Skip to content

Security Operations Centre (SOC)

What is Security Operations Centre (SOC)?

A centralised facility and team responsible for monitoring, detecting, analysing, and responding to cybersecurity incidents on a 24/7 basis. SOC teams use SIEM, EDR, and other tools to maintain security visibility across the organisation.

Information Security

Each of these is named in at least one of the same controls as security operations centre (soc). The number is how many controls name both.

What the standards actually require on security operations centre (soc)

Requirements naming security operations centre (soc) across 5 standards, quoted from the control text.

UR E26 Goal 3 (Detect) requires monitoring + detection capabilities to identify cyber incidents. Logging: all CBS log security-relevant events (authentication + authorization + configuration change + privileged action + network connection + failure);

IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting · IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM

NSS-17 + NSS-42-G require continuous monitoring + detection + incident response + recovery aligned with CSL. Logging: all CBS log security-relevant events (authentication + authorization + privileged action + configuration change + network connection + system...

IAEA-NSS17-Detect-Monitor-Logging-IR-Recovery-Exercises · IAEA NSS-17 - Detection + Monitoring + Logging + Incident Response + Recovery + Computer Security Exercises

Kuwait NCF Detect function. Security Monitoring and Logging: comprehensive logging (Identity + Network + Endpoint + Cloud + Application + Database + Privileged Access + Network Devices + Cloud Trail + Container + IoT/OT) + centralised log management + Security...

KNCF-Detect-Monitoring-SIEM-SOC-Threat-Intel-CTI-MITRE-ATT-CK-EDR-XDR-MDR-24-7-Continuous · Kuwait NCF Detect + Monitoring + SIEM + SOC + Threat Intel + EDR + XDR + 24/7

Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + c...

LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM · Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12

Lloyds Cyber Insurance Requirements - Risk Selection and Cyber Hygiene Underwriting Criteria. Underwriters must conduct rigorous risk selection + due diligence assessing insured-cyber hygiene including: (a) Mandatory cyber hygiene requirements (insurance-grade...

LLOYDS-CI-Risk-Selection-Cyber-Hygiene-Underwriting-Criteria-Pre-Bind-Risk-Engineering-MFA-Backup-EDR · Lloyds Cyber Insurance Risk Selection + Hygiene + Pre-Bind Engineering

Questions people ask about security operations centre (soc)

What is Security Operations Centre (SOC)?
A centralised facility and team responsible for monitoring, detecting, analysing, and responding to cybersecurity incidents on a 24/7 basis. SOC teams use SIEM, EDR, and other tools to maintain security visibility across the organisation.
Why is Security Operations Centre (SOC) important for compliance?
Security Operations Centre (SOC) is a key concept in Information Security. Understanding security operations centre (soc) helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Operations Centre (SOC)?
Security Operations Centre (SOC) appears in the requirement text of IACS Unified Requirements E26/E27 - Cyber Resilience of Ships and On-Board Systems, IAEA Nuclear Security Series - Computer Security at Nuclear Facilities (NSS-17-T Rev 1), Kuwait National Cybersecurity Framework, Lloyd's Minimum Standards - Cyber Security, Lloyd's of London Cyber Insurance Requirements and Underwriting Standards. Across these standards we have identified 5 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Operations Centre (SOC)?
Explore our compliance framework pages to see how security operations centre (soc) applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Operations Centre (SOC) applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.