Glossary
Security operations center (SOC)
The team responsible for continuously monitoring an organization's systems, triaging alerts, and coordinating incident response.
Also called: SOC, security operations centre
A security operations center (SOC) is the team, and usually the physical or virtual room, responsible for continuously monitoring an organization's systems for security threats, triaging alerts, and coordinating incident response. Analysts typically work in tiers: a first tier triages alerts from a SIEM, escalating anything suspicious to more senior analysts who investigate using threat intelligence and forensic tools.
A SOC differs from a broader IT operations team in scope and mandate: IT operations keeps systems running, while a SOC exists specifically to detect and respond to malicious activity, though the two increasingly share tooling and even staff in smaller organizations. Many SOCs now use SOAR platforms to automate routine response steps and behavior-based analytics to catch threats that rule-based detection misses.
SOCs matter because detection speed and response speed directly determine how much damage an intrusion causes, commonly tracked through mean time to detect and mean time to resolve. A frequent pitfall is running a SOC entirely on the alert volume a SIEM produces without investing in threat hunting, so attackers who evade automated rules go unnoticed for long periods.
Last reviewed September 22, 2026