What's changed: Created Professional Security Operations Engineer Chapter 6 (Domain 6 "Observability": key security analytics (metrics/KPIs=MTTD-MTTR/trends), dashboards (Google SecOps SOAR/SIEM/Looker Studio), report generation/customization; health-monitoring metrics, centralized dashboards, threshold alerts, Cloud Monitoring notifications, identifying health issues with Cloud Logging, silent source detection).
6.1Dashboards and reports
Understand identifying key security analytics (metrics, KPIs, trends), implementing dashboards to visualize security telemetry, ingestion metrics, detections, alerts, and IOCs (Google SecOps SOAR, SIEM, Looker Studio), and generating/customizing reports.
Observability makes the SOC's state and outcomes visible. Measure operations with metrics, and communicate via dashboards and reports.
6.1.1Security analytics and dashboards
First identify key security analytics: metrics (detections, alerts, false-positive rate), KPIs (MTTD—mean time to detect, MTTR—mean time to respond, case-resolution rate), and trends (rising/falling attacks, top threats). Visualize them in dashboards: security telemetry, ingestion metrics (log volume/cost), detections, alerts, and IOCs—via built-in Google SecOps SOAR/SIEM dashboards or flexible Looker Studio. For executives/stakeholders, generate and customize reports to communicate SOC outcomes and trends. Map "measure operational health = KPIs like MTTD/MTTR" and "flexible visualization/reporting = Looker Studio."
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

