Release #2: A basic CDC Model
F or our discussions I will define a reference model with functions, responsibilities and an organizational background. The external requirements are based on the EU and German ligislations and requirements for the finance sector. (1) BTW, a well known eBook from Carson Zimmermann is named " Ten Strategies of a world-class Cybersecurity Operation Center " is a good read for practioneers. You should read it too. CDC Reference Model Our CDC reference model does not include the responsibility for the administration of security technologies, like firewalls, intrusion detection systems, SIEM, AV scanners and such. The detailed organizational setup depends on the size of the organisation, the bigger the organisation the less technical and administrative responsibilities should the CDC have and the more interdependence within the organisation exists. If the CDC is located outside the IT department (maybe in the staff department of the CISO), then it is very unlikely that the C