Terminology Index

Glossary

2953 terms

Open concept maps
S
32

SOC

The team or function that monitors, detects, and responds to security threats day to day, the operational center of blue-team work. Often used as shorthand for Security Operations Center.

The SOC is where security operations happen: analysts, engineers, and managers running detection, triage, investigation, response, and continuous improvement. SOCs come in many shapes, in-house, outsourced, hybrid, follow-the-sun, and span tiers of analyst seniority. As a foundational blue-team concept, the SOC is the answer to 'where is security actually done day to day,' and many other concepts (detection engineering, IR, threat hunting) live within or around it.

Introduced in: Blue Team Operations

Examples

  • A team monitoring telemetry and triaging alerts 24/7 in the SOC.
  • In-house, outsourced, hybrid, and follow-the-sun SOC models.
  • Detection, IR, and hunting all operating within the SOC.