To avoid ambiguity, UTIOM uses the following definitions:
Security Operations (SecOps): The overall organizational capability to detect, respond, and continuously reduce cyber risk in operational reality.
SOC: The organizational function (internal, external, or hybrid) responsible for executing part of SecOps.
Incident Response (IR): The structured capability to prepare for, detect, analyze, contain, eradicate, recover, and learn from incidents.
Detection Engineering: The engineering discipline that designs and maintains detection logic, telemetry requirements, testing, and automation as a lifecycle.
Threat-Informed: Decisions are prioritized based on realistic adversary behaviors and business risk, not generic best practice.
Adineh, R. (2026). Terminology and Scope. UTIOM Framework
Book, edition 1.2. utiom.de/book/terminology/