Security Operations Centre (SOC)
Definition
The dedicated team and technology platform responsible for continuous monitoring, detection, analysis, and coordinated response to security events. May be in-house, co-managed, or fully outsourced.
- Function
- Continuous monitoring, detection, analysis and response
- Delivery models
- In-house, co-managed, or fully outsourced
- Coverage
- Typically 24/7
Common questions
What is the difference between an in-house SOC and a fully outsourced one?+
An in-house SOC gives the organisation direct control and institutional knowledge of its own environment, while an outsourced or managed SOC trades some of that visibility for lower cost and easier round-the-clock coverage.
Does a SOC replace the need for an incident response team?+
No, the SOC typically handles detection and initial triage, then hands confirmed incidents to a formal incident response process that may involve legal, communications and technical remediation staff beyond the SOC itself.
Related terms
- Escalation Path
- The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
- Managed Security Service Provider (MSSP)
- A third-party organisation that delivers security monitoring, tooling, and analyst coverage as a contracted service. Used in fully outsourced and co-managed SOC...
- Playbook
- A documented step-by-step procedure for responding to a specific type of security event. Playbooks standardise analyst behaviour, reduce response time, and ensure...
- SIEM (Security Information and Event Management)
- A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...
- Threat Hunting
- A proactive, human-led process that searches for evidence of adversary activity in an environment under the assumption that automated controls have been...