John Hubbard - Did you interview other analysts and dial back to your days as an analyst?
I remember pretty vividly what my struggles were coming into that job. Just understanding what each bit of data was and what it could tell me. Where it was coming from, how it was formatted, and that's all stuff that I definitely wanted to write into the course.
And yes, I’d been talking to analysts along the way. As I'd been flying around and teaching in various places, I'd try to pay particular attention to people who were newer analysts and say, "What are you struggling with? What is it that you want to learn more about? And what do you think would make you better?" And I talked to a lot of people in that respect. I also asked them what they didn't like about the job. Which is what gave birth to some of the other content in the course about making the job more pleasant, because SOC analysts…
--
Learn more about John Hubbard and the SANS SEC450 Blue Team Fundamentals course:
Full blog post: http://cyber-defense.sans.org/u/XoF
SEC450 course page: http://www.sans.org/u/XmO
John Hubbard’s bio: http://www.sans.org/u/XmT
Connect with John on Twitter: twitter.com/SecHubb