Canadian Cyber Centre releases SOC best practices guidance, ITSAP.00.500
The Canadian Centre for Cyber Security has published ITSAP.00.500, guidance for organizations of all sizes on building, running and outsourcing a SOC.
The Canadian Centre for Cyber Security has published ITSAP.00.500, "Best practices for setting up a SOC," as part of its Awareness series. The document is dated September 2026 and is aimed at organizations of all sizes that are establishing, operating or improving a security operations center (SOC), as well as those considering buying the capability from a third party as SOC as a service (SOCaaS).
The publication is available on the Cyber Centre's website at Best practices for setting up a security operations centre (ITSAP.00.500).
The Cyber Centre defines a SOC as a combination of people, processes and technology that improves an organization's resilience against cyber threats. It is run from a central location by a team of information security professionals. The guidance names three roles in that team: security engineers, who may work closely with the development team, security analysts, and threat hunters. That detail matters for anyone budgeting a SOC, because it signals that the regulator sees the function as more than a monitoring desk staffed by tier-one analysts watching a dashboard.
On what a SOC actually does, the publication is direct. SOCs are primarily responsible for detecting and responding to cyber incidents and threats. The guidance also says SOCs can conduct vulnerability assessments, which places at least part of the proactive security work inside the SOC's remit rather than leaving it entirely with a separate team.
The Cyber Centre explains its reasoning for publishing now. It says many organizations are building SOC capabilities because cyber threats are evolving and becoming more sophisticated, and because the range of systems that need watching has grown. Three drivers are named specifically:
- increasing reliance on operational technology (OT) systems alongside information technology (IT) environments
- growing reliance on cloud services
- growing reliance on artificial intelligence (AI)-enabled systems
According to the publication, this convergence creates a greater need for continuous security monitoring and response. For Canadian organizations in energy, manufacturing, utilities and other sectors where OT and IT now share networks, that is a clear statement from the federal cyber authority that plant-floor systems belong in scope for security monitoring, not in a separate silo.
The guide's table of contents shows the ground it covers: how SOCs operate, SOC as a service, benefits of SOCs, considerations when establishing a SOC, using AI in a SOC, and a "Learn more" section. The inclusion of a dedicated section on SOCaaS is notable. The Cyber Centre says the publication provides guidance to organizations interested in subscribing to a SOC from a third-party provider, which acknowledges the reality that many small and mid-sized Canadian organizations will never staff a 24/7 in-house team and shouldn't be shamed for it.
The section on using AI in a SOC addresses the other side of the AI coin. The Cyber Centre lists AI-enabled systems as a source of expanded risk that a SOC must monitor, and it also devotes a section to AI as a tool the SOC itself can use. The full content of that section, and of the considerations section, is not reproduced in the material reviewed for this report, so the specific recommendations the Cyber Centre makes on AI tooling, staffing models, metrics or technology selection are not detailed here. Readers should consult the source document directly for those specifics.
ITSAP.00.500 is an awareness publication. Nothing in the material reviewed indicates that it introduces binding requirements, deadlines, reporting obligations or penalties. It is guidance, and the Cyber Centre frames it as best practice for establishing, operating and continuously improving a SOC. Organizations subject to sector-specific regulation in Canada should treat it as a reference point that regulators and auditors may expect them to be familiar with, rather than as a new rule in itself.
For identity and security teams, the practical question is whether the SOC, in-house or outsourced, can actually see identity. Check that authentication logs from your identity provider (Entra ID sign-in and audit logs, Okta System Log, Active Directory security events, cloud IAM logs such as AWS CloudTrail) are flowing into the SOC's SIEM and that analysts have detections for privilege escalation, MFA changes, new federation trusts and service account misuse, not just malware alerts. If you are evaluating a SOCaaS provider, ask them which identity sources they ingest by default and how they handle OT accounts, because a SOC that can see every packet but has no idea who is behind the keyboard is just an expensive way to watch a breach in high definition. The good news is that the Cyber Centre has now put SOC capability on the agenda for organizations of every size, so the conversation about funding proper identity telemetry just got a lot easier to start.
Be the first to comment
Members only: sign up if you have something worth saying.
Want to weigh in? Sign in or create a free account.
No comments yet.