Skip to main content

Command Palette

Search for a command to run...

Services Models VS Operations Models

Updated
•20 min read•View as Markdown

This Document provide a structured ref for Telecom & Enterprise managed services and operation center, through define each role and how it simple structure inside Companies. while service delivery models may contain one or more center for daily operations based on the scope of work.

The most important distinction is that these concepts do not all describe the same type of thing:

  • Managed Services is primarily a service delivery / outsourcing model.

  • Network Operations Center (NOC) is an operational function focused on network resources and infrastructure.

  • Telecom Service Operations (Telco SOC) is an operational function focused on end-to-end services and customer impact.

  • Managed Security Services (MSS) is a security service delivery model.

  • Telecom Security Operations (Telco SOC) is a security operational function specialized for telecom environments.

  • Security Operations Center (SOC) is a security operational function for enterprise IT, cloud, identity, applications, and related environments.

Operations Models:

Question NOC Telco Service OC Telecom Security OC Enterprise SOC
What are we protecting/operating? Network infrastructure Customer services Telecom infrastructure/services against cyber threats Enterprise digital environment
Primary view Network-centric Service/customer-centric Telecom-security-centric Security-centric
Main event Alarm/fault Service degradation Security event/attack/fraud signal Security alert/incident
Main tools NMS/EMS/OSS CEM/service assurance Signaling security/SIEM/FMS SIEM/EDR/NDR/SOAR
Main objective Restore network Restore service/customer experience Detect/respond to telecom threats Detect/respond to cyber threats
Typical escalation Field/vendor/L2/L3 NOC/IT/customer care NOC/fraud/IR/vendor IT/IR/network/cloud

1. Service Delivery Models

1.1 — Telecom Managed Services - T-MS

Definition: A service model where a telecom operator outsources the day-to-day running, maintenance, and optimization of its network and supporting IT systems to a specialized third party — typically an equipment vendor (Ericsson, Nokia, Huawei, ZTE), a system integrator, or a dedicated managed service provider — under a contract with defined SLAs, covering anywhere from a single domain (e.g., field maintenance) to full end-to-end network operation.

↪ 1. T-MS — Scope

  • Network operations: 24x7 monitoring, fault handling, and performance management (RAN, core, transport, IP/MPLS, fiber, data centers)

  • Field maintenance: preventive (site visits, battery/generator checks) and corrective (failure fixes), plus spare parts logistics

  • Change and release management: software upgrades, patches, configuration changes, new site rollouts

  • Network optimization and planning: coverage/capacity analysis, parameter tuning, traffic forecasting

  • OSS/BSS and IT operations support: billing, provisioning, CRM systems

  • Service desk operations

  • Energy and site management: power, fuel, tower operations

  • Enterprise variant: managed WAN/SD-WAN, managed LAN/Wi-Fi, managed voice/UC

↪ 2. T-MS — Objective

  • Optimize operating cost and resource utilization

  • Let the operator focus on core business (customers, services, growth) rather than day-to-day network running

  • Gain access to scarce technical skills and vendor-specific expertise

  • Ensure 24x7 coverage without building an equivalent internal workforce

  • Accelerate adoption of new technology (5G rollout, cloud-native core, automation)

  • Provide predictable, SLA-bound cost and performance

↪ 3. T-MS — Teams

  • Transition/Onboarding Team — knowledge transfer, tooling setup at contract start

  • NOC Engineers (L1/L2/L3) — provided by the MSP as part of the managed scope

  • Field Maintenance Technicians — site visits, preventive/corrective maintenance

  • Network Optimization Engineers — RF/parameter tuning, capacity planning

  • OSS/BSS Support Engineers — billing, provisioning systems

  • Vendor Management/Service Governance Office — retained on the operator's side to manage the contract and hold the MSP to SLAs

  • Account/Delivery Managers (MSP side) — day-to-day relationship and escalation ownership

↪ 4. T-MS — Tools/Technologies

  • Vendor Element/Network Management Systems (Huawei iMaster NCE, Ericsson ENM, Nokia NetAct)

  • Fault, performance, and configuration management platforms

  • OSS/BSS platforms (billing, provisioning, CRM)

  • Workforce management and field dispatch tools

  • Ticketing/ITSM systems (ServiceNow, Remedy)

  • Network planning and optimization tools

  • Automation/AIOps platforms for predictive maintenance

↪ 5. T-MS — KPIs/SLAs

  • Network/site availability (%)

  • MTTA (Mean Time to Acknowledge) and MTTR (Mean Time to Repair)

  • First-time-fix rate

  • Ticket SLA compliance rate

  • Call setup success rate, dropped call rate

  • Outage minutes and frequency

  • Preventive maintenance completion rate

  • Cost savings/OPEX reduction vs. baseline

↪ 6. T-MS — Typical Outputs

  • Network availability and performance reports

  • SLA compliance/penalty reports

  • Incident and outage reports with root cause

  • Preventive maintenance completion logs

  • Network optimization and capacity planning reports

  • Transition and knowledge-transfer documentation

  • Periodic governance/steering committee reports

  • Contract renewal/exit transition plans


1.2 — Managed Security Services - MSS

Definition: Managed Security Services (MSS) is a security service-delivery model in which an organization contracts a specialized provider, commonly an MSSP (Managed Security Service Provider), to operate, monitor, manage, or support some or all of its cybersecurity controls and processes under a defined scope, service model, KPIs, and SLAs.

↪ 1. MSS — Scope

  • Security device management: firewalls/NGFW, IPS/IDS, secure web and email gateways, VPN, WAF

  • Managed detection and response (MDR/XDR) across endpoints, network, cloud, and identity

  • Security Operation Center - Manage SIEM through monitoring and detection and response

  • Vulnerability management: scanning, prioritization, and remediation tracking

  • DDoS protection and anti-fraud monitoring

  • Threat intelligence and dark web/brand monitoring

  • Incident response and digital forensics (often as a retainer)

  • Identity security: managed IAM/PAM

  • Cloud security: CSPM, CWPP, SASE/SSE

  • Data protection: DLP, encryption key management

  • Governance, risk, and compliance (GRC) support, including virtual CISO (vCISO) services

  • Security awareness training and phishing simulation

↪ 2. MSS — Objective

  • Provide continuous (24x7x365) protection against cyber threats without the cost and difficulty of building an in-house SOC

  • Reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to security incidents

  • Close the skills gap — give access to specialized analysts, threat hunters, and forensic experts that are scarce and expensive to hire directly

  • Maintain and demonstrate regulatory compliance (ISO 27001, PCI DSS, GDPR, NIS2, etc.)

  • Lower total cost of ownership compared to building equivalent capability internally

  • Improve overall security posture through continuous monitoring, tuning, and threat intelligence

  • Provide predictable, subscription-based security spending (OPEX vs. CAPEX)

↪ 3. MSS — Teams

  • SOC Analysts (Tier 1): monitor alerts, perform initial triage, escalate confirmed incidents

  • Incident Responders (Tier 2/3): investigate escalated incidents, contain and remediate threats

  • Threat Hunters: proactively search for hidden threats not caught by automated detection

  • Threat Intelligence Analysts: track threat actors, TTPs, and emerging campaigns relevant to the customer

  • Detection Engineers: build and tune detection rules/use cases

  • Forensic Analysts: conduct deep-dive investigations and evidence collection after major incidents

  • Vulnerability Management Analysts: run scans, prioritize findings, track remediation

  • Compliance/GRC Specialists: manage audit evidence, policy alignment, and regulatory reporting

  • vCISO (Virtual CISO): provides strategic security leadership, often for smaller customers without a dedicated CISO

  • Customer Success/Account Managers: manage the relationship, SLA reporting, and escalation ownership

  • Customer-side counterpart: a smaller retained in-house team (often under the CISO) that owns the MSSP relationship and makes final incident decisions

↪ 4. MSS — Tools/Technologies

  • SIEM (Splunk, Microsoft Sentinel, QRadar, Elastic) for log correlation

  • SOAR platforms for automated playbook-driven response

  • EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender) for endpoint detection

  • NDR for network-based detection

  • Firewalls/NGFW, IPS/IDS, WAF for perimeter and application protection

  • Vulnerability scanners (Qualys, Tenable, Rapid7)

  • Threat Intelligence Platforms (TIP) and threat feeds

  • UEBA for behavioral anomaly detection

  • CSPM/CWPP tools for cloud workload and posture security

  • IAM/PAM platforms (Okta, CyberArk) for identity-based access control

  • DLP solutions for data loss prevention

  • Case management/ticketing systems (ServiceNow, Jira) for incident tracking

  • Sandboxing tools for malware analysis

↪ 5. MSS — KPIs/SLAs

  • MTTD (Mean Time to Detect) — how fast a threat is identified

  • MTTR/MTTC (Mean Time to Respond/Contain) — how fast an incident is acted on and contained

  • Alert response time — SLA on acknowledging alerts by severity tier (e.g., Critical within 15 min, High within 1 hour)

  • False positive rate — quality of detection tuning

  • Coverage metrics — percentage of assets/endpoints under monitoring, MITRE ATT&CK technique coverage

  • Patch/vulnerability remediation SLA — time to remediate critical vulnerabilities (e.g., 7 days for critical, 30 for high)

  • Incident escalation accuracy — proportion of escalations that are true positives

  • Uptime/availability of managed security devices and monitoring platforms

  • Compliance audit pass rate and time to produce audit evidence

  • Customer satisfaction (CSAT) and reporting cadence adherence

↪ 6. MSS — Typical Outputs

  • Real-time and periodic (daily/weekly/monthly) security dashboards and reports

  • Incident reports with root cause, impact, and remediation actions

  • Threat intelligence briefings and advisories relevant to the customer's industry

  • Vulnerability assessment reports with prioritized remediation recommendations

  • Compliance reports and audit-ready evidence packages

  • Executive summaries and risk posture reports for leadership/board

  • Post-incident reviews and lessons-learned documentation

  • Tuned detection rules and updated playbooks

  • SLA performance reports against contracted targets

  • Security awareness training completion and phishing simulation results


2. Operation Centers Models

2.1 — Telecom Service Assurance/Operation Center - T-SOC

Definition: Monitors end-to-end customer-facing services (voice, data, broadband, VAS) rather than individual network elements — focused on customer experience and SLA compliance, not raw equipment alarms.

↪ 1. T-SOC — Scope

  • End-to-end service quality monitoring (CEM) for voice, SMS, mobile data, VoLTE, broadband, leased lines, IPTV, VAS, IoT

  • Customer-impacting incident management, prioritized by number/value of affected customers

  • Major incident and crisis coordination

  • Problem management (root cause of recurring issues)

  • SLA management for enterprise/wholesale customers

  • Service activation/provisioning follow-up

  • Coordination across NOC, field teams, vendors, IT, and customer care

↪ 2. T-SOC — Objective

  • Ensure customers receive the service quality they're paying for

  • Minimize customer-perceived downtime and degradation

  • Meet contractual SLAs for enterprise/wholesale clients

  • Translate technical faults into business/customer impact

  • Reduce churn caused by poor service experience

  • Provide one point of accountability for service quality across silos

↪ 3. T-SOC — Teams

  • Service Operations Analysts (L1) — monitor KPIs, log tickets

  • Service Assurance Engineers (L2) — investigate degradations

  • Major Incident Managers — own coordination during big outages

  • Problem Managers — drive root cause analysis

  • SLA/Account Managers — track contractual compliance

  • Customer Experience Analysts — correlate network issues to customer impact

↪ 4. T-SOC — Tools/Technologies

  • Service assurance platforms and service inventory/CMDB

  • Customer Experience Management (CEM) tools and probes

  • Service Quality Monitoring (SQM) dashboards

  • ITSM/ticketing (ServiceNow, Remedy)

  • Fault-to-service correlation engines

  • Synthetic transaction monitoring

↪ 5. T-SOC — KPIs/SLAs

  • Service availability (per service type)

  • SLA breach count and time-to-breach

  • Mean Time to Restore Service (MTRS)

  • Customers/services impacted per incident

  • First-call resolution rate

  • Major incident frequency and duration

↪ 6. T-SOC — Typical Outputs

  • Service availability and SLA compliance reports

  • Major incident post-mortems and customer communications

  • Root cause analysis reports

  • Executive dashboards on customer-impacting issues

  • SLA credit/penalty calculations


2.2 — Telecom Network Operation Center - T-NOC

Definition: NOC is a centralized operational function, typically operating 24x7 in telecom environments, that monitors, maintains, troubleshoots, and coordinates restoration of network infrastructure and network resources across domains such as RAN, core, transport, fixed access, and supporting infrastructure.

↪ 1. T-NOC — Scope

  • RAN (2G/3G/4G/5G base stations)

  • Core network (packet core, voice core, IMS)

  • Transport (microwave, fiber, DWDM, IP/MPLS, routers, switches)

  • Fixed access (FTTH, DSL)

  • Data centers, power, and environmental systems

  • FCAPS: Fault, Configuration, Accounting, Performance, (basic) Security management

↪ 2. T-NOC — Objective

  • Maximize network uptime/availability

  • Detect and resolve faults before or as soon as they affect customers

  • Keep network performance within target thresholds

  • Execute planned maintenance/upgrades with minimal disruption

  • Provide a real-time, accurate picture of network health

↪ 3. T-NOC — Teams

  • L1 Monitoring/Triage Engineers — alarm monitoring, ticketing handling

  • L2 Field/Remote Engineers — deeper troubleshooting

  • L3 Specialist/Vendor Engineers — software fixes, design issues

  • Field Maintenance Technicians — on-site repairs, preventive maintenance

  • Change/Release Managers — planned maintenance windows

  • NOC Shift Managers — oversee operations and escalations

  • Vendor Support — supplier-specific technical escalation

  • Problem Management — recurring-incident and RCA coordination

  • Capacity / Performance Engineers — trend and resource analysis

↪ 4. T-NOC — Tools/Technologies

  • Element/Network Management Systems (Huawei U2020, Ericsson ENM, Nokia NetAct)

  • Fault and performance management systems

  • Alarm correlation engines

  • Ticketing and workforce management tools

  • AIOps/automation for predictive maintenance and auto-healing

↪ 5. T-NOC — KPIs/SLAs

  • Network/site availability (%)

  • MTTA (Mean Time to Acknowledge)

  • MTTR (Mean Time to Repair)

  • Number and duration of outages

  • Alarm backlog and resolution rate

  • Call setup success rate, dropped call rate

↪ 6. T-NOC — Typical Outputs

  • Real-time alarm/fault dashboards

  • Network availability and performance reports

  • Outage/incident reports with root cause

  • Maintenance schedules and change logs

  • Capacity planning and trend reports


2.3 — Telecom Security Operation Center - T-SOC

Definition: Telco SOC is a security capability specialized for threats and telemetry associated with telecom infrastructure, signaling, interconnects, subscribers, RAN, core networks, IMS, telecom applications, and telecom management planes. A telecom operator does not necessarily need a separate dedicated Telco SOC. Telecom-security responsibilities may instead be integrated into the enterprise SOC, network-security teams, fraud-management teams, or dedicated signaling-security operations.

↪ 1. T-SOC — Scope

  • Signaling security: SS7, Diameter, GTP monitoring and firewalling

  • Fraud: SIM box bypass, IRSF, Wangiri, subscription fraud (paired with FMS)

  • SIM swap/account takeover monitoring

  • 5G core security: service-based architecture APIs, slicing isolation

  • IMS/VoLTE and SIP security

  • RAN threats: rogue base stations, IMSI catchers

  • OSS/BSS and management-plane security

  • Subscriber data protection (CDRs, HLR/HSS/UDM)

  • Lawful interception system integrity

↪ 2. T-SOC — Objective

  • Protect telecom-specific infrastructure that generic IT security tools don't cover

  • Prevent signaling-based attacks (interception, tracking, fraud)

  • Minimize revenue loss from telecom fraud

  • Maintain compliance with GSMA guidelines and national regulators

  • Protect subscriber privacy and data

  • Secure the network without compromising its availability requirements

↪ 3. T-SOC — Teams

  • Telecom Security Analysts — security monitoring with telecom-domain knowledge

  • Signaling Security Analysts / Engineers — SS7, Diameter, GTP and interconnect security

  • Fraud Management Analysts — fraud investigation and loss analysis

  • Signaling Firewall Engineers — signaling-security controls and policy

  • Telecom Threat Intelligence Analysts — telecom-relevant actors, vulnerabilities and campaigns

  • Incident Responders — coordinated investigation and containment

  • 5G Core Security Specialists — SBA/SBI and cloud-native security

  • RAN Security Specialists — RAN/RF security where applicable

  • Security Assurance Specialists — hardening, testing and assurance

↪ 4. T-SOC — Tools/Technologies

  • Signaling firewalls (SS7/Diameter/GTP)

  • Fraud Management Systems (FMS)

  • Telecom-specific SIEM use cases

  • Core network/SBC log monitoring

  • GSMA threat intelligence feeds

  • NESAS/3GPP SCAS compliance tooling

↪ 5. T-SOC — KPIs/SLAs

  • Signaling attack detection/block rate

  • Fraud loss reduction (value and volume)

  • MTTD/MTTR for telecom-specific incidents

  • SIM swap fraud detection rate

  • Compliance audit pass rate (GSMA FS.11, FS.19, NESAS)

  • Cloud-native monitoring for 5G core

  • RAN security telemetry where available

↪ 6. T-SOC — Typical Outputs

  • Signaling-security incident reports

  • Telecom fraud reports

  • Threat-intelligence briefings

  • Security incident reports

  • Telecom-specific detection reports

  • Signaling firewall policy/tuning reports

  • Regulatory/assurance evidence

  • 5G security posture reports

  • Cross-team incident reports with NOC/fraud/SOC

  • Security-control effectiveness reports


2.4 — Cybersecurity Operation Center - CSOC/SOC

Definition: SOC is a security operational function that continuously monitors, detects, investigates, responds to, and helps contain cybersecurity threats across enterprise IT, endpoints, networks, identity, applications, cloud, and other monitored environments.

↪ 1. SOC — Scope

  • Continuous monitoring across endpoints, network, cloud, identity, applications

  • Detection engineering and rule tuning

  • Incident response lifecycle (detect, contain, eradicate, recover)

  • Threat hunting and threat intelligence

  • Vulnerability management support

  • Digital forensics and malware analysis

↪ 2. SOC — Objective

  • Detect and respond to attacks before significant damage occurs

  • Reduce MTTD/MTTR for security incidents

  • Provide continuous visibility across the attack surface

  • Support regulatory and audit compliance

  • Validate detection coverage (e.g., against MITRE ATT&CK)

↪ 3. SOC — Teams

  • Tier 1 Analysts — alert monitoring and triage

  • Tier 2 Incident Responders — investigation and containment

  • Tier 3 Threat Hunters / SMEs — proactive analysis and advanced investigations

  • Threat Intelligence Analysts

  • Detection Engineers

  • Digital Forensics / Malware Analysts

  • Cloud Security Specialists

  • Identity Security Specialists

  • SOC Manager / Shift Manager

  • Incident / Problem / Crisis Managers where applicable

↪ 4. SOC — Tools/Technologies

  • SIEM (Splunk, Sentinel, QRadar)

  • SOAR for automated response

  • EDR/XDR (CrowdStrike, SentinelOne, Defender)

  • NDR and UEBA

  • Threat intelligence platforms

  • Vulnerability scanners, sandboxing tools

  • Case management / ITSM

  • Digital-forensics tooling

  • Vulnerability / exposure-management systems

↪ 5. SOC — KPIs/SLAs

  • MTTD / MTTR / MTTC

  • False positive rate

  • Alert volume and escalation rate

  • MITRE ATT&CK technique coverage

  • SLA compliance on response time by severity

↪ 6. SOC — Typical Outputs

  • Security incidents

  • Incident reports

  • Investigation notes

  • Post-incident reviews

  • Threat-intelligence briefings

  • Detection-content changes

  • Detection coverage/gap reports

  • Compliance evidence packages

  • Executive security posture reports

  • Security-health dashboards

  • Automation/playbook improvements


3. Escalation Matrix

Escalation matrix the one of most playbook used on daily basis for operation handling incident and problem over technology or people operation, it show you where to go to get solution when need assist.

Trigger Primary Owner Secondary / Escalation Typical Next Step
Single cell/site alarm NOC RAN L2 / Field Remote diagnosis / field dispatch
Multiple sites impacted NOC Transport/Core/Field/Vendor Correlation and major-incident assessment
Customer service degradation Service Assurance NOC / IT / Vendor Service-to-resource correlation
Enterprise SLA risk Service Assurance Account / NOC / Engineering Restore service before SLA breach
Security alert Enterprise SOC IR / IT / Network Investigate and contain
Telecom signaling attack Telco SOC NOC / IR / Signaling Engineering Block/contain and validate service
Suspected telecom fraud Fraud Management Telco SOC / Revenue Assurance Investigate fraud pattern and prevent loss
Major multi-domain outage Major Incident Manager All relevant operations Cross-functional recovery
Repeated fault Problem Management Engineering / Vendor RCA and permanent corrective action

[Note] Escalation Matrix defined by MNO or Vendor based on contract with customer. above table for learning purposes


4. RACI Concept

A detailed RACI is operator-specific, but a common pattern is: A = Accountable, R = Responsible, C = Consulted, I = Informed.

Activity Service Assurance NOC Telco SOC Enterprise SOC Field Vendor Fraud
Network alarm monitoring C A/R C C I C I
Network restoration C A/R C I R R I
Customer-impact assessment A/R C C I I C I
Telecom security incident C C A/R C C C C
Enterprise cyber incident I C C A/R I C I
Telecom fraud case C C C I I C A/R
Major incident coordination A/R R R R R R C
Root-cause analysis A R R R C R C

[Note] RACI defined by MNO or Vendor based on contract. above table for learning purposes


5. Reference Frameworks and Standards

The following sources/framework families are useful:

  • ITU-T network management and FCAPS-related recommendations

  • 3GPP security architecture specifications, including 5G security architecture

  • 3GPP Security Assurance Specifications (SCAS)

  • GSMA security guidelines

  • GSMA NESAS

  • TM Forum service assurance and customer experience assurance frameworks

  • NIST Cybersecurity Framework

  • NIST incident-response guidance

  • MITRE ATT&CK for detection and telemetry mapping


6. Key Terminology Summary

Term Meaning
TMS Telecom Managed Services — outsourced/contracted operational service model
MSS Managed Security Services — contracted security-service delivery model
MSSP Managed Security Service Provider
NOC Network Operations Center — network-resource operations
Service Assurance End-to-end service/customer-impact operations
SOC Security Operations Center — cybersecurity operations
Telco SOC Telecom-specialized security operations
EMS Element Management System
NMS Network Management System
OSS Operations Support Systems
BSS Business Support Systems
CEM Customer Experience Management
SIEM Security Information and Event Management
SOAR Security Orchestration, Automation and Response
EDR Endpoint Detection and Response
XDR Extended Detection and Response
NDR Network Detection and Response
FMS Fraud Management System
FCAPS Fault, Configuration, Accounting, Performance, Security
RCA Root Cause Analysis
MTTA Mean Time to Acknowledge
MTTD Mean Time to Detect
MTTC Mean Time to Contain
MTTR Mean Time to Respond/Resolve/Restore — define the exact metric locally/contractually
MTRS Mean Time to Restore Service
SLA Service Level Agreement
KPI Key Performance Indicator
RACI Responsible, Accountable, Consulted, Informed
SCAS Security Assurance Specifications
NESAS Network Equipment Security Assurance Scheme

12 views