Cybersecurity glossary
What is a Security Operations Center (SOC)?
Learn what a Security Operations Center (SOC) is, how analysts detect and respond around the clock, which operating models exist, and what metrics separate a real SOC from a ticket factory.
Definition
A Security Operations Center (SOC) is the people, process, and technology function that continuously monitors an organization’s environment, triages alerts, investigates suspicious activity, and coordinates response—often around the clock.
Why someone has to watch the wire
Sensors do not contain ransomware. People working a defined operating rhythm do. A Security Operations Center (SOC) is that rhythm: intake, triage, investigation, escalation, and feedback into better detections.
A SOC that only closes tickets is a queue. A SOC that reduces dwell time is a control.
Core SOC work
Monitor and triage
Ingest alerts, enrich them, and decide: false positive, notable, or incident—within an agreed SLA.
Investigate
Build a timeline across identity, endpoint, and cloud until scope is honest enough to act.
Coordinate response
Trigger playbooks, isolate with IT, revoke sessions, and escalate major incidents to IR leadership.
Improve the system
Return noise, gaps, and missed techniques to detection engineering and asset owners.
A shift that actually reduces risk
Take a clean queue
Know source health, on-call coverage, and which detections are in maintenance.
Work high-fidelity first
Priority is attacker progress and crown-jewel assets, not whichever alert is oldest.
Document the story
Every case captures evidence, identity, and the decision—so the next shift is not amnesiac.
Escalate with authority
When thresholds hit, IR, legal, or exec comms join by plan, not by improvisation.
Hand off and tune
Unowned noise becomes a detection ticket; confirmed TTPs become new coverage.
Operating models
| Model | Fits when | Main risk |
|---|---|---|
| In-house 24×7 | High impact, complex estate, need tight business context | Burnout and hiring; process must protect analysts |
| Follow-the-sun / hybrid | Global org that can share cases cleanly across regions | Handoff gaps and tool-access mismatches |
| Managed SOC / MDR | Need coverage and skills you cannot hire yet | Vendor cannot contain without your identity and IT owners |
| Business-hours only | Accepted overnight dwell with strong preventive controls | Attackers prefer the hours you are dark |
- Give the SOC asset and identity context (owners, criticality, known-benign automation).
- Define escalation paths with names and after-hours reachability.
- Protect analyst time: cap unactionable alerts and staff detection engineering.
- Grant least-privilege response rights that are still enough to isolate and revoke.
- Run joint exercises with IT so containment is not a first-time conversation.
- Measure quality of closures, not only speed—wrong “false positive” labels hide breaches.
- Keep a written mission: what the SOC owns versus AppSec, GRC, and IT operations.
- Invest in career paths so Tier 1 is not a dead end that drives attrition.
The practical takeaway
A SOC is the operational heartbeat of detection and response. Staff it with clear authority, high-fidelity alerts, and a feedback loop into engineering—or you have purchased consoles for people who cannot actually stop an intrusion.
Related security terms
Blue Team
Broader defensive function; the SOC is often its operational core.
Incident Response
Escalation path when SOC triage confirms a real incident.
Detection Engineering
Builds the alerts SOC analysts live inside.
Alert Fatigue
Capacity failure mode that ruins SOC effectiveness.
Security Information and Event Management (SIEM)
Typical monitoring platform the SOC queries all shift.
Frequently asked questions
What is a SOC in simple terms?
It is the team (and the room or virtual room) that watches security alerts, decides what is real, and kicks off response—ideally before attackers finish their job.
Is the SOC the same as incident response?
The SOC usually handles detection and initial triage. Dedicated IR or a CSIRT may take over major incidents. In smaller orgs, the same people wear both hats.
Do you need a 24×7 in-house SOC?
Not always. Follow-the-sun, managed SOC, or hybrid models can cover nights if escalation paths and data access actually work. Business hours only is a choice about accepted dwell time.
What do SOC tiers mean?
Tier 1 typically triages and closes obvious noise. Tier 2 investigates. Tier 3 hunts or handles complex incidents. Rigid tiers can trap talent; many teams prefer skill-based swarms.
What tools does a SOC use?
SIEM or XDR, EDR, identity logs, email security, ticketing, threat intel, and often SOAR—plus documented playbooks.
How do you measure a SOC?
Alert fidelity, time to triage, MTTD/MTTR on real incidents, coverage of priority techniques, and analyst retention—not ticket volume.
When should you outsource?
When you cannot staff coverage or skills, but you can still own detections, asset context, and containment authority. An MSSP without isolation rights only writes reports.
References
Explore authoritative guidance and frameworks related to security operations center (soc).
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.