Service-Level Agreement (SLA)
Definition
A policy or contractual commitment defining how quickly the SOC must perform specific actions (acknowledge, escalate, contain, resolve) for incidents of each severity class. SLA targets are usually expressed as time-to-action from the moment the incident is confirmed.
- Defines
- Time-to-action targets by severity class
- Typical stages covered
- Acknowledge, escalate, contain, resolve
- Measured from
- Moment the incident is confirmed
- Context
- SOC operations and incident response
Common questions
Why does the SLA clock start at confirmation rather than detection?+
Detection can include unconfirmed alerts and false positives; starting the clock at confirmation ensures the SLA measures the SOC's actual response performance on real incidents rather than penalising time spent triaging noise.
How does severity class affect the SLA target?+
Higher-severity incidents carry tighter time-to-action targets, for example minutes to acknowledge a critical incident versus hours for a low-severity one, so the same SOC applies different urgency depending on business impact.
Related terms
- Contact Tree
- A structured list of individuals and teams to notify during an incident, showing the order of contact and the conditions under which...
- Escalation Criteria
- The documented conditions that require an analyst to transfer an incident to a higher tier or to external stakeholders. Examples include: severity...
- Handoff Package
- The bundle of information an analyst prepares before transferring an incident to a higher tier. Contents include incident ID, timeline, severity, containment...
- P1/P2/P3/P4 Severity Tiers
- A common four-level severity classification used in SLA structures. P1 (Critical) carries the shortest time windows; P4 (Low) carries the longest. The...
- SLA Breach
- An instance where a required action was not completed before its SLA timer expired. Each breach is recorded against the incident ticket...