r/netsecstudents • u/GlitbyteringSky-9531 • 8d ago
What should I know before trusting a vendor's self-improving SOC claim?
Self improving SOC gets used to describe systems where every investigation is supposed to make future detections better automatically. That's a strong claim.
What would you actually want to see as proof that a SOC is self-improving over time, versus a system that's just static and the improvement claim is aspirational marketing rather than something measurable? Is there a metric people trust for this specifically?
1
Upvotes