# SOC Foundations for Federal Cyber Defense and Operations Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/soc-foundations-for-federal-cyber-defense-and-operations-self-paced>

## Overview

This course prepares analysts to operate effectively inside a federal Security Operations Center. It's built both for people new to SOC work and for analysts already doing the job who need to solidify the federal standards and terminology behind what they do day to day. What separates this course from generic SOC training is that every operational topic — log collection, continuous monitoring, detection engineering, incident response — is grounded in the statutes, policy memoranda, and technical standards that actually govern federal cyber defense.

## What you'll learn

- How FISMA, OMB policy, NIST guidance, and CISA directives fit together to govern federal SOC operations
- SOC organizational models and Tier 1–3 responsibilities, mapped to the NICE Workforce Framework
- The log sources a federal SOC must collect, and current requirements under OMB M-26-14
- Detection engineering and MITRE ATT&CK coverage mapping, applied to alert triage and prioritization
- The incident response lifecycle under NIST SP 800-61 Rev. 3 and the CISA federal response playbooks
- Federal incident reporting obligations, and how SOC findings connect to RMF and the ATO lifecycle
- SOC performance metrics, the common toolset, and career pathways mapped to DoD 8140.03

## Curriculum

#### Module 1

Foundations of Federal Cybersecurity & the SOC Mission

#### Module 2

SOC Team Structure, Roles & Responsibilities

#### Module 3

Log Collection & Federal Logging Standards

#### Module 4

Continuous Monitoring & Detection Engineering

#### Module 5

Incident Response Workflow — NIST SP 800-61 Rev. 3

#### Module 6

Reporting, Coordination & Compliance

#### Module 7

SOC Metrics, Tools & Career Pathways

## Pricing

**Tuition:** $1249
