SECAI Core · phase 9 of 15
Security operations center
The location where security professionals monitor and protect critical information assets in an organization.
The Explain card
- Plain English
- A security operations center (SOC) is where security professionals monitor, detect and respond to threats against an organisation's critical information assets.
- Example
- A SOC analyst receives an alert from the AI gateway: one API key has generated hundreds of prompts containing known jailbreak phrases in ten minutes. The analyst correlates it with login logs, confirms the key was leaked, revokes it, and opens an incident.
- Why it matters
- AI systems generate new kinds of telemetry: prompt logs, guardrail hits, model-output anomalies. Defenders need the SOC to ingest and understand these signals, not just firewall and endpoint data.
- Hook
- The control room where the alarms actually get answered.
Where it sits in the deck
Phase 9: Roles, Teams, and Organisational Accountability
Governance frameworks are executed by people — introduce the human roles and organisational structures responsible for building, operating, and auditing AI systems.