In this blog post, the author discusses considerations for a security operation center (SOC) in the context of deploying it to the cloud using different operating models - centralized, decentralized, and hybrid.
They focus specifically on AWS native security services and the use of AWS Security Hub.
They provide a reference architecture for a decentralized hybrid model and explain how to deploy it.
The post also covers additional factors to consider, such as limited staff skills, compliance requirements, and budget.
















