Ends tomorrow! Save on skills that make you shine with 40% off 3 months of Coursera Plus. Save now

Cisco Learning and Certifications

Security Operations Center (SOC)

36,153 already enrolled

Included with Coursera Plus

Gain insight into a topic and learn the fundamentals.

360 reviews

1 week to complete
at 10 hours a week
Flexible schedule
Learn at your own pace
98%
Most learners liked this course
Gain insight into a topic and learn the fundamentals.

360 reviews

1 week to complete
at 10 hours a week
Flexible schedule
Learn at your own pace
98%
Most learners liked this course

91%

of learners achieved a positive career outcome

See how employees at top companies are mastering in-demand skills

 logos of Petrobras, TATA, Danone, Capgemini, P&G and L'Oreal

Build your subject-matter expertise

This course is part of the Cybersecurity Operations Fundamentals Specialization
When you enroll in this course, you'll also be enrolled in this Specialization.
  • Learn new concepts from industry experts
  • Gain a foundational understanding of a subject or tool
  • Develop job-relevant skills with hands-on projects
  • Earn a shareable career certificate

There are 8 modules in this course

In this module, you will explore what a Security Operations Center, or SOC, does and how SOC team members support day-to-day security monitoring and response. You will identify common threat actors, their motivations, and the assets and systems they target. You will also examine why organizations implement SOCs, the business value they provide, and the technical and procedural challenges SOCs commonly face.

What's included

6 videos6 readings4 assignments

In this module, you will examine the core responsibilities of a Security Operations Center (SOC) and how it works with other teams across the organization. You will place the SOC within the incident response lifecycle, from detection through recovery. You will also outline the key services a SOC provides across each incident response phase.

What's included

4 videos4 readings3 assignments

In this module, you will distinguish common SOC types (for example, internal, outsourced, and hybrid) and the staffing considerations that shape each, such as roles, coverage models, and escalation paths. You will also compare SOC deployment models (on‑premises, cloud, and managed services) and connect each to typical consumer profiles based on needs like cost, control, scalability, and response expectations.

What's included

4 videos8 readings3 assignments

In this module, you will examine the core roles on an effective SOC team and how each role supports incident response. You will outline the key skills expected for common SOC positions and the primary tools each role relies on. You will also identify how SOC team members coordinate with one another and communicate with external groups during an incident.

What's included

4 videos7 readings3 assignments

In this module, you will identify the types of data a Security Operations Center (SOC) relies on and how security event data fits into SOC monitoring and analysis. You will distinguish SOC-relevant data sources and the kinds of events they produce. You will also review common SOC tools and the key features that support collecting, correlating, and analyzing security data.

What's included

5 videos14 readings3 assignments

In this module, you will identify the external intelligence resources, regulatory bodies, and government and industry organizations a SOC communicates with. You will outline how these relationships support security operations and coordination across stakeholders. You will also describe the key policies, procedures, and governance rules that guide SOC engagement with users, HR, and legal when violations are detected.

What's included

4 videos6 readings3 assignments

In this module, you will focus on how SOC metrics are used to measure and communicate SOC effectiveness. You will examine core ideas behind security data aggregation and how it supports consistent reporting. You will explore Time to Detection (TTD) in a network security context and what it indicates about detection performance. You will consider how to describe the detection effectiveness of security controls using SOC-focused metrics.

What's included

6 videos6 readings5 assignments

In this module, you will describe core SOC workflow management system (WMS) concepts and their role in security operations. You will outline how a typical workflow management system is integrated within a SOC. You will describe what SOC WMS integration involves across tools and processes. You will provide an example of how SOC workflow automation is applied in practice.

What's included

7 videos14 readings5 assignments

Earn a career certificate

Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.

Instructor

Instructor ratings
(103 ratings)
Cisco Learning & Certifications
28 Courses100,959 learners

Offered by

Explore more from Security

Why people choose Coursera for their career

Felipe M.

Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."

Jennifer J.

Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."

Larry W.

Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."

Chaitanya A.

"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."

Learner reviews

  • 5 stars

    84.76%

  • 4 stars

    12.18%

  • 3 stars

    1.10%

  • 2 stars

    0.83%

  • 1 star

    1.10%

Showing 3 of 360

LS

Reviewed on May 14, 2025

BG

Reviewed on Aug 21, 2023

NJ

Reviewed on Feb 9, 2025

Frequently asked questions