SOC operations

SOC Fundamentals

Overview

A Security Operations Center continuously monitors, detects, investigates, and responds to cybersecurity threats across an organization's entire technology environment.

Key concepts

  • SOC, SOC analyst, security event/alert/incident
  • Telemetry, threat monitoring
  • Playbooks, MTTD, MTTR

How it works

A Security Operations Center (SOC) is a team or facility that continuously monitors, detects, investigates, and responds to cybersecurity threats — protecting an organization's systems, networks, endpoints, cloud services, accounts, applications, and data. SOC operations can be run internally, outsourced to a managed security service provider, or shared between internal and external teams.

Core terms

TermMeaning
SOCA centralized team that monitors and defends an organization's technology environment.
SOC analystMonitors security alerts, investigates suspicious activity, documents findings, and responds to incidents.
Security eventAny observable activity — a login attempt, file creation, process execution, firewall connection.
Security alertA notification generated when activity matches a detection rule or appears suspicious.
Security incidentA confirmed or suspected event threatening confidentiality, integrity, or availability.
TelemetrySecurity-relevant data collected from devices, networks, applications, cloud services, and accounts.

Process & performance terms

TermMeaning
Threat monitoringContinuous review of security data to identify suspicious, malicious, or unauthorized activity.
Incident responsePreparing for, identifying, investigating, containing, removing, recovering from, and learning from incidents.
PlaybookA documented set of steps analysts follow to investigate and respond to a specific alert or incident type.
Mean time to detect (MTTD)The average time it takes to identify a security incident.
Mean time to respond (MTTR)The average time it takes to investigate, contain, and respond to an incident.