Short answer
Security operations detects, investigates, and coordinates responses to security events using defined evidence and procedures. It provides a fair ladder from guided alert handling to cross-team detection and response standards.
About Security operations
Detects, investigates, and coordinates responses to security events using defined evidence and procedures. The competency measures event handling and response improvement, not every preventive security control.
Use this competency for
- Roles that monitor alerts, investigate security events, or coordinate containment and recovery.
- Functions accountable for detection quality, case evidence, response procedures, or security event follow-up.
Do not use this competency for
- Roles limited to preventive control design with no security event monitoring or response responsibility.
Important distinctions
Identity management
Identity management governs identities and permissions. Security operations investigates and responds when observed activity may indicate a security event.
Risk management
Risk management evaluates possible future exposure. Security operations handles observed signals and coordinates action on active or suspected events.
Expectations by level
IC1
Handles defined alerts
Triages well-defined security alerts with guidance, follows evidence and escalation procedures, and maintains a complete case timeline.
Observable behaviors
- Validates alert context against the current triage steps.
- Preserves relevant evidence and records each action taken.
- Escalates when scope or severity exceeds the defined boundary.
Examples
- Closed a known false positive after attaching the expected verification evidence.
- Escalated suspicious sign-in activity with affected identities, times, and source data.
IC2
Investigates events
Independently investigates ambiguous security events, coordinates scoped containment and recovery, and improves detections or procedures from case evidence.
Observable behaviors
- Builds and tests competing explanations from available evidence.
- Coordinates response owners without altering evidence needed for review.
- Updates a detection or playbook after documenting a confirmed gap.
Examples
- Linked endpoint and identity events to define the affected scope before containment.
- Adjusted a noisy detection after reviewing closed cases and testing the revised condition.
IC3
Sets response standards
Defines detection and response standards across teams, frames unfamiliar event patterns, and directs complex investigations through clear evidence and decision points.
Observable behaviors
- Defines case quality, severity, and escalation standards.
- Reviews detection coverage against observed event patterns.
- Leads cross-team response decisions with assumptions and evidence recorded.
Examples
- Created one severity model after teams used conflicting escalation thresholds.
- Directed an investigation across several systems and left a tested improvement plan for detection gaps.