A global corporation with major offices in North America, Europe, and Asia needs to establish a 24/7 security monitoring capability. The goal is to handle common alerts locally within each region for efficiency, while escalating complex, novel, or widespread threats to a central team of highly skilled experts for in-depth analysis and coordination. Which Security Operations Center (SOC) model BEST fits this architectural requirement?
-
A
A distributed SOC with fully independent regional teams.
-
B
A virtual SOC (VSOC) leveraging geographically dispersed analysts without a central command.
-
C
A co-managed SOC where a third-party manages all Tier 1 analysis globally.
-
D
A tiered or hierarchical SOC with regional Tier 1/2 teams and a central Tier 3 command SOC.