No Result
View All Result
Simon Angling
  • Home
  • About Me
  • Cyber Security
  • Productivity
  • Blog
    • Cyber Security
    • Design
    • Education
    • Learning Out Loud
    • Microsoft
    • Productivity
    • Technology
  • Contact Me
Simon Angling
  • Home
  • About Me
  • Cyber Security
  • Productivity
  • Blog
    • Cyber Security
    • Design
    • Education
    • Learning Out Loud
    • Microsoft
    • Productivity
    • Technology
  • Contact Me
No Result
View All Result
Simon Angling
No Result
View All Result
Home Cyber Security

What is Security Orchestration, Automation, and Response (SOAR)

Simon Angling by Simon Angling
May 9, 2023 - Updated on July 12, 2023
in Cyber Security, Microsoft, Technology
What is a Security Information and Event Management (SIEM)

Security Orchestration, Automation and Response (SOAR) is a collection of technologies that enable organizations to monitor, analyze, and automate response to security incidents from a single interface.

This article forms part of a series of articles that look at various acronyms used in cyber security, explain them and explore Microsoft’s solution. For more acronyms please visit: https://simonangling.com/cyber-security-acronyms

SOAR Components

  • Orchestration within SOAR connects security tools and allows for the consolidation of threat data to allow for analysis for automation and response.
  • Automation refers to the ability of a SOAR platform to automate security operations tasks and workflows. This includes automating repetitive tasks such as incident response and threat hunting.
  • Response, intricately linked with Automation, can also be seen as a SOARs ability to free up resources by automating the initial response through playbooks and allowing for a faster and often more accurate response to an ongoing threat.

Microsoft’s SOAR Solution

As discussed in What is a Security Information and Event Management (SIEM), Microsoft Sentinel is a unified Security Operations (SecOps) platform that brings together SIEM with security orchestration, automation, and response (SOAR).

Microsoft’s SIEM solution, Microsoft Sentinel, was recognized as a Leader in the 2022 Gartner Magic Quadrant for Security Information and Event Management.

2022 Gartner Magic Quadrant™ for Security Information and Event Management.
(Source: Gartner, 2022)

What is the difference between SIEM and SOAR?

Both Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) are cyber-security tools that aggregate and correlate data from multiple sources to detect and respond to threats. However, SIEM focuses on generating alerts from traditional infrastructure components, while SOAR takes in more data and automates the remediation and response process.

Both solutions are best used together, and Microsoft Sentinel is that blending of the two.

Related

Tags: Cyber Security
Previous Post

What is a Cloud Access Security Broker (CASB)?

Next Post

CIS Security Controls and Compliance

Next Post

CIS Security Controls and Compliance

Comments 1

  1. Ant A says:
    2 years ago

    I like this series, you shoukd write more… its dificult to rememeber all these sometimes. Especially since im just staring oit.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts

GTD and InBox Zero with Microsoft Outlook

Microsoft Defender Products and Licensing Demystified

What is Security Orchestration, Automation, and Response (SOAR)

Defender for Endpoint for Servers vs Defender for Cloud Server

Free Data Ingestion into Microsoft Sentinel Explained

Increasing upload_max_size in php.ini with Azure Web Apps

What is Security Orchestration, Automation, and Response (SOAR)

Azure Front Door Vanilla, Standard and Premium

What is Zero Trust, and how Microsoft implements it

Microsoft Cybersecurity Reference Architectures (MCRA) Updated

Categories

  • Africa Overland
  • Archive
  • Asides
  • Cyber Security
  • Design
  • Education
  • Learning Out Loud
  • Microsoft
  • Personal
  • Productivity
  • Quotes
  • South Africa
  • Technology
  • Travel
  • Web Development
  • Privacy Policy
  • Cookie Policy

© 2024 Simon Angling

No Result
View All Result
  • Home
  • About Me
  • Cyber Security
  • Productivity
  • Blog
    • Cyber Security
    • Design
    • Education
    • Learning Out Loud
    • Microsoft
    • Productivity
    • Technology
  • Contact Me

© 2024 Simon Angling