Is It Time for Sec-Ops?
February 23, 2012

Aruna Ravichandran
CA Technologies

If an attacker were bogging down your apps, how would you know? You wouldn't, unless you bridge the gap between ops and security.

Inspired by the teamwork that began with the Agile movement, IT organizations are tearing down walls in the service delivery process. DevOps is shortening release cycles by uniting development and delivery. But another wall stands in the way of an agile enterprise: the one between operations and security.

Most ops teams have no way of knowing when they’re dealing with an attack or a slow server. With the security and ops teams working separately, issues can take longer to identify, and longer to fix, compromising both operational performance and the security of the enterprise.

It’s time to demolish the divide between the Network Operations Center (NOC) and the Security Operations Center (SOC).

Here’s how to get started.

Step 1: Prioritize

Start with what matters most:

- Which apps or services are the most critical to your organization?

- Which ones can’t afford to have a security problem remain undiagnosed for even a few minutes?

Step 2: Collaborate with the security team

Because you’ll be shifting some responsibility from one team to another, it’s important to ensure that everyone understands why.

- Facilitate communication between the NOC and SOC teams about what they will gain by bringing security events into the NOC.

- Ensure the NOC team understands the importance of giving the SOC team visibility into certain aspects of NOC monitoring tools.

- Discuss the various tools you’ll need to accomplish this coordination and the processes you will need to create or modify.

Step 3: Identify the right monitoring tools

It’s important to look for a tool that won’t add new complexity to the NOC or its processes. The ideal tool would consolidate and correlate all events—security and operational—under a single pane of glass.

It also should:

- Provide real-time monitoring information.

- Allow for customization, so that both the SOC and NOC teams can see the information they need to see.

- Integrate security system events with the NOC's overall event management system.

- Connect security-related events with the business services they affect so you can prioritize problems when they arise.

- Identify a problem’s cause with little or no manual work.

This article is adapted from a longer article that appeared in the Discover Performance newsletter.

Aruna Ravichandran is VP, Product & Solutions Marketing, DevOps, CA Technologies
Share this

Industry News

April 17, 2025

GitLab announced the general availability of GitLab Duo with Amazon Q.

April 17, 2025

Perforce Software and Liquibase announced a strategic partnership to enhance secure and compliant database change management for DevOps teams.

April 17, 2025

Spacelift announced the launch of Saturnhead AI — an enterprise-grade AI assistant that slashes DevOps troubleshooting time by transforming complex infrastructure logs into clear, actionable explanations.

April 16, 2025

CodeSecure and FOSSA announced a strategic partnership and native product integration that enables organizations to eliminate security blindspots associated with both third party and open source code.

April 16, 2025

Bauplan, a Python-first serverless data platform that transforms complex infrastructure processes into a few lines of code over data lakes, announced its launch with $7.5 million in seed funding.

April 15, 2025

Perforce Software announced the launch of the Kafka Service Bundle, a new offering that provides enterprises with managed open source Apache Kafka at a fraction of the cost of traditional managed providers.

April 14, 2025

LambdaTest announced the launch of the HyperExecute MCP Server, an enhancement to its AI-native test orchestration platform, HyperExecute.

April 14, 2025

Cloudflare announced Workers VPC and Workers VPC Private Link, new solutions that enable developers to build secure, global cross-cloud applications on Cloudflare Workers.

April 14, 2025

Nutrient announced a significant expansion of its cloud-based services, as well as a series of updates to its SDK products, aimed at enhancing the developer experience by allowing developers to build, scale, and innovate with less friction.

April 10, 2025

Check Point® Software Technologies Ltd.(link is external) announced that its Infinity Platform has been named the top-ranked AI-powered cyber security platform in the 2025 Miercom Assessment.

April 10, 2025

Orca Security announced the Orca Bitbucket App, a cloud-native seamless integration for scanning Bitbucket Repositories.

April 10, 2025

The Live API for Gemini models is now in Preview, enabling developers to start building and testing more robust, scalable applications with significantly higher rate limits.

April 09, 2025

Backslash Security(link is external) announced significant adoption of the Backslash App Graph, the industry’s first dynamic digital twin for application code.

April 09, 2025

SmartBear launched API Hub for Test, a new capability within the company’s API Hub, powered by Swagger.

April 09, 2025

Akamai Technologies introduced App & API Protector Hybrid.