Continuous security monitoring + 24x7 SOC operations are expected per FSA Cybersecurity Guidelines particularly for Tier 2/3 institutions. (1) SOC Operating Models: (a) Internal SOC - dedicated team + tooling; (b) Hybrid SOC - internal + MSSP Managed Security Service Provider; (c) Outsourced SOC - MSSP managed; (d) MDR Managed Detection and Response - emerging; (e) XDR Extended Detection and Response platforms; (f) Cloud SOC integration; (g) Follow-the-Sun for 24x7 coverage; (h) SOC analyst tiers - L1 triage + L2 investigation + L3 threat hunting + L4 incident response. (2) SIEM Security Information and Event Management: (a) Log aggregation + normalisation + correlation; (b) Major SIEM vendors - Splunk + IBM QRadar + Microsoft Sentinel + Elastic Security + Exabeam + Sumo Logic; (c) Cloud-native SIEM - AWS Security Hub + Google Chronicle + Azure Sentinel; (d) Use Case Library + Detection Rules; (e) MITRE ATT and CK alignment; (f) Custom detection development; (g) Log retention typically 1-7 years for financial; (h) SIEM as central audit trail. (3) EDR Endpoint Detection and Response: (a) CrowdStrike Falcon + SentinelOne + Microsoft Defender for Endpoint + Carbon Black + Sophos Intercept X; (b) Behavioural detection + machine learning; (c) Process tree + parent-child analysis; (d) Threat hunting capabilities; (e) Remote isolation + containment; (f) IOC Indicator of Compromise tracking; (g) Memory forensics; (h) Mac + Linux + Windows + Server + Workstation coverage. (4) Network Detection and Response (NDR): (a) Darktrace + ExtraHop + Vectra + Corelight; (b) Lateral movement detection; (c) Encrypted traffic analysis; (d) DNS + HTTP/S anomaly detection; (e) Command and Control detection; (f) Data exfiltration detection; (g) IoT + OT visibility. (5) XDR Extended Detection and Response: (a) Cross-Domain correlation (endpoint + network + cloud + identity); (b) Single Pane of Glass for SOC; (c) Vendor XDR platforms - CrowdStrike + Palo Alto Cortex + Trend Micro Vision One + Microsoft + Sophos; (d) Open XDR architectures; (e) Automated response orchestration. (6) UEBA User and Entity Behaviour Analytics: (a) Baseline normal user behaviour; (b) Anomaly detection (unusual login + access + data access); (c) Privileged user monitoring; (d) Insider threat detection; (e) Compromised account detection; (f) Behaviour-based risk scoring. (7) SOAR Security Orchestration Automation and Response: (a) Palo Alto Cortex XSOAR + Splunk SOAR + Microsoft Sentinel SOAR; (b) Playbook automation; (c) Case management; (d) Integration with ticketing + ITSM; (e) Threat intel enrichment; (f) Automated response (with human approval for high-impact). (8) Threat Intelligence Integration: (a) Strategic threat intel (sector-specific + executive); (b) Tactical threat intel (TTPs + IOCs); (c) Operational threat intel (campaign-specific); (d) FS-ISAC Japan + JPCERT/CC + FISC sharing; (e) Commercial TI - Mandiant + Recorded Future + CrowdStrike + Microsoft + Anomaly + ThreatConnect; (f) STIX 2.1 + TAXII 2.1 sharing standards; (g) MISP open source platform; (h) Indicators of Compromise (IOCs) + Indicators of Attack (IoAs). (9) Detection Use Cases (Financial-Specific): (a) ATM jackpotting; (b) Wire transfer fraud; (c) Account takeover (ATO); (d) Card-not-present fraud; (e) Insider trading + market abuse; (f) Mule account detection; (g) AML transaction monitoring intersection; (h) Crypto exchange wallet attacks; (i) Mobile banking malware; (j) Customer phishing campaigns. (10) Threat Hunting: (a) Hypothesis-driven hunting; (b) Indicator-based hunting; (c) Tactic-based hunting (MITRE ATT and CK); (d) Anomaly-based hunting; (e) Threat Intel-driven hunting; (f) Continuous hunting program for Tier 3; (g) Hunt findings + lessons learned. (11) SOC Metrics + KPIs: (a) Mean Time to Detect (MTTD); (b) Mean Time to Respond (MTTR); (c) Alert volume + false positive rate; (d) Detection coverage (MITRE ATT and CK mapping); (e) Analyst utilisation; (f) Threat hunt findings; (g) SOC maturity progression; (h) Board cyber dashboard. (12) FSA Notification Trigger: (a) Significant cyber incident detected; (b) Customer-impacting incident; (c) Material data breach; (d) Service disruption; (e) Ransomware detected; (f) Per Banking Act Article 52-2 + FSA Inspection Manual notification thresholds. Coordinates with NIST SP 800-94 IDS/IPS + NIST SP 800-92 Log Management + MITRE ATT and CK + STIX 2.1 + TAXII 2.1 + MISP + FS-ISAC Japan + JPCERT/CC + FISC + Banking Act + FSA Inspection Manual + ISO/IEC 27035 Incident Management + ISO/IEC 27037 Digital Evidence + ENISA SOC Capability Maturity Model + Cloud Security Alliance + Splunk + IBM QRadar + Microsoft Sentinel + Elastic + CrowdStrike + SentinelOne + Carbon Black + Darktrace + Mandiant + Recorded Future. Japan FSA Cybersecurity SOC + Detection applies.
This control maps to 50 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 50 it maps to, and the evidence behind each claim, over MCP and REST.