Infrastructure
Do you have a Security Operations Center (SOC)?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Describe your security monitoring capability, whether an in-house SOC, a managed detection-and-response provider, or a hybrid, and its coverage hours. Explain how alerts are triaged and escalated.What the security reviewer is checking
The reviewer is really asking who is watching your environment and how fast they respond — not whether you have a room full of analysts. It is entirely acceptable (and common for cloud-native companies) not to run a formal in-house SOC, provided you can describe the monitoring function that replaces it: what telemetry is collected, how alerts are triaged, what your on-call coverage looks like, and whether a managed detection and response (MDR) partner extends coverage around the clock. What fails review is claiming "24/7 SOC" and then being unable to name staffing, tooling, or escalation paths during a follow-up call.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.We operate a security monitoring function rather than a traditional standalone SOC, and it provides continuous coverage of our production environment. Security-relevant telemetry — cloud audit logs, application logs, authentication events, and endpoint detection and response (EDR) alerts — is centralized in our SIEM, where detection rules generate alerts routed to an on-call rotation with 24/7 paging. High-severity alerts have a 15-minute acknowledgment target, and our incident response plan defines escalation from the on-call engineer to the security lead and executive team. For around-the-clock triage depth we partner with a managed detection and response provider that investigates alerts and can initiate containment. Detection coverage and alert quality are reviewed monthly, and response procedures are exercised through incident response tabletop tests at least annually.
Evidence reviewers expect you to attach
- Security monitoring or logging policy describing telemetry sources and retention
- MDR/MSSP contract summary or service description, if a partner provides coverage
- On-call rotation and escalation documentation from your incident response plan
- SOC 2 report section covering monitoring controls (CC7.2, CC7.3)
- Sample alert-to-resolution timeline from a past incident or exercise (sanitized)
Follow-up questions reviewers ask next
- What are your alert acknowledgment and response time targets by severity?
- Which log sources feed your SIEM, and how long are logs retained?
- Is monitoring coverage 24/7, and who responds outside business hours?
- Do you use an MDR or MSSP, and what is their scope of authority to act?
- How do you test and tune detection rules for coverage gaps?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated infrastructure questions
Where is your infrastructure hosted (AWS, GCP, Azure)?Do you use a web application firewall (WAF)?How do you protect against DDoS attacks?Do you have logging and monitoring in place?How do you secure your CI/CD pipeline?What vulnerability scanning do you perform?
Browse the full security questionnaire question library