# What is a Security Operations Center (SOC)?

> A security operations center (SOC) is the people, processes, and technology responsible for continuously monitoring an organization’s digital environment and coordinating the detection, investigation, and response to security incidents.

- Canonical URL: https://yellowcube.eu/glossary/security-operations-center/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

A SOC is an operational capability, not necessarily a physical room: it may be internal, outsourced, distributed across several locations, or delivered through a hybrid model.

The SOC normally brings together security telemetry, analysts, investigation procedures, threat intelligence, and response playbooks. Its effectiveness depends less on the number of dashboards it owns than on useful visibility, clear decision rights, skilled staff, and the ability to contain threats safely.

### Key points

- **Primary purpose:** Turn security signals into prioritized investigations and timely action.
- **Typical responsibilities:** Monitoring, alert triage, threat hunting, incident coordination, detection engineering, reporting, and continuous improvement.
- **Operating models:** In-house, co-managed, outsourced, or shared across a group of organizations.
- **Important limitation:** A SOC cannot reliably detect activity that its tools cannot see, and it should not be judged only by alert volume or nominal 24/7 coverage.

### Related terms

[Managed detection and response (MDR)](<https://yellowcube.eu/glossary/managed-detection-and-response/>) · [Security information and event management (SIEM)](<https://yellowcube.eu/glossary/security-information-and-event-management/>) · [Security orchestration, automation and response (SOAR)](<https://yellowcube.eu/glossary/security-orchestration-automation-and-response/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/>) · [Security metrics](<https://yellowcube.eu/glossary/security-metrics/>)

### Sources

[NIST SP 800-61r3: Incident Response Recommendations](https://csrc.nist.gov/pubs/sp/800/61/r3/final) · [NIST SP 800-53 Rev. 5: Security and Privacy Controls](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

