The security operations domain focuses on the *investigation of a potential data breach* and the *implementation of preventative measures* after a security incident has occurred. This includes using strategies, processes, and tools such as: - Training and awareness - Reporting and documentation - Intrusion detection and prevention - [[Security Information and Event Management|SIEM]] tools - Log management - Incident management - [[Playbooks]] - Post-breach forensics - Reflecting on lessons learned The cybersecurity professionals involved in this domain work as a team to manage, prevent, and investigate threats, risks, and vulnerabilities. These individuals are trained to handle active attacks, such as large amounts of data being accessed from an organisation's internal network, outside of normal working hours. Once a threat is identified, the team works diligently to keep private data and information safe from threat actors.