ماذا يفعل SOC فعلاً؟What does a SOC actually do?
أربع وظائف يومية: جمع وتحليل سجلات الأنظمة والشبكة، رصد الأنشطة المشبوهة وربطها ببعضها، التحقيق في التنبيهات لتحديد ما هو حقيقي، والاستجابة الأولية للتهديدات. القيمة ليست في الأدوات بل في القدرة على التمييز بين الضوضاء والتهديد الحقيقي.Four daily functions: collecting and analysing system and network logs, detecting and correlating suspicious activity, investigating alerts to separate real threats, and performing initial response. The value is not in the tools but in the ability to distinguish noise from a genuine threat.
متى تحتاجه فعلاً؟When do you actually need one?
تحتاج SOC إذا: كنت تتعامل مع بيانات حساسة أو تخدم عملاء مؤسسيين، أو تعمل في قطاع منظّم، أو لديك بنية معقدة متعددة الأنظمة، أو كنت هدفاً محتملاً لكونك جزءاً من سلسلة توريد. لا تحتاجه إذا كان حجمك صغيراً وأصولك محدودة — خدمة مُدارة أخفّ وأوفر.You need a SOC if: you handle sensitive data or serve enterprise clients, operate in a regulated sector, run a complex multi-system environment, or are a plausible target as part of a supply chain. You do not need one if you are small with limited assets — a managed service is lighter and cheaper.
SOC داخلي أم خدمة مُدارة؟Internal SOC or managed service?
SOC داخلي يستلزم فريقاً مناوباً على مدار الساعة (8-12 مهندساً على الأقل لثلاث ورديات)، وأدوات، وتدريباً مستمراً — تكلفة عالية. الخدمة المُدارة توفّر المراقبة على مدار الساعة بتكلفة شهرية معتدلة، لكن قد تعرف بيئتك أقل. الحل الهجين شائع: مراقبة مُدارة مع محلل داخلي للتحقيق.An internal SOC requires a round-the-clock team (at least 8–12 engineers across three shifts), tooling and continuous training — a high cost. A managed service provides 24/7 monitoring at a moderate monthly cost but may know your environment less deeply. A hybrid is common: managed monitoring with an internal analyst for investigation.
المكونات التقنية الأساسيةCore technical components
أربعة مكونات: منصة إدارة الأحداث والمعلومات الأمنية (SIEM) لتجميع السجلات وربطها، منصة كشف واكتشاف (EDR) على الأجهزة، أتمتة للاستجابة (SOAR) لتقليل العمل اليدوي، وقاعدة معرفة بالتهديدات. الأهم هو جودة السجلات المُغذّاة — منصة جيدة ببيانات سيئة لا ترى شيئاً.Four components: a SIEM platform to aggregate and correlate logs, an EDR platform on endpoints, automation for response (SOAR) to reduce manual work, and a threat-intelligence feed. What matters most is the quality of the logs fed in — a good platform with poor data sees nothing.
مؤشرات قياس الفاعليةMetrics for measuring effectiveness
قِس: زمن الكشف (كيف تُكتشف التهديدات بسرعة)، زمن الاحتواء، نسبة التنبيهات الحقيقية إلى الإجمالي (لتفادي إنهاك المحللين)، ونسبة الحوادث التي اكتُشفت داخلياً مقابل التي أبلغ عنها طرف خارجي. إذا كان معظم ما تكتشفه يأتي من الخارج، فمركزك لا يعمل.Measure: detection time (how fast threats are found), containment time, the ratio of true alerts to total (to avoid analyst fatigue), and the share of incidents discovered internally versus reported by an outsider. If most of what you discover comes from outside, your SOC is not working.
البدء العمليStarting practically
لا تبدأ ببناء SOC كامل. ابدأ بتغطية الأصول الحرجة فقط، وتأكد من أن سجلاتها تصل وتحلّلها، ثم وسّع التغطية تدريجياً. SOC يغطي 20% من الأصول بكفاءة أفضل من SOC يغطي 100% بلا تحليل حقيقي.Do not start by building a full SOC. Begin with coverage of critical assets only, ensure their logs arrive and are analysed, then expand coverage gradually. A SOC covering 20% of assets effectively beats one covering 100% with no real analysis.

