1.3.1. People, Process, and Technology in the SOC
💡 First Principle: SOC maturity is measured by how much of the routine work is automated, how well the remaining human work is structured by process, and how effectively analysts can focus their judgment on the genuinely ambiguous threats.
A Tier 1 SOC analyst monitors dashboards and triages alerts — they handle high volume, follow playbooks, and escalate what doesn't fit. A Tier 2 analyst performs deeper investigation on escalated incidents. A Tier 3 analyst handles threat hunting, malware analysis, and complex incident response. This tiering isn't bureaucracy — it's efficiency. Tier 3 skills are expensive and scarce; using them for Tier 1 work is wasteful.
Process in the SOC means standardized playbooks for known threat types (phishing, malware, unauthorized access), defined escalation criteria, and documented response procedures. Playbooks reduce the cognitive load on analysts during stressful incidents and ensure nothing is missed.
Technology means SIEM (log aggregation and correlation), SOAR (automated response), EDR (endpoint visibility), and threat intelligence platforms — the tools covered in depth in Phase 2.
For the CySA+ exam, recognize that "efficiency and process improvement" (Objective 1.5) is about moving the boundary between automated and human work — automating what's repeatable so humans focus on what requires judgment.
⚠️ Exam Trap: SOAR automates the response to known, well-defined alert types. It does not replace analyst judgment for novel threats, complex investigations, or situations that don't match established playbooks. The exam distinguishes between automation-suitable and judgment-requiring scenarios.
Reflection Question: An organization receives 10,000 security alerts per day. Which types of alerts are best handled by automated SOAR playbooks, and which require human analyst investigation? What criteria distinguish the two?