Glossary

Security Operations Centre (SOC)

Central team providing 24/7 security monitoring and incident response.

A

B

C

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

A Security Operations Centre (SOC) is a centralised unit (either in-house or outsourced) staffed by security analysts who monitor, detect, investigate and respond to cyber threats around the clock. The SOC leverages tools such as SIEM platforms, endpoint detection and response systems, and threat intelligence feeds to maintain continuous visibility over the organisation's security posture.

For many organisations, a SOC is essential for meeting the monitoring and incident response requirements of frameworks like ISO 27001 and SOC 2. Whether operated internally or provided as a managed service, the SOC must have clearly defined playbooks, escalation procedures and performance metrics to ensure that threats are identified and contained before they cause significant damage.

T

U

V

W

Z

Frequently asked questions

What is a security operations center (SOC)?
A security operations centre (SOC) is a team and facility responsible for continuously monitoring, detecting, analysing and responding to cybersecurity threats across an organisation.
What does a SOC do?
A SOC monitors systems and logs for suspicious activity, investigates alerts, responds to security incidents, and works to reduce the organisation’s overall risk.
What is the difference between a SOC and a SIEM?
A SIEM (Security Information and Event Management) is the tooling that collects and correlates security data, while a SOC is the team and process that uses tools such as a SIEM to monitor and respond.
Is a security operations centre the same as SOC 2?
No — a security operations centre (SOC) is a cybersecurity team and function, while SOC 2 is an auditing standard for how service organisations manage data. They are unrelated despite sharing the abbreviation.