Security operations centre (SOC)
A function responsible for monitoring, investigation and coordination. Staffing, hours, scope and authority depend on the operating model.
Security information and event management (SIEM)
A platform for collecting and analysing event data. Buying it does not establish who monitors it or handles incidents.
Endpoint detection and response (EDR)
Technology to observe endpoint activity and support investigation or response. Coverage, configuration and ownership determine its use.
Virtual CISO (vCISO)
An external leadership arrangement with defined responsibilities, time commitment, reporting and decision authority.
Incident response retainer
A contracted arrangement for response capability with specified mobilisation, capacity, exclusions and fees.
Co-managed service
Internal staff and a provider share defined responsibilities and handover points.
Service acceptance
Agreed evidence that a service is ready, such as source coverage, working access and an escalation exercise.
Service-level agreement
Defined commitments and measurement rules. Acknowledgement, investigation and containment are different clocks.

