Defense
SOC (Security Operations Center)
Center for monitoring and responding to security incidents 24/7
SOC (Security Operations Center) is a centralized unit responsible for continuous monitoring, detection, analysis, and response to cyber threats 24/7.
SOC Functions
- Real-time security monitoring
- Threat detection and analysis
- Incident response
- Incident investigation
- Threat Hunting
SOC Tiers
Tier 1 — Security Analyst
- Initial alert analysis
- Incident escalation
Tier 2 — Incident Responder
- Deep incident analysis
- Response and containment
Tier 3 — Threat Hunter
- Proactive threat hunting
- Detection rule development
SOC Metrics
- MTTD — Mean Time To Detect
- MTTR — Mean Time To Respond
- Alert Volume — number of alerts
- False Positive Rate — false alarm rate
Related Terms
Category
WAF, SIEM, SOC, EDR, protection and monitoring tools