Start here — Studying Security Operations (CyBOK KA 8)
How to use this folder. The three BOKSA articles (8, 8.2-3, 8.4) are your map; this folder is the actual study material. Work through the numbered documents in order — each covers a part of the topic with one or two core resources. Total self-study: roughly half a day.
What you are studying
Security Operations & Incident Management (SOIM) is how organisations detect and respond to attacks that get past prevention. The whole field runs on one loop — Monitor, Analyse, Plan, Execute, Knowledge (MAPE-K). These documents:
- The MAPE-K loop and the vocabulary — the big picture: SOC, SIEM, IDS/IPS, DMZ, SOAR, CTI, and how they fit together. (matches article 8)
- Monitoring: the data sources — what a SOC watches (network, host, application logs) and how. (article 8.2-3)
- Analysis: misuse vs anomaly detection — how you turn data into alerts, and the base-rate fallacy. (article 8.2-3)
- SIEM: normalisation and correlation — how a SIEM brings it all together into incidents. (article 8.4)
The authoritative sources for the whole topic
- CyBOK KA 8 — Security Operations & Incident Management (Debar, v1.0.2) — the reference text. Dense; look things up, don't read cover to cover.
- CyBOK SOIM webinar slides — the KA walked through by the CyBOK team.
- MITRE ATT&CK — the shared catalogue of real attacker tactics; the language a SOC uses to describe what it sees.
All links in this folder were checked and working on 21 August 2026.