{"id":1199,"date":"2026-09-13T17:39:16","date_gmt":"2026-09-13T17:39:16","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1199"},"modified":"2026-09-13T17:39:16","modified_gmt":"2026-09-13T17:39:16","slug":"soar","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/soar\/","title":{"rendered":"SOAR"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SOAR\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">SOAR exists because most companies own a dozen security tools that cannot talk to each other. The orchestration layer is a fix for a problem the stack created.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Detection<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>SOAR stands for security orchestration, automation and response. It connects separate security tools, runs defined sequences of steps against incoming alerts without a human performing each one, and executes containment actions. The output is meant to be fewer manual hours per alert and a consistent, recorded response every time.<\/p>\n<\/div>\n\n<p>The category delivers when the process was already sound. It fails, expensively, when the process was not.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#letters\">The three capabilities<\/a><\/li>\n    <li><a href=\"#playbook\">What a playbook actually runs<\/a><\/li>\n    <li><a href=\"#fails\">Where SOAR fails<\/a><\/li>\n    <li><a href=\"#versus\">SOAR, SIEM and XDR<\/a><\/li>\n    <li><a href=\"#osto\">Where Osto fits<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"letters\">The three capabilities<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Capability<\/th><th>What it means in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Orchestration<\/td><td>Connecting tools that were never designed to work together, so an action in one can be triggered by a finding in another. This is integration plumbing, and it is the part that ages<\/td><\/tr>\n    <tr><td>Automation<\/td><td>Running the repetitive steps without a person: gathering context, checking reputation, looking up the asset owner, opening the ticket<\/td><\/tr>\n    <tr><td>Response<\/td><td>Taking the containment action itself, such as isolating a device, disabling an account or blocking an address, either automatically or on approval<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Orchestration is the letter worth examining before buying. Its value is directly proportional to how fragmented the estate already is. A team running four tools from one vendor needs far less of it than a team running fourteen from nine.<\/p>\n\n<h2 id=\"playbook\" class=\"c-sage\">What a playbook actually runs<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 182\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"A SOAR playbook running from alert through enrichment and decision to containment and record.\">\n  <defs><marker id=\"so\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"10\" y=\"26\" width=\"132\" height=\"76\" rx=\"12\" fill=\"#e2eff7\"\/>\n  <text x=\"76\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6f96\">Alert<\/text>\n  <text x=\"76\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Impossible travel<\/text>\n  <line x1=\"146\" y1=\"64\" x2=\"162\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#so)\"\/>\n\n  <rect x=\"168\" y=\"26\" width=\"132\" height=\"76\" rx=\"12\" fill=\"#e3f0e9\"\/>\n  <text x=\"234\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Enrich<\/text>\n  <text x=\"234\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Device, role, history<\/text>\n  <line x1=\"304\" y1=\"64\" x2=\"320\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#so)\"\/>\n\n  <rect x=\"326\" y=\"26\" width=\"132\" height=\"76\" rx=\"12\" fill=\"#efe4f0\"\/>\n  <text x=\"392\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Decide<\/text>\n  <text x=\"392\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Auto or ask a human<\/text>\n  <line x1=\"462\" y1=\"64\" x2=\"478\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#so)\"\/>\n\n  <rect x=\"484\" y=\"26\" width=\"132\" height=\"76\" rx=\"12\" fill=\"#fbe9dc\"\/>\n  <text x=\"550\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">Contain<\/text>\n  <text x=\"550\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Revoke, isolate, block<\/text>\n  <line x1=\"620\" y1=\"64\" x2=\"636\" y2=\"64\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#so)\"\/>\n\n  <rect x=\"642\" y=\"26\" width=\"108\" height=\"76\" rx=\"12\" fill=\"#cfd5f2\"\/>\n  <text x=\"696\" y=\"56\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Record<\/text>\n  <text x=\"696\" y=\"77\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10\" fill=\"#0f1538\">Timeline, evidence<\/text>\n\n  <rect x=\"10\" y=\"120\" width=\"740\" height=\"46\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"380\" y=\"140\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">The middle two steps are where the hours go and where automation pays.<\/text>\n  <text x=\"380\" y=\"157\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#3f4796\">The last step is what an auditor asks to see, and the one teams most often skip.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<p>Enrichment is the honest win. An analyst manually collecting device, owner, role and recent history for every alert spends most of their day on lookups. That work is deterministic, so it automates cleanly and safely.<\/p>\n\n<h2 id=\"fails\" class=\"c-plum\">Where SOAR fails<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Failure<\/th><th>How it happens<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Playbook rot<\/td><td>A playbook is written once against the environment of that quarter. Tools change, APIs change, the playbook silently stops working or fires on the wrong condition<\/td><\/tr>\n    <tr><td>Integration maintenance<\/td><td>Every connector is a dependency owned by somebody. In a small team, nobody is that somebody after the first month<\/td><\/tr>\n    <tr><td>Automating an undefined process<\/td><td>If the manual response was inconsistent, automating it produces fast, consistent, wrong outcomes<\/td><\/tr>\n    <tr><td>Blast radius<\/td><td>Automated containment that disables accounts on a noisy detection can take out a team during a false positive. The fear of this leaves most playbooks stuck at notify only<\/td><\/tr>\n    <tr><td>Bought to fix alert volume<\/td><td>Automation applied to a bad signal produces automated noise. Tuning detection first is cheaper and more effective<\/td><\/tr>\n    <tr><td>Nobody left who wrote it<\/td><td>Playbooks are code without the review discipline of code, and they outlive their authors<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Automate the lookup before automating the action<\/p>\n  <p>The two halves of a playbook carry very different risk. Enrichment is read-only, so a broken step wastes a query and nothing else. Containment writes to production, and a wrong action during a false positive is itself an incident. Teams that succeed automate enrichment aggressively, keep containment behind an approval step until the detection is proven, and only then remove the human from the specific paths that have earned it.<\/p>\n<\/div>\n\n<h2 id=\"versus\" class=\"c-sky\">SOAR, SIEM and XDR<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th><\/th><th>SOAR<\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a><\/th><th><a href=\"https:\/\/www.osto.one\/resources\/glossary\/xdr\/\">XDR<\/a><\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Primary job<\/td><td>Act on the alert<\/td><td>Collect, retain and correlate logs<\/td><td>Detect across signal layers natively<\/td><\/tr>\n    <tr><td>Produces<\/td><td>Executed actions and a response record<\/td><td>Alerts and searchable history<\/td><td>Correlated incidents rather than raw alerts<\/td><\/tr>\n    <tr><td>Needs other tools<\/td><td>Yes, entirely. It has nothing of its own to act on<\/td><td>Needs log sources<\/td><td>Ships its own telemetry<\/td><\/tr>\n    <tr><td>Main cost<\/td><td>Building and maintaining playbooks<\/td><td>Ingest volume and tuning<\/td><td>Committing to one vendor&#8217;s coverage<\/td><\/tr>\n    <tr><td>Fails when<\/td><td>The environment changes underneath it<\/td><td>Everything is collected and nothing is reviewed<\/td><td>A layer sits outside its reach<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The three overlap heavily now. Most SIEM platforms ship response actions, and most XDR products include automation, which is why the standalone category has narrowed to large operations centres with genuinely heterogeneous estates.<\/p>\n\n<h2 id=\"osto\">Where Osto fits<\/h2>\n\n<p>Osto is not a SOAR platform. There is no playbook builder and no connector marketplace, and a security operations centre managing fourteen vendors has a real orchestration problem that this stack is not built to solve.<\/p>\n\n<p>What changes on a single stack is how much orchestration is needed in the first place. Detection and the enforcement points are the same platform, so the context a playbook would go and fetch is already attached to the alert: the identity, the device, the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">access role<\/a>, the cloud posture finding, the mail event. Correlation happens in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">one SIEM<\/a> because the events never lived in separate products.<\/p>\n\n<p>The containment actions sit in the same place as the detection too. Revoking access, isolating a device, blocking traffic at the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web protection layer<\/a>: none of those require an integration to be built and maintained between two vendors. That also means the response record needed for <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">incident response<\/a> evidence under <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> or CERT-In reporting comes from one timeline rather than being assembled from several.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Less to orchestrate in the first place<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Detection, identity, endpoint and web protection on one stack, so context arrives with the alert and containment does not need a connector. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is SOAR?<\/summary>\n  <p>Security orchestration, automation and response. It links separate security tools, runs defined steps against alerts without manual work, and carries out containment actions, producing a consistent and recorded response.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between SOAR and SIEM?<\/summary>\n  <p>A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> collects and correlates logs to produce alerts. SOAR acts on those alerts. SIEM tells you something happened; SOAR does something about it. Many SIEM platforms now include response features, which has narrowed the gap considerably.<\/p>\n<\/details>\n\n<details>\n  <summary>What is a playbook?<\/summary>\n  <p>A defined sequence of steps triggered by a specific alert type: gather context, evaluate conditions, take or request an action, record the outcome. Playbooks are effectively code, and they degrade as the environment around them changes.<\/p>\n<\/details>\n\n<details>\n  <summary>Does a small team need SOAR?<\/summary>\n  <p>Rarely as a separate product. The orchestration value scales with how many disconnected tools you run. A small team is usually better served by reducing tool count and tuning detections than by adding an automation layer over noisy alerts.<\/p>\n<\/details>\n\n<details>\n  <summary>Should containment be fully automated?<\/summary>\n  <p>Not at the start. Automate enrichment, which is read-only and low risk. Keep containment behind approval until a detection has proven itself accurate, because automated action on a false positive can disable working accounts or systems.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/xdr\/\">XDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/incident-response\/\">Incident Response<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>SOAR exists because most companies own a dozen security tools that cannot talk to each other. The orchestration layer is\u2026<\/p>\n","protected":false},"author":8,"featured_media":1200,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[599,598,600],"class_list":["post-1199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-security-orchestration-automation-and-response","tag-soar","tag-soar-vs-siem"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1199"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1199\/revisions"}],"predecessor-version":[{"id":1201,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1199\/revisions\/1201"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1200"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}