Terminology Index
Glossary
2953 terms
S32
Security Operations Center
The team and function responsible for monitoring, detecting, and responding to security threats, the operational heart of blue-team work, run continuously to defend the organization.
The SOC is the operational center for ongoing defense: analysts watching telemetry, triaging alerts, investigating events, and responding to incidents, supported by engineering, intelligence, and management. SOCs vary from small in-house teams to large 24/7 operations and hybrid models with MDR partners. As a defining blue-team-operations concept, the SOC is where strategy, tools, and people meet to do the actual work of defending the organization day after day.
Introduced in: Blue Team Operations
Examples
- A 24/7 SOC monitoring telemetry and triaging alerts continuously.
- Hybrid SOC arrangements combining in-house staff with MDR.
- The SOC running detection, investigation, and response operations.
