SOAR
What is SOAR?
Security Orchestration, Automation and Response platforms that combine security tool integration, workflow automation, and case management for efficient incident handling.
Terms that appear alongside soar
Each of these is named in at least one of the same controls as soar. The number is how many controls name both.
- mitre 6 shared controls
- incident response 6 shared controls
- security monitoring 5 shared controls
- threat intelligence 5 shared controls
- cloud security 5 shared controls
- threat hunting 4 shared controls
- iso 27001 4 shared controls
- internal audit 4 shared controls
Frameworks that govern soar
What the standards actually require on soar
Requirements naming soar across 6 standards, quoted from the control text.
Implement Logging and Monitoring + Compliance and Audit + Cloud Configuration Management + Cloud Security Monitoring + SLA Management per MTCS SS 584.
MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM · MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM →Integrate D3FEND with broader cybersecurity ecosystem and frameworks. ATT&CK-D3FEND bidirectional mappings - each D3FEND defensive technique is mapped to ATT&CK offensive techniques it counters + each ATT&CK offensive technique maps to D3FEND defensive techniq...
MITRE-D3FEND-Integration-Mapping-ATTACK-CWE-CVE-CAPEC-NIST-CSF-CIS-ISO-27001-STIX-OpenC2 · MITRE D3FEND Integration + Mapping + ATT&CK + CWE + CVE + CAPEC + NIST CSF + CIS + ISO 27001 + STIX + OpenC2 →HKMA TM-G-1 Cyber + Audit + Outsourcing + Cloud. (1) SECURITY MONITORING AND SIEM (TM-G-1.7.1) - SIEM + SOC + 24x7 monitoring + log management + correlation + use cases + alert handling + escalation + UEBA + behavior analytics + SOAR automation + threat detect...
HKMA-TMG1-Cyber-Monitoring-Threat-Intel-IR-Audit-Outsource-Cloud · TM-G-1 Security Monitoring + SIEM + Threat Intel + Cyber IR + Audit + Outsourcing + Cloud Computing Risk →HKMA C-RAF implementation roadmap. ORGANIZATIONAL ROLES at AI: (a) BOARD + RISK COMMITTEE - C-RAF governance oversight + cyber-strategy + risk appetite + reporting;
HKMA-CRAF-Implementation-Roles-Tooling-Assurance · HKMA C-RAF Implementation Roadmap, Organizational Roles, Tooling and Assurance →ISMAP Cloud Operations covers the day-to-day security operations of cloud services. (1) Cloud Security Monitoring and Logging: 24x7 Security Operations Center (SOC) + SIEM Security Information and Event Management (Splunk + Microsoft Sentinel + IBM QRadar + Su...
ISMAP-CloudOperations-Monitoring-Logging-IncidentResponse-NISC-Reporting-Vulnerability-Change-SLA · ISMAP Cloud Operations - Security Monitoring + SIEM + Logging + Incident Response + NISC Reporting + Vulnerability Management + Penetration Testing + Change Management + SLA Management →Continuous security monitoring + 24x7 SOC operations are expected per FSA Cybersecurity Guidelines particularly for Tier 2/3 institutions. (1) SOC Operating Models: (a) Internal SOC - dedicated team + tooling;
JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage · Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA →Questions people ask about soar
What is SOAR?
Why is SOAR important for compliance?
Which compliance frameworks address SOAR?
Where can I learn more about SOAR?
See how SOAR applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.