DO NOT aim for SOAR playbooks for rarely used runbooks
Whenever you plan to deploy SOAR, start with building automation playbooks that are most commonly used by analysts or are critical for them to perform for SOC operations. Involve your analysts to check their day to day tasks that consume the most time. Prioritize by building them first instead of focusing on non-critical / rarely used playbooks.
Comments
Post a Comment