SOC
Also known as: Security Operations Center
A SOC (Security Operations Center) is the function that continuously monitors, assesses, and responds to a business's security events.
A SOC (Security Operations Center) is the organizational function that continuously watches a business's security events, triages them, and responds when an actual incident occurs. It brings people, processes, and tools like EDR or SIEM together into ongoing monitoring, instead of letting alerts pile up unwatched.
In practice, analysts continuously review incoming alerts, tell real incidents apart from false positives, and take predefined steps once an attack is confirmed, such as isolating an affected device. A SOC can exist as its own department, but the function is more commonly bought as a service from an outside provider that covers monitoring outside normal office hours too.
A common misconception is that a SOC is just software that reacts automatically. In reality, every security toolchain – EDR, SIEM, or otherwise – needs people to assess the alerts and decide what to do; without that ongoing review, a SOC is just a tool with nobody operating it.
What it means in practice
For a business, running its own around-the-clock SOC usually isn't practical, but having access to that function as an outsourced service is. A sign that it's missing is security tools generating alerts that nobody sees outside office hours. NDVDL brings SOC services into ongoing support where it makes sense for the business in question.
Is this handled properly at your site?
We look at how it actually stands with you — and say honestly whether anything needs doing.
Related terms
All termsA term from your quote missing here?
Send us the passage you do not follow. We will explain it — with no obligation to order anything.