Skip to content

Glossary

Define these before you count anything

Precision here is not pedantry. Every metric a SOC reports rests on the boundary between an event, a detection, an alert and an incident — and where those boundaries are undefined, the numbers cannot be defended.

Put the definitions in the report itself

Not in a separate document that nobody opens. A reader twelve months from now needs to know what you meant by “incident” in this edition — and if you change a definition mid-year, say so in the change history rather than letting the trend line quietly break.

The four that must be defined before any number is reported

These are not synonyms. If your report does not define them, every count in it is arguable.

Event
A change or message from a system, network or security component that may have significance for information security. Most events are not interesting. All of them are data.
Detection
An event, or a correlation of events, that a rule has identified as matching a pattern of concern. A detection is the output of your detection logic — not yet a judgement.
Alert
A detection that has been routed to a human for a decision. The distinction from detection matters: detections that never reach anyone are not alerts, and counting them as such overstates coverage.
Incident
An event, or set of events, that breaches or may breach information security — confidentiality, integrity, availability, or the provision of services. This is the point at which obligations attach.

Operational terms

False positive
An event that appears to be a threat but is determined not to be. A false positive that closes without a tuning decision will recur, at the same cost, indefinitely.
False negative
A real threat the detection stack did not catch. It cannot be observed by the stack itself, which is why efficacy testing exists.
Triage
The initial assessment establishing whether an event is significant and whether it is true. Triage produces a decision, and that decision is recorded either way.
Detection rule
The setting, algorithm or signature used to identify suspicious activity automatically. Every rule needs an owner, a response action and a review date.
Containment
Action taken to stop the spread or impact of an incident — isolation, process termination, access blocking, quarantine. Containment is not resolution.
Break-glass
A documented emergency path that exceeds normal authority, with mandatory immediate notification and an after-the-fact review. Untested break-glass is not a control.
Awareness time
The moment the organisation became aware of a significant incident. It is what the statutory reporting clock runs from, and it deserves a mandatory field.
Dwell time
How long an adversary was present before detection. The metric nobody wants to publish, and the one that most honestly describes detection capability.

Statutory terms — Lithuanian, with working English renderings

These are working translations, not official ones. Keep the Lithuanian term alongside the English so a reader can map back to the legal text.

Cybersecurity subjectKibernetinio saugumo subjektas
An entity that meets the identification criteria and is registered in the national cybersecurity information system. Duties attach from registration, not from meeting the criteria.
Essential / important subjectEsminis / svarbus subjektas
The two tiers of cybersecurity subject. The first attracts proactive supervision and the higher sanction ceiling; the second, reactive supervision.
Cybersecurity managerKibernetinio saugumo vadovas
The statutory appointment responsible for implementing the entity's compliance, directly accountable to the head, and expressly prohibited from performing system administration.
Security officerSaugos įgaliotinis
The equivalent appointment scoped to a specific network and information system.
Security Operations CentreSaugumo operacijų centras
In national law, the group of persons appointed by the head of the entity to perform the incident detection, logging and incident-management functions — and required to be independent of those responsible for operating the systems it monitors.
Large cyber incidentDidelis kibernetinis incidentas
The national term corresponding to a significant incident under the directive. The national thresholds are what actually determine classification in Lithuania.
Cybersecurity requirements descriptionKibernetinio saugumo reikalavimų aprašas
The government act carrying the operative organisational and technical requirements — log retention, monitoring, detection and account hygiene among them.

Roles and functions

SOC Officer
Used on this site for the person accountable for the SOC as a function. Depending on the organisation this may or may not be the statutory cybersecurity manager — the two are related but not identical, and the eligibility criteria attach only to the statutory role.
Incident commander
The person holding decision rights during an incident: containment approval, communication ownership, and the call on when it is over.
Detection engineering
The function that builds, tests, tunes and retires detection content. Separated from the duty roster because otherwise the queue always wins.
Managed detection and response
A productised package of detection plus defined response rights and service commitments, usually delivered by a provider. It changes who does the work, not who is accountable for it.