulfill ISO 27001 (A.5.24 - A.5.28, A.8.15 - A.8.17) and NIS 2 (Article 21 - Incident Handling & Supply Chain Security) compliance frameworks.
1. Security Operations Center (SOC) Framework
The SOC serves as the operational center for continuous monitoring and incident response. To maintain agility as a remote-first organization, anDREa integrates SOC responsibilities directly into the Management Team (MT) and Support & Assurance functions.
Evaluation & Implementation Matrix
| SOC Domain | anDREa Architecture | Maturity | Auditor Notes & Opportunities |
|---|---|---|---|
| People & Roles | Managed by the MT (Director, Operations Manager, Business Manager) with first-line triage supported by External Researchers. | 7/10 | Status: Responsibilities explicitly mapped via RACI. Gap: Relies on MT availability; no standalone 24/7 analyst squad. |
| Incident Handling | 24/7/365 telemetry monitoring coupled with rigorous post-incident Root Cause Analysis (RCA) and Corrective and Preventive Actions (CAP). | 9/10 | Status: Robust containment and recovery plans. Target: Increase frequency of tabletop simulations for non-Azure outages. |
| Threat Intelligence | Direct ingestion of telemetry from Microsoft Defender, NCSC CERT feeds, and upstream vendor advisory bulletins. | 8/10 | Status: Active, contextual analysis of our tech stack. Target: Automate telemetry mapping to specific internal threat vectors. |
| Vulnerability Mgmt | Strict Patch Management SLA (72-hour turnaround for Critical patches), annual independent penetration testing, and an active Coordinated Vulnerability Discosure Policy policy. | 9/10 | Status: Automatic enforcement via Google/Azure tooling. Target: Embed automated DAST into all software release pipelines. |
2. Security Information & Event Management (SIEM) Strategy
anDREa utilizes a decentralized SIEM topology to aggregate, safeguard, and analyze system telemetry across environments without introducing single points of failure.
Technical Implementation
| SIEM Component | Technical Strategy | Maturity | Strategic Context |
|---|---|---|---|
| Log Aggregation | Centralized collection via Azure Log Analytics (for the myDRE platform) and Drive Log Events (for Google Workspace). | 9/10 | Ingests all Entra ID, cloud resource, and administrative activity logs. Keeping Google and Azure planes separate is an explicit architectural choice. |
| Log Protection | Log Analytics Workspace repositories are strictly immutable. Modification or deletion privileges are completely restricted. | 10/10 | Guarantees data integrity for forensic investigations and compliance audits. |
| Alerting & Correlation | Real-time monitoring and custom rule logic tracking failed MFA attempts, PIM role activations, and resource degradation. | 8/10 | Managed via native cloud security dashboards. Next step is deploying "honeypot" alerts for unauthorized data access detection. |
| Forensic Retention | Data retention policy enforces 2 years "hot" availability and 7+ years archived for system interaction logs. | 9/10 | Engineered to exceed baseline regulatory audits and long-term compliance mandates. |
3. NIS 2 Alignment & Gap Analysis
The SOC/SIEM operational model is optimized to meet the stringent security management practices required by the NIS 2 directive (specifically mapped against SC-30).
Key Compliance Enablers
- Significant Incident Reporting Timelines: Operational procedures are explicitly tuned to the NIS 2 staggered reporting timeline:
- Within 24 Hours: Initial Early Warning submission.
- Within 72 Hours: Formal Incident Notification with preliminary impact assessment.
- Asset Management & Tracking: Provisioned virtual assets (VMs and specific Workspaces) are dynamically cataloged and tracked via myDRE Insights to guarantee that configuration baselines and patch status are systematically monitored.