GlossarySOC and monitoring

SOC

Short answer

A SOC (Security Operations Centre) is the team, processes and tools that monitor an organisation's systems, detect security threats and coordinate the response to incidents. It can be internal, outsourced or a mix of both.

What a SOC does

A SOC collects alerts from tools such as EDR and SIEM, triages them to separate real threats from false positives, investigates confirmed incidents and coordinates the response: isolating devices, blocking accounts and guiding recovery. It also tunes detection rules over time so that alerts become more accurate.

In house, outsourced or hybrid

Building an internal SOC requires analysts, tooling and processes that few small and mid sized companies can sustain. Many work with an external SOC, or combine their own IT or security team with an external provider. Coverage hours vary: some SOCs operate around the clock, others during business hours with escalation outside them.

How a SOC is measured

Common indicators are mean time to detect (MTTD), mean time to respond (MTTR), the volume of alerts handled and the share of false positives.

Where it shows up in compliance

A SOC supports the monitoring and incident management requirements of ISO 27001, ENS, NIS2 and DORA.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, 24/7 SOC operations, detection engineering and incident handling.

Go to the topic hub