Security Operations
What is Security Operations?
The day-to-day activities of monitoring, detecting, investigating, and responding to cybersecurity threats and incidents.
Terms that appear alongside security operations
Each of these is named in at least one of the same controls as security operations. The number is how many controls name both.
- incident response 9 shared controls
- authentication 7 shared controls
- vulnerability 5 shared controls
- integrity 5 shared controls
- cybersecurity 5 shared controls
- threat intelligence 4 shared controls
- security monitoring 4 shared controls
- log retention 4 shared controls
Frameworks that govern security operations
What the standards actually require on security operations
Requirements naming security operations across 6 standards, quoted from the control text.
Establish and maintain a security operations center that operates 24/7, with allowance for remote/on-call staff.
3.6.1e · Establish Security Operations Center (SOC) →Give security operations the context to prioritise incidents, combining alert severity with the sensitivity of the affected asset as defined in the incident response plan.
ASBv3-IR-5 · Detection and analysis - prioritize incidents →NSS-17 + NSS-42-G require comprehensive access control aligned with CSL: unique user identification + no shared accounts where feasible (emergency shared accounts logged + reviewed);
IAEA-NSS17-AccessControl-OT-IT-Authentication-Authorization · IAEA NSS-17 - Access Control + Authentication + Authorization + IAM + Privileged Access for OT and IT →ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Info...
ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities · ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities →Conduct an annual audit of the Facility Security Plan and supporting security operations, including cyber controls, with documented scope, methodology, findings, and corrective action plans submitted to facility leadership and the FSO.
MTSA-Audit · Annual Audit of the Security Plan →Operations and management interfaces to 5G NFs must be authenticated, encrypted, and logged. Administrative access requires strong authentication, role separation, and privileged access management.
33.501-OAM · Management Plane Security →Questions people ask about security operations
What is Security Operations?
Why is Security Operations important for compliance?
Which compliance frameworks address Security Operations?
Where can I learn more about Security Operations?
See how Security Operations applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.