An organisation's security operations team, whose job is watching for cyber threats and incidents, spotting them, analysing them and responding to them.
Also called security operations centre.
In the Ultra Transcenders books
Each book explains SOC in context, with comparison tables and the common traps.
Terms in this definition
- Security Operations
Found at Security > Security Operations in VCF Operations, this page gathers user and infrastructure security information in one place, including host encryption, security advisories and overall posture.
- Job
A sequence of steps executed together on one agent or runner, or on the server for agentless work. While running, each occupies one of your parallel jobs.
Related terms
- Resource-context RBAC
Lets teams outside the SOC see the Microsoft Sentinel data that comes from Azure resources they can already reach, opening it from the resource or from Azure Monitor, with no rights granted on the workspace itself.
- SecurityIncident
Each create or update of a Sentinel incident writes another row here, so it suits SOC metrics like time to close or triage. To see only the current state of every incident, summarise with arg_max.