Cybersecurity Glossary

What is a Security Operations Center?

A Security Operations Center, or SOC, is the operational function responsible for monitoring and investigating security events. Analysts work with endpoint, identity, network and cloud telemetry to distinguish normal activity from attacks and initiate the right response.

A SOC can be internal, outsourced or hybrid. The name describes a capability, not necessarily a physical room. Effective coverage depends on useful telemetry, defined escalation paths, skilled analysts and enough context about the organization's systems.

What does a SOC do?

  • - Monitor alerts and prioritize them by risk and affected asset.
  • - Investigate related events and determine whether an incident exists.
  • - Contain straightforward threats or escalate to the CSIRT.
  • - Improve detection rules and document recurring attacker behavior.

Does a SOC prevent every attack?

No. A SOC reduces detection and response time, but it cannot compensate for every missing patch, excessive permission or insecure application. Prevention, architecture and incident response remain separate but connected responsibilities.

How is an alert handled?

  1. Triage:
    check the source, affected identity, asset criticality and initial indicators.
  2. Enrichment:
    add context from identity, endpoint, network, cloud and threat intelligence.
  3. Investigation:
    reconstruct timeline and scope and test benign explanations against attack hypotheses.
  4. Containment:
    with appropriate authority, disable an account, isolate a host, revoke a token or block malicious communication.
  5. Escalation and closure:
    hand confirmed incidents to response, document cause and improve detection.

Playbooks provide direction but should not reduce analysis to rigid checklists. The same alert may be harmless on a test system and critical on a domain controller. Asset and identity context often matters more to priority than the severity assigned by a product.

Which roles work in a SOC?

  • - Analysts perform triage, investigation and initial containment.
  • - Detection engineers develop data models, rules and tests.
  • - Threat hunters search for activity that did not trigger an alert.
  • - Incident responders coordinate deep analysis, containment and recovery.
  • - SOC management owns service, staffing, risk, metrics and interfaces.

Small teams combine several roles. The number of tier labels matters less than clear authority, on-call coverage and escalation. The CSIRT may be part of the SOC or operate as a separate incident and crisis function.

Internal, outsourced or hybrid?

ModelStrengthChallenge
InternalDeep business and system contextStaffing, shifts and specialist skills
Outsourced/MDRFast access to platform and 24/7 operationContext, interfaces and contractual limits
HybridExternal scale with internal authorityClean hand-offs and shared processes

Which tools does a SOC need?

A SIEM correlates and searches events, EDR provides process and endpoint visibility, and identity, network and cloud tools add telemetry and response actions. SOAR can orchestrate recurring steps while case management preserves decisions. No product replaces data quality, relevant use cases and analysts who understand the environment.

How is SOC effectiveness measured?

Alert counts and closed tickets mainly measure activity. More useful measures include coverage of relevant attack techniques, time to qualified assessment, time to containment, recurring false positives and successful exercises. The organization should also know which critical systems lack adequate telemetry. Purple-team and red-team exercises test whether detection works from sensor to human decision and response rather than only existing on paper.

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on Security Operations Center (SOC)? Tell us!