Frequently asked questions
FAQ
Frequently asked questions
An existing deployment can be assessed for transition. We review its architecture, documentation, access, integrations, detection content, and known issues before agreeing responsibility. Any remediation needed for service acceptance is identified during this assessment.
Platform support is confirmed during discovery against the product, deployment model, integrations, and required engineering tasks. The proposal names the supported platform and scope. We do not assume that every SIEM or configuration can be covered by the same service.
SIEM management maintains and improves the monitoring platform. Managed SOC uses security telemetry and alerts to investigate suspicious activity and coordinate incidents. A client may need either service or both, depending on its existing capabilities.
SIEM management is the ongoing administration and maintenance of a security information and event management platform. It can include data integrations, ingestion health, detection rules, access, configurations, and usage reviews. The service scope identifies which components the provider manages.
Pricing reflects coverage, workload, supported tools, investigation responsibilities, governance, and required expertise. Onboarding, platform licensing, standby availability, and activated on-call work are identified separately where applicable.
The service establishes workload assumptions and escalation arrangements for unusual demand. We review increases caused by incidents, new integrations, or recurring noisy detections, then agree priorities and any required capacity or scope changes.
These activities are not automatically included in routine SOC operations. Proactive threat hunting, forensic investigation, malware analysis, and recovery require their own scope and specialist capability. The proposal identifies any included activities and the arrangements for additional expertise.
Measures are selected around the work being delivered. They may include alert acknowledgement, triage and escalation times, case backlog, investigation quality, and handover completion. Each measure defines when timing starts, the applicable coverage hours, and how dependencies are recorded.
The response matrix defines the owner for each action. Innoraft may investigate, escalate, coordinate, or perform specifically authorized containment actions within scope. Actions affecting business systems follow the agreed approval process. Remediation ownership is documented separately.
These requirements can be included in service planning. We confirm the named time zone, working days, shift times, paging criteria, and backup arrangements before committing to a schedule. PagerDuty access and escalation paths are tested during onboarding.
Pagination
- First page
- Previous page
- …
- 3
- 4
- 5
- 6
- …
- Next page
- Last page