Skip to content
BoKSA

Start here — Studying Security Operations (CyBOK KA 8)

Start here — Studying Security Operations (CyBOK KA 8)

How to use this folder. The three BOKSA articles (8, 8.2-3, 8.4) are your map; this folder is the actual study material. Work through the numbered documents in order — each covers a part of the topic with one or two core resources. Total self-study: roughly half a day.

What you are studying

Security Operations & Incident Management (SOIM) is how organisations detect and respond to attacks that get past prevention. The whole field runs on one loop — Monitor, Analyse, Plan, Execute, Knowledge (MAPE-K). These documents:

  1. The MAPE-K loop and the vocabulary — the big picture: SOC, SIEM, IDS/IPS, DMZ, SOAR, CTI, and how they fit together. (matches article 8)
  2. Monitoring: the data sources — what a SOC watches (network, host, application logs) and how. (article 8.2-3)
  3. Analysis: misuse vs anomaly detection — how you turn data into alerts, and the base-rate fallacy. (article 8.2-3)
  4. SIEM: normalisation and correlation — how a SIEM brings it all together into incidents. (article 8.4)

The authoritative sources for the whole topic

All links in this folder were checked and working on 21 August 2026.