What a SOC does
A SOC collects alerts from tools such as EDR and SIEM, triages them to separate real threats from false positives, investigates confirmed incidents and coordinates the response: isolating devices, blocking accounts and guiding recovery. It also tunes detection rules over time so that alerts become more accurate.
In house, outsourced or hybrid
Building an internal SOC requires analysts, tooling and processes that few small and mid sized companies can sustain. Many work with an external SOC, or combine their own IT or security team with an external provider. Coverage hours vary: some SOCs operate around the clock, others during business hours with escalation outside them.
How a SOC is measured
Common indicators are mean time to detect (MTTD), mean time to respond (MTTR), the volume of alerts handled and the share of false positives.
Where it shows up in compliance
A SOC supports the monitoring and incident management requirements of ISO 27001, ENS, NIS2 and DORA.




