Using AI Safely in a Security Operations Centre
Completion requirements

Scenario
A Security Operations Centre (SOC) wants to use AI to triage alerts, summarise investigations, and assist analysts. The objective is not to replace analysts; it is to make well-governed decisions faster while preserving evidence, privacy, and accountability.
Learning outcomes
- Choose low-risk, high-value AI use cases for detection engineering and incident response.
- Design human-in-the-loop review for recommendations that affect users, systems, or investigations.
- Define quality, security, and privacy checks for AI-generated SOC output.
Watch: AI-assisted cyber defence
- — background on using AI for defensive cyber work.
- — use as a discussion prompt: what telemetry, controls, and review points would your SOC need?
Read: operational guidance
- NIST AI 600-1: Generative AI Profile — risk considerations to carry into operational AI use.
- Microsoft Security for AI: Protect — examples of posture management and threat protection for AI workloads.
- CISA Roadmap for AI — public-sector perspective on AI safety, security, and resilience.
Book shelf
- Machine Learning and Security, Clarence Chio and David Freeman — connects security workflows with practical ML concepts.
- AI Engineering, Chip Huyen — relevant for evaluation, observability, and operating AI applications.