Skip to content
IT Atlas

Security · Security Operations

Security Operations

The people, process and platform that monitor, triage, investigate and respond to security events continuously.

IntermediateUpdated 2026-09-01

Overview

A security operations function turns telemetry into decisions. Whether it is a 24/7 in house SOC, a hybrid model, or an MDR partnership, the same components exist: data collection, detection engineering, triage, investigation, response and continuous improvement.

Operating model choice matters more than tooling. Small teams should optimise for high signal detections and a strong partner relationship rather than attempting round the clock staffing.

Sequence

SOC value chain
  1. 1Telemetry
  2. 2Collection
  3. 3SIEM / XDR
  4. 4Detection
  5. 5Investigation
  6. 6Response
  7. 7Improvement

Layer model

Data sources
EndpointsIdentityEmailNetworkCloud control planesApplicationsFirewallsDNSSaaS audit logs
Functions
Triage (Tier 1)Investigation (Tier 2)Hunting and detection engineeringIncident commandThreat intelligenceAutomation
Measures
Time to detectTime to containDetection coverage by techniqueFalse positive rateEscalation quality

Security considerations

  • Define severity and escalation before go live, including who may authorise containment actions.
  • Track coverage against ATT&CK and close gaps as a backlog, not an aspiration.
  • Automate enrichment first, it saves analyst time with far less risk than automated blocking.

Common misconfigurations

  • Alerts delivered to email rather than a queue with ownership and SLA.
  • Response actions available in tooling but not permitted by process, so analysts wait hours for approval.
  • No feedback loop from incidents into detection improvements.