SOAR (Security
Orchestration, Automation and Response) is a genre of compatible software
programs that allow an organization to collect data about security threats from
multiple sources and respond to low-level security events without human
assistance. The term, which was coined by the research firm Gartner, can be
applied to compatible products and services that help define, prioritize,
standardize and automate incident response functions.
The goal of using a
SOAR software stack is to improve the efficiency of physical and digital
security operations by merging threat and vulnerability management, security
incidence response and security operations automation. According to Gartner,
the three most important capabilities of SOAR technologies are:
Threat and vulnerability management: These technologies support the remediation of
vulnerabilities. They provide formalized workflow, reporting and collaboration
capabilities.
Security incident response: These technologies support how an organization
plans, manages, tracks and coordinates the response to a security incident.
Security operations automation: These technologies support the automation and
orchestration of workflows, processes, policy execution and reporting.
Security
orchestration, automation and response (SOAR) programs offer an alternative
means for addressing the cybersecurity skills gap by reducing the amount of
work that requires human intervention. While both security information and
event management (SIEM) and SOAR stacks aggregate relevant data from multiple
sources, SOAR services integrate with a wider range of internal and external
applications and are useful for spotting patterns of attack as well as isolated
occurrences.
Comments
Post a Comment