Security+ ยท 4.0 Security Operations
SOAR (Security Orchestration, Automation, Response)
A class of tools that automates routine security-operation tasks and playbooks. Reduces mean-time-to-respond by machines doing what analysts used to do manually.
How this shows up at NCAE
Your 60-second restore cron is a poor man's SOAR. Cedarville's Falco + ntfy push notification + auto-revert is a full small SOAR for NCAE.