Services Models VS Operations Models
This Document provide a structured ref for Telecom & Enterprise managed services and operation center, through define each role and how it simple structure inside Companies. while service delivery models may contain one or more center for daily operations based on the scope of work.
The most important distinction is that these concepts do not all describe the same type of thing:
Managed Services is primarily a service delivery / outsourcing model.
Network Operations Center (NOC) is an operational function focused on network resources and infrastructure.
Telecom Service Operations (Telco SOC) is an operational function focused on end-to-end services and customer impact.
Managed Security Services (MSS) is a security service delivery model.
Telecom Security Operations (Telco SOC) is a security operational function specialized for telecom environments.
Security Operations Center (SOC) is a security operational function for enterprise IT, cloud, identity, applications, and related environments.
Operations Models:
| Question | NOC | Telco Service OC | Telecom Security OC | Enterprise SOC |
|---|---|---|---|---|
| What are we protecting/operating? | Network infrastructure | Customer services | Telecom infrastructure/services against cyber threats | Enterprise digital environment |
| Primary view | Network-centric | Service/customer-centric | Telecom-security-centric | Security-centric |
| Main event | Alarm/fault | Service degradation | Security event/attack/fraud signal | Security alert/incident |
| Main tools | NMS/EMS/OSS | CEM/service assurance | Signaling security/SIEM/FMS | SIEM/EDR/NDR/SOAR |
| Main objective | Restore network | Restore service/customer experience | Detect/respond to telecom threats | Detect/respond to cyber threats |
| Typical escalation | Field/vendor/L2/L3 | NOC/IT/customer care | NOC/fraud/IR/vendor | IT/IR/network/cloud |
1. Service Delivery Models
1.1 — Telecom Managed Services - T-MS
Definition: A service model where a telecom operator outsources the day-to-day running, maintenance, and optimization of its network and supporting IT systems to a specialized third party — typically an equipment vendor (Ericsson, Nokia, Huawei, ZTE), a system integrator, or a dedicated managed service provider — under a contract with defined SLAs, covering anywhere from a single domain (e.g., field maintenance) to full end-to-end network operation.
↪ 1. T-MS — Scope
Network operations: 24x7 monitoring, fault handling, and performance management (RAN, core, transport, IP/MPLS, fiber, data centers)
Field maintenance: preventive (site visits, battery/generator checks) and corrective (failure fixes), plus spare parts logistics
Change and release management: software upgrades, patches, configuration changes, new site rollouts
Network optimization and planning: coverage/capacity analysis, parameter tuning, traffic forecasting
OSS/BSS and IT operations support: billing, provisioning, CRM systems
Service desk operations
Energy and site management: power, fuel, tower operations
Enterprise variant: managed WAN/SD-WAN, managed LAN/Wi-Fi, managed voice/UC
↪ 2. T-MS — Objective
Optimize operating cost and resource utilization
Let the operator focus on core business (customers, services, growth) rather than day-to-day network running
Gain access to scarce technical skills and vendor-specific expertise
Ensure 24x7 coverage without building an equivalent internal workforce
Accelerate adoption of new technology (5G rollout, cloud-native core, automation)
Provide predictable, SLA-bound cost and performance
↪ 3. T-MS — Teams
Transition/Onboarding Team — knowledge transfer, tooling setup at contract start
NOC Engineers (L1/L2/L3) — provided by the MSP as part of the managed scope
Field Maintenance Technicians — site visits, preventive/corrective maintenance
Network Optimization Engineers — RF/parameter tuning, capacity planning
OSS/BSS Support Engineers — billing, provisioning systems
Vendor Management/Service Governance Office — retained on the operator's side to manage the contract and hold the MSP to SLAs
Account/Delivery Managers (MSP side) — day-to-day relationship and escalation ownership
↪ 4. T-MS — Tools/Technologies
Vendor Element/Network Management Systems (Huawei iMaster NCE, Ericsson ENM, Nokia NetAct)
Fault, performance, and configuration management platforms
OSS/BSS platforms (billing, provisioning, CRM)
Workforce management and field dispatch tools
Ticketing/ITSM systems (ServiceNow, Remedy)
Network planning and optimization tools
Automation/AIOps platforms for predictive maintenance
↪ 5. T-MS — KPIs/SLAs
Network/site availability (%)
MTTA (Mean Time to Acknowledge) and MTTR (Mean Time to Repair)
First-time-fix rate
Ticket SLA compliance rate
Call setup success rate, dropped call rate
Outage minutes and frequency
Preventive maintenance completion rate
Cost savings/OPEX reduction vs. baseline
↪ 6. T-MS — Typical Outputs
Network availability and performance reports
SLA compliance/penalty reports
Incident and outage reports with root cause
Preventive maintenance completion logs
Network optimization and capacity planning reports
Transition and knowledge-transfer documentation
Periodic governance/steering committee reports
Contract renewal/exit transition plans
1.2 — Managed Security Services - MSS
Definition: Managed Security Services (MSS) is a security service-delivery model in which an organization contracts a specialized provider, commonly an MSSP (Managed Security Service Provider), to operate, monitor, manage, or support some or all of its cybersecurity controls and processes under a defined scope, service model, KPIs, and SLAs.
↪ 1. MSS — Scope
Security device management: firewalls/NGFW, IPS/IDS, secure web and email gateways, VPN, WAF
Managed detection and response (MDR/XDR) across endpoints, network, cloud, and identity
Security Operation Center - Manage SIEM through monitoring and detection and response
Vulnerability management: scanning, prioritization, and remediation tracking
DDoS protection and anti-fraud monitoring
Threat intelligence and dark web/brand monitoring
Incident response and digital forensics (often as a retainer)
Identity security: managed IAM/PAM
Cloud security: CSPM, CWPP, SASE/SSE
Data protection: DLP, encryption key management
Governance, risk, and compliance (GRC) support, including virtual CISO (vCISO) services
Security awareness training and phishing simulation
↪ 2. MSS — Objective
Provide continuous (24x7x365) protection against cyber threats without the cost and difficulty of building an in-house SOC
Reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) to security incidents
Close the skills gap — give access to specialized analysts, threat hunters, and forensic experts that are scarce and expensive to hire directly
Maintain and demonstrate regulatory compliance (ISO 27001, PCI DSS, GDPR, NIS2, etc.)
Lower total cost of ownership compared to building equivalent capability internally
Improve overall security posture through continuous monitoring, tuning, and threat intelligence
Provide predictable, subscription-based security spending (OPEX vs. CAPEX)
↪ 3. MSS — Teams
SOC Analysts (Tier 1): monitor alerts, perform initial triage, escalate confirmed incidents
Incident Responders (Tier 2/3): investigate escalated incidents, contain and remediate threats
Threat Hunters: proactively search for hidden threats not caught by automated detection
Threat Intelligence Analysts: track threat actors, TTPs, and emerging campaigns relevant to the customer
Detection Engineers: build and tune detection rules/use cases
Forensic Analysts: conduct deep-dive investigations and evidence collection after major incidents
Vulnerability Management Analysts: run scans, prioritize findings, track remediation
Compliance/GRC Specialists: manage audit evidence, policy alignment, and regulatory reporting
vCISO (Virtual CISO): provides strategic security leadership, often for smaller customers without a dedicated CISO
Customer Success/Account Managers: manage the relationship, SLA reporting, and escalation ownership
Customer-side counterpart: a smaller retained in-house team (often under the CISO) that owns the MSSP relationship and makes final incident decisions
↪ 4. MSS — Tools/Technologies
SIEM (Splunk, Microsoft Sentinel, QRadar, Elastic) for log correlation
SOAR platforms for automated playbook-driven response
EDR/XDR (CrowdStrike, SentinelOne, Microsoft Defender) for endpoint detection
NDR for network-based detection
Firewalls/NGFW, IPS/IDS, WAF for perimeter and application protection
Vulnerability scanners (Qualys, Tenable, Rapid7)
Threat Intelligence Platforms (TIP) and threat feeds
UEBA for behavioral anomaly detection
CSPM/CWPP tools for cloud workload and posture security
IAM/PAM platforms (Okta, CyberArk) for identity-based access control
DLP solutions for data loss prevention
Case management/ticketing systems (ServiceNow, Jira) for incident tracking
Sandboxing tools for malware analysis
↪ 5. MSS — KPIs/SLAs
MTTD (Mean Time to Detect) — how fast a threat is identified
MTTR/MTTC (Mean Time to Respond/Contain) — how fast an incident is acted on and contained
Alert response time — SLA on acknowledging alerts by severity tier (e.g., Critical within 15 min, High within 1 hour)
False positive rate — quality of detection tuning
Coverage metrics — percentage of assets/endpoints under monitoring, MITRE ATT&CK technique coverage
Patch/vulnerability remediation SLA — time to remediate critical vulnerabilities (e.g., 7 days for critical, 30 for high)
Incident escalation accuracy — proportion of escalations that are true positives
Uptime/availability of managed security devices and monitoring platforms
Compliance audit pass rate and time to produce audit evidence
Customer satisfaction (CSAT) and reporting cadence adherence
↪ 6. MSS — Typical Outputs
Real-time and periodic (daily/weekly/monthly) security dashboards and reports
Incident reports with root cause, impact, and remediation actions
Threat intelligence briefings and advisories relevant to the customer's industry
Vulnerability assessment reports with prioritized remediation recommendations
Compliance reports and audit-ready evidence packages
Executive summaries and risk posture reports for leadership/board
Post-incident reviews and lessons-learned documentation
Tuned detection rules and updated playbooks
SLA performance reports against contracted targets
Security awareness training completion and phishing simulation results
2. Operation Centers Models
2.1 — Telecom Service Assurance/Operation Center - T-SOC
Definition: Monitors end-to-end customer-facing services (voice, data, broadband, VAS) rather than individual network elements — focused on customer experience and SLA compliance, not raw equipment alarms.
↪ 1. T-SOC — Scope
End-to-end service quality monitoring (CEM) for voice, SMS, mobile data, VoLTE, broadband, leased lines, IPTV, VAS, IoT
Customer-impacting incident management, prioritized by number/value of affected customers
Major incident and crisis coordination
Problem management (root cause of recurring issues)
SLA management for enterprise/wholesale customers
Service activation/provisioning follow-up
Coordination across NOC, field teams, vendors, IT, and customer care
↪ 2. T-SOC — Objective
Ensure customers receive the service quality they're paying for
Minimize customer-perceived downtime and degradation
Meet contractual SLAs for enterprise/wholesale clients
Translate technical faults into business/customer impact
Reduce churn caused by poor service experience
Provide one point of accountability for service quality across silos
↪ 3. T-SOC — Teams
Service Operations Analysts (L1) — monitor KPIs, log tickets
Service Assurance Engineers (L2) — investigate degradations
Major Incident Managers — own coordination during big outages
Problem Managers — drive root cause analysis
SLA/Account Managers — track contractual compliance
Customer Experience Analysts — correlate network issues to customer impact
↪ 4. T-SOC — Tools/Technologies
Service assurance platforms and service inventory/CMDB
Customer Experience Management (CEM) tools and probes
Service Quality Monitoring (SQM) dashboards
ITSM/ticketing (ServiceNow, Remedy)
Fault-to-service correlation engines
Synthetic transaction monitoring
↪ 5. T-SOC — KPIs/SLAs
Service availability (per service type)
SLA breach count and time-to-breach
Mean Time to Restore Service (MTRS)
Customers/services impacted per incident
First-call resolution rate
Major incident frequency and duration
↪ 6. T-SOC — Typical Outputs
Service availability and SLA compliance reports
Major incident post-mortems and customer communications
Root cause analysis reports
Executive dashboards on customer-impacting issues
SLA credit/penalty calculations
2.2 — Telecom Network Operation Center - T-NOC
Definition: NOC is a centralized operational function, typically operating 24x7 in telecom environments, that monitors, maintains, troubleshoots, and coordinates restoration of network infrastructure and network resources across domains such as RAN, core, transport, fixed access, and supporting infrastructure.
↪ 1. T-NOC — Scope
RAN (2G/3G/4G/5G base stations)
Core network (packet core, voice core, IMS)
Transport (microwave, fiber, DWDM, IP/MPLS, routers, switches)
Fixed access (FTTH, DSL)
Data centers, power, and environmental systems
FCAPS: Fault, Configuration, Accounting, Performance, (basic) Security management
↪ 2. T-NOC — Objective
Maximize network uptime/availability
Detect and resolve faults before or as soon as they affect customers
Keep network performance within target thresholds
Execute planned maintenance/upgrades with minimal disruption
Provide a real-time, accurate picture of network health
↪ 3. T-NOC — Teams
L1 Monitoring/Triage Engineers — alarm monitoring, ticketing handling
L2 Field/Remote Engineers — deeper troubleshooting
L3 Specialist/Vendor Engineers — software fixes, design issues
Field Maintenance Technicians — on-site repairs, preventive maintenance
Change/Release Managers — planned maintenance windows
NOC Shift Managers — oversee operations and escalations
Vendor Support — supplier-specific technical escalation
Problem Management — recurring-incident and RCA coordination
Capacity / Performance Engineers — trend and resource analysis
↪ 4. T-NOC — Tools/Technologies
Element/Network Management Systems (Huawei U2020, Ericsson ENM, Nokia NetAct)
Fault and performance management systems
Alarm correlation engines
Ticketing and workforce management tools
AIOps/automation for predictive maintenance and auto-healing
↪ 5. T-NOC — KPIs/SLAs
Network/site availability (%)
MTTA (Mean Time to Acknowledge)
MTTR (Mean Time to Repair)
Number and duration of outages
Alarm backlog and resolution rate
Call setup success rate, dropped call rate
↪ 6. T-NOC — Typical Outputs
Real-time alarm/fault dashboards
Network availability and performance reports
Outage/incident reports with root cause
Maintenance schedules and change logs
Capacity planning and trend reports
2.3 — Telecom Security Operation Center - T-SOC
Definition: Telco SOC is a security capability specialized for threats and telemetry associated with telecom infrastructure, signaling, interconnects, subscribers, RAN, core networks, IMS, telecom applications, and telecom management planes. A telecom operator does not necessarily need a separate dedicated Telco SOC. Telecom-security responsibilities may instead be integrated into the enterprise SOC, network-security teams, fraud-management teams, or dedicated signaling-security operations.
↪ 1. T-SOC — Scope
Signaling security: SS7, Diameter, GTP monitoring and firewalling
Fraud: SIM box bypass, IRSF, Wangiri, subscription fraud (paired with FMS)
SIM swap/account takeover monitoring
5G core security: service-based architecture APIs, slicing isolation
IMS/VoLTE and SIP security
RAN threats: rogue base stations, IMSI catchers
OSS/BSS and management-plane security
Subscriber data protection (CDRs, HLR/HSS/UDM)
Lawful interception system integrity
↪ 2. T-SOC — Objective
Protect telecom-specific infrastructure that generic IT security tools don't cover
Prevent signaling-based attacks (interception, tracking, fraud)
Minimize revenue loss from telecom fraud
Maintain compliance with GSMA guidelines and national regulators
Protect subscriber privacy and data
Secure the network without compromising its availability requirements
↪ 3. T-SOC — Teams
Telecom Security Analysts — security monitoring with telecom-domain knowledge
Signaling Security Analysts / Engineers — SS7, Diameter, GTP and interconnect security
Fraud Management Analysts — fraud investigation and loss analysis
Signaling Firewall Engineers — signaling-security controls and policy
Telecom Threat Intelligence Analysts — telecom-relevant actors, vulnerabilities and campaigns
Incident Responders — coordinated investigation and containment
5G Core Security Specialists — SBA/SBI and cloud-native security
RAN Security Specialists — RAN/RF security where applicable
Security Assurance Specialists — hardening, testing and assurance
↪ 4. T-SOC — Tools/Technologies
Signaling firewalls (SS7/Diameter/GTP)
Fraud Management Systems (FMS)
Telecom-specific SIEM use cases
Core network/SBC log monitoring
GSMA threat intelligence feeds
NESAS/3GPP SCAS compliance tooling
↪ 5. T-SOC — KPIs/SLAs
Signaling attack detection/block rate
Fraud loss reduction (value and volume)
MTTD/MTTR for telecom-specific incidents
SIM swap fraud detection rate
Compliance audit pass rate (GSMA FS.11, FS.19, NESAS)
Cloud-native monitoring for 5G core
RAN security telemetry where available
↪ 6. T-SOC — Typical Outputs
Signaling-security incident reports
Telecom fraud reports
Threat-intelligence briefings
Security incident reports
Telecom-specific detection reports
Signaling firewall policy/tuning reports
Regulatory/assurance evidence
5G security posture reports
Cross-team incident reports with NOC/fraud/SOC
Security-control effectiveness reports
2.4 — Cybersecurity Operation Center - CSOC/SOC
Definition: SOC is a security operational function that continuously monitors, detects, investigates, responds to, and helps contain cybersecurity threats across enterprise IT, endpoints, networks, identity, applications, cloud, and other monitored environments.
↪ 1. SOC — Scope
Continuous monitoring across endpoints, network, cloud, identity, applications
Detection engineering and rule tuning
Incident response lifecycle (detect, contain, eradicate, recover)
Threat hunting and threat intelligence
Vulnerability management support
Digital forensics and malware analysis
↪ 2. SOC — Objective
Detect and respond to attacks before significant damage occurs
Reduce MTTD/MTTR for security incidents
Provide continuous visibility across the attack surface
Support regulatory and audit compliance
Validate detection coverage (e.g., against MITRE ATT&CK)
↪ 3. SOC — Teams
Tier 1 Analysts — alert monitoring and triage
Tier 2 Incident Responders — investigation and containment
Tier 3 Threat Hunters / SMEs — proactive analysis and advanced investigations
Threat Intelligence Analysts
Detection Engineers
Digital Forensics / Malware Analysts
Cloud Security Specialists
Identity Security Specialists
SOC Manager / Shift Manager
Incident / Problem / Crisis Managers where applicable
↪ 4. SOC — Tools/Technologies
SIEM (Splunk, Sentinel, QRadar)
SOAR for automated response
EDR/XDR (CrowdStrike, SentinelOne, Defender)
NDR and UEBA
Threat intelligence platforms
Vulnerability scanners, sandboxing tools
Case management / ITSM
Digital-forensics tooling
Vulnerability / exposure-management systems
↪ 5. SOC — KPIs/SLAs
MTTD / MTTR / MTTC
False positive rate
Alert volume and escalation rate
MITRE ATT&CK technique coverage
SLA compliance on response time by severity
↪ 6. SOC — Typical Outputs
Security incidents
Incident reports
Investigation notes
Post-incident reviews
Threat-intelligence briefings
Detection-content changes
Detection coverage/gap reports
Compliance evidence packages
Executive security posture reports
Security-health dashboards
Automation/playbook improvements
3. Escalation Matrix
Escalation matrix the one of most playbook used on daily basis for operation handling incident and problem over technology or people operation, it show you where to go to get solution when need assist.
| Trigger | Primary Owner | Secondary / Escalation | Typical Next Step |
|---|---|---|---|
| Single cell/site alarm | NOC | RAN L2 / Field | Remote diagnosis / field dispatch |
| Multiple sites impacted | NOC | Transport/Core/Field/Vendor | Correlation and major-incident assessment |
| Customer service degradation | Service Assurance | NOC / IT / Vendor | Service-to-resource correlation |
| Enterprise SLA risk | Service Assurance | Account / NOC / Engineering | Restore service before SLA breach |
| Security alert | Enterprise SOC | IR / IT / Network | Investigate and contain |
| Telecom signaling attack | Telco SOC | NOC / IR / Signaling Engineering | Block/contain and validate service |
| Suspected telecom fraud | Fraud Management | Telco SOC / Revenue Assurance | Investigate fraud pattern and prevent loss |
| Major multi-domain outage | Major Incident Manager | All relevant operations | Cross-functional recovery |
| Repeated fault | Problem Management | Engineering / Vendor | RCA and permanent corrective action |
[Note] Escalation Matrix defined by MNO or Vendor based on contract with customer. above table for learning purposes
4. RACI Concept
A detailed RACI is operator-specific, but a common pattern is: A = Accountable, R = Responsible, C = Consulted, I = Informed.
| Activity | Service Assurance | NOC | Telco SOC | Enterprise SOC | Field | Vendor | Fraud |
|---|---|---|---|---|---|---|---|
| Network alarm monitoring | C | A/R | C | C | I | C | I |
| Network restoration | C | A/R | C | I | R | R | I |
| Customer-impact assessment | A/R | C | C | I | I | C | I |
| Telecom security incident | C | C | A/R | C | C | C | C |
| Enterprise cyber incident | I | C | C | A/R | I | C | I |
| Telecom fraud case | C | C | C | I | I | C | A/R |
| Major incident coordination | A/R | R | R | R | R | R | C |
| Root-cause analysis | A | R | R | R | C | R | C |
[Note] RACI defined by MNO or Vendor based on contract. above table for learning purposes
5. Reference Frameworks and Standards
The following sources/framework families are useful:
ITU-T network management and FCAPS-related recommendations
3GPP security architecture specifications, including 5G security architecture
3GPP Security Assurance Specifications (SCAS)
GSMA security guidelines
GSMA NESAS
TM Forum service assurance and customer experience assurance frameworks
NIST Cybersecurity Framework
NIST incident-response guidance
MITRE ATT&CK for detection and telemetry mapping
6. Key Terminology Summary
| Term | Meaning |
|---|---|
| TMS | Telecom Managed Services — outsourced/contracted operational service model |
| MSS | Managed Security Services — contracted security-service delivery model |
| MSSP | Managed Security Service Provider |
| NOC | Network Operations Center — network-resource operations |
| Service Assurance | End-to-end service/customer-impact operations |
| SOC | Security Operations Center — cybersecurity operations |
| Telco SOC | Telecom-specialized security operations |
| EMS | Element Management System |
| NMS | Network Management System |
| OSS | Operations Support Systems |
| BSS | Business Support Systems |
| CEM | Customer Experience Management |
| SIEM | Security Information and Event Management |
| SOAR | Security Orchestration, Automation and Response |
| EDR | Endpoint Detection and Response |
| XDR | Extended Detection and Response |
| NDR | Network Detection and Response |
| FMS | Fraud Management System |
| FCAPS | Fault, Configuration, Accounting, Performance, Security |
| RCA | Root Cause Analysis |
| MTTA | Mean Time to Acknowledge |
| MTTD | Mean Time to Detect |
| MTTC | Mean Time to Contain |
| MTTR | Mean Time to Respond/Resolve/Restore — define the exact metric locally/contractually |
| MTRS | Mean Time to Restore Service |
| SLA | Service Level Agreement |
| KPI | Key Performance Indicator |
| RACI | Responsible, Accountable, Consulted, Informed |
| SCAS | Security Assurance Specifications |
| NESAS | Network Equipment Security Assurance Scheme |
