Skip to content

SOC (Security Operations Centre)

Definition

A function providing continuous monitoring, alert triage, and early detection of security events. The SOC is the first tier of response: it identifies candidate incidents, filters false positives, and escalates confirmed or suspected incidents to the CSIRT. SOC analysts typically work from a SIEM platform against defined detection rules and playbooks.

Full form
Security Operations Centre
Primary role
Continuous monitoring and alert triage
Escalation target
CSIRT
Core platform
SIEM

Common questions

What is the practical difference between a SOC and a CSIRT?+

The SOC is the first tier: it watches alerts continuously, filters out false positives, and confirms whether something looks like a genuine incident. The CSIRT is the team that takes over once an incident is confirmed or suspected, handling deeper investigation, containment, and formal response.

Does every SOC analyst work directly from raw log data?+

Not typically. Analysts mostly work through a SIEM platform that has already aggregated and correlated logs against detection rules, surfacing candidate alerts. Raw log review is usually a deeper step taken only when an alert needs closer investigation.

Can a SOC operate without formal playbooks?+

It can, but consistency suffers. Playbooks give analysts a defined sequence of triage and escalation steps for common alert types, which is what makes SOC output repeatable enough to hand off reliably to the CSIRT.

Related terms

CSIRT (Computer Security Incident Response Team)
A dedicated team responsible for coordinating the response to confirmed security incidents. The CSIRT manages containment, forensic investigation, communication to stakeholders, and...
Escalation Path
The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
Tactics, Techniques, and Procedures (TTPs)
A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
Threat Actor
An individual or group responsible for a security incident or malicious campaign. Threat actors are categorised by motivation (financial, espionage, hacktivism, destruction)...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.