SOC (Security Operations Centre)
Definition
A function providing continuous monitoring, alert triage, and early detection of security events. The SOC is the first tier of response: it identifies candidate incidents, filters false positives, and escalates confirmed or suspected incidents to the CSIRT. SOC analysts typically work from a SIEM platform against defined detection rules and playbooks.
- Full form
- Security Operations Centre
- Primary role
- Continuous monitoring and alert triage
- Escalation target
- CSIRT
- Core platform
- SIEM
Common questions
What is the practical difference between a SOC and a CSIRT?+
The SOC is the first tier: it watches alerts continuously, filters out false positives, and confirms whether something looks like a genuine incident. The CSIRT is the team that takes over once an incident is confirmed or suspected, handling deeper investigation, containment, and formal response.
Does every SOC analyst work directly from raw log data?+
Not typically. Analysts mostly work through a SIEM platform that has already aggregated and correlated logs against detection rules, surfacing candidate alerts. Raw log review is usually a deeper step taken only when an alert needs closer investigation.
Can a SOC operate without formal playbooks?+
It can, but consistency suffers. Playbooks give analysts a defined sequence of triage and escalation steps for common alert types, which is what makes SOC output repeatable enough to hand off reliably to the CSIRT.
Related terms
- CSIRT (Computer Security Incident Response Team)
- A dedicated team responsible for coordinating the response to confirmed security incidents. The CSIRT manages containment, forensic investigation, communication to stakeholders, and...
- Escalation Path
- The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
- Tactics, Techniques, and Procedures (TTPs)
- A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
- Threat Actor
- An individual or group responsible for a security incident or malicious campaign. Threat actors are categorised by motivation (financial, espionage, hacktivism, destruction)...