| Framework of security orchestration, automation and response for cloud computing |
 |
Nowadays, as network security strategies continue to evolve, the security architecture for cloud service providers (CSPs) or cloud service customers (CSCs) has changed from a simple combination of prevention and recovery to a new stage integrating detection, prevention, and response. Leading enterprises and organizations have attached greater importance to security orchestration, automation and response (SOAR). SOAR is regarded as the key technology to improve network elasticity and the efficiency of security operations for cloud computing, which can be detailed as follows:
1)By leveraging artificial intelligence (AI), it is possible to establish a security operation functionality in the cloud that includes threat analysis and controlled automated response, which could greatly improve the efficiency of security operations.
2)In cloud computing, SOAR has naturally a cost advantage.
3)With the development of cloud-native technology, there are new approaches to implementing managed and scalable incident response in cloud computing.
Recommendation ITU-T X.1651 describes the overview of SOAR for cloud computing, including the definition and the emerging background of SOAR, and analyses advantages of SOAR coping with security threats of cloud computing especially in incident responses. Then it also provides a framework of SOAR for cloud computing to improve the efficiency of security operations for both CSPs and CSCs.
|
|
| Citation: |
https://handle.itu.int/11.1002/1000/16702 |
| Series title: |
X series: Data networks, open system communications and security X.1600-X.1699: Cloud computing security X.1640-X.1659: Cloud computing security best practices and guidelines |
| Approval date: |
2026-06-10 |
| Provisional name: | X.soar-cc |
| Approval process: | TAP |
|
Status: |
In force |
|
Maintenance responsibility: |
ITU-T Study Group 17 |
|
Further details: |
Patent statement(s)
Development history
[19 related work items in progress]
|
|
|
| Ed. |
ITU-T Recommendation |
Status |
Summary |
Table of Contents |
Download |
|
1
|
X.1651 (06/2026)
|
In force
|
here
|
here
|
here
|
| Title |
Approved on |
Download |
|
Guidelines for identity-based cryptosystems used for cross-domain secure communications
|
2023
|
here
|
|
Overview of hybrid approaches for key exchange with quantum key distribution
|
2022
|
here
|
|
Guidelines for security management of using artificial intelligence technology
|
2022
|
here
|
|
Successful use of security standards (2nd edition)
|
2020
|
here
|
|
Description of the incubation mechanism and ways to improve it
|
2020
|
here
|
|
Strategic approaches to the transformation of security studies
|
2020
|
here
|
|