soc30 / lms
connected
dashboard
WEEK_1 · DAY_01 · 1 HOUR

Introduction to the SOC

What a Security Operations Center is, why it exists, and how it delivers value

Splunk Lab

Learning Objectives

  • Define a SOC and its mission
  • Understand the threat landscape SOCs defend against
  • Identify SOC business outcomes (MTTD, MTTR, risk reduction)
  • Differentiate SOC vs NOC vs IT support

Module 1 — What is a SOC?

A Security Operations Center is a centralized function — people, process, technology — that continuously monitors, detects, analyzes, and responds to cyber threats across an organization.

SOCs operate 24/7/365 and are the operational arm of the security program. They turn raw logs into decisions and actions.

Models: in-house, MSSP (managed), MDR (managed detection & response), hybrid, virtual SOC.

Module 2 — Why Companies Build SOCs

Regulatory pressure: PCI-DSS, HIPAA, SOX, GDPR, NIS2, ISO 27001 all require monitoring & incident response.

Risk reduction: average breach cost is USD 4.88M (IBM 2024); a mature SOC reduces dwell time from months to hours.

Brand & customer trust: a fast, transparent breach response preserves reputation.

Module 3 — SOC vs NOC vs IT Support

NOC watches availability and performance (uptime, latency, capacity).

IT Support fixes user-reported issues (password resets, hardware).

SOC watches security signals — adversary activity, policy violations, indicators of compromise.

All three sit in operations; only the SOC has an adversary on the other side.

Module 4 — Threat Landscape 2025

Top categories: ransomware-as-a-service, identity-driven attacks, supply chain, cloud misconfigurations, AI-augmented phishing.

Adversaries: nation-state APTs, financially motivated crime groups, hacktivists, insiders.

Identity-driven breaches take 292 days to identify and contain on average.

Lab 1 — Tour the SOC Platform

  1. Open the LMS dashboard and skim the 30-day curriculum.
  2. Open the Splunk ES lab and click each top-level tab (Posture, Incident Review, Search…).
  3. Write a 4-line definition of a SOC in your own words.
  4. List 5 outcomes a SOC delivers to the business.
Launch Lab Workbench

Key Takeaways

  • A SOC is people + process + technology operating 24/7 against an active adversary
  • MTTD and MTTR are the universal SOC scoreboards
  • Splunk Enterprise Security is today's industry-standard SIEM