I've been working to modernize our Cyber Security Operation Center (SOC) response time service level objectives (SLOs). Like many organizations, we've seen the goal of the "1 : 10 : 60" which aims to have SOCs "detect" an event within 1 minute, "analyze" within 10 minutes, and "contain" within an hour. For a variety of reasons, we set less aggressive targets --- aiming at 15/60/240 minutes for these objectives. Might other organizations be willing to share/discuss their actual SLOs and target objectives for SOC performance?

644 viewscircle icon2 Comments
Sort by:
Executive Vice President, Chief Digital Officer & Head of Cybersecurity in IT Services2 years ago

For SOC services, looking at the criticality of operations, it is better to set very aggressive SLOs which are "1:5:30". This will help to contain actions against critical alerts and meet SOC performance objectives.

Chief Digital Officer in IT Services2 years ago

I have seen the “1:10:60” goal for improving SOC response times to be a popular target for many organizations. However, depending on your particular needs and resources, this target may not always be attainable. We have set less aggressive targets of 15/60/240 minutes for SOC performance, and these have worked for us in the past.

Content you might like

CIO46%

CISO42%

Other C-suite individual (please specify)8%

Difficult to say.2%

View Results

Over reach by an aggressive prosecutor ?6%

UBERs prior CEO should be the one charged ?39%

This sort of payment/use of bug bounty happens routinely ?30%

CISOs/CSOs are now on notice for the actions they take ?16%

I am going to do a deep dive on my bug bounty program immediately ?2%

Most companies do some sort of breach coverup - especially when it comes to potential IP theft?4%

View Results