Terminology Index

Glossary

2953 terms

Open concept maps
S
32

Security Operations Center

The team and function responsible for monitoring, detecting, and responding to security threats, the operational heart of blue-team work, run continuously to defend the organization.

The SOC is the operational center for ongoing defense: analysts watching telemetry, triaging alerts, investigating events, and responding to incidents, supported by engineering, intelligence, and management. SOCs vary from small in-house teams to large 24/7 operations and hybrid models with MDR partners. As a defining blue-team-operations concept, the SOC is where strategy, tools, and people meet to do the actual work of defending the organization day after day.

Introduced in: Blue Team Operations

Examples

  • A 24/7 SOC monitoring telemetry and triaging alerts continuously.
  • Hybrid SOC arrangements combining in-house staff with MDR.
  • The SOC running detection, investigation, and response operations.