SOC
検出エンジニアリング
The discipline of designing, implementing, and tuning security monitoring rules, analytics, and automation to identify threats with accuracy and minimal false positives.
Quick answer: The discipline of designing, implementing, and tuning security monitoring rules, analytics, and automation to identify threats with accuracy and minimal false positives.
This term page is part of the Protermify Cybersecurity glossary and is published as static HTML for fast indexing and clear language coverage.
Definition
The discipline of designing, implementing, and tuning security monitoring rules, analytics, and automation to identify threats with accuracy and minimal false positives.
Operational example
Detection engineering allowed the SOC to refine alert logic and improve the quality of actionable security alerts.
Localized term
検出エンジニアリング
Localized example
検出エンジニアリングによりSOCはアラートロジックを洗練し、実用的なセキュリティアラートの質を高めることができた。
Definition language
English reference definition
Source
ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK
Exam relevance
- CISSP
- CompTIA Security+
- CEH
Target audience
- SOC Analysts
- Security Engineers
- Incident Responders