A Security Operations Center (SOC) is the centralized team and facility that monitors, detects, investigates, and responds to security events, usually around the clock. Analysts work alerts, hunt for threats that slipped past automated detection, and coordinate the response when something real surfaces.
A SOC leans on a SIEM for visibility, pulls in threat intelligence for context, and runs a triage-and-escalation process so the flood of alerts gets sorted before anyone burns hours on a false positive. Maturity varies widely. Some SOCs do little more than watch a dashboard and forward emails, while others run proactive threat hunting and automated response playbooks. The quiet killer of any SOC is alert fatigue: when analysts face thousands of low-value alerts a day, the one that matters gets closed alongside the noise. Good tuning and clear runbooks matter more than expensive tooling.
How is the SOC tested on the CISSP?
Domain 7: Security Operations covers SOC roles, tooling, procedures, and effectiveness metrics. Expect to connect the SOC to incident response, vulnerability management, and threat intelligence. CISA outlines foundational practices in its Cyber Essentials.
Related terms: SIEM, Incident Response