← Book contents
TERMINOLOGY AND SCOPE Book · edition v1.2

Terminology and Scope

To avoid ambiguity, UTIOM uses the following definitions:

Security Operations (SecOps): The overall organizational capability to detect, respond, and continuously reduce cyber risk in operational reality.

SOC: The organizational function (internal, external, or hybrid) responsible for executing part of SecOps.

Incident Response (IR): The structured capability to prepare for, detect, analyze, contain, eradicate, recover, and learn from incidents.

Detection Engineering: The engineering discipline that designs and maintains detection logic, telemetry requirements, testing, and automation as a lifecycle.

Threat-Informed: Decisions are prioritized based on realistic adversary behaviors and business risk, not generic best practice.

Cite this chapter: Adineh, R. (2026). Terminology and Scope. UTIOM Framework Book, edition 1.2. utiom.de/book/terminology/
← Back to book contents

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →