Evaluating a partner for establishing a security operations center includes an assessment of its experience and capabilities. The food and beverages company assessed our incident response management processes, the span of pre-deployment activities for infrastructure and applications, and our experience in conducting similar transitions.
We established a managed security operations center (MSOC) to detect and prevent security incidents. Subsequently, we established MSOC operations to provide 24x7 monitoring of cybersecurity threats, incident response and threat intelligence for the company. The ISO 27001 compliant MSOC deployed EY’s proprietary assets and tools, such as next-generation Cognitive Cyber Center (CCC) and EY Security Governance Services.
The implementation involved deployment of specific use cases as actionable correlation rules within the security information and event management (SIEM) system, coupled with newly created threat intelligence inputs and automatic lookups.
During the course of the engagement, EY helped the client recover from an appliance failure incident by invoking the business continuity plan (BCP) and restoring services after return merchandize authorization (RMA) in a very short span of time.
Different aspects of EY’s MSOC for a global food and beverages company