A well-established security operation system requires the combination of people, processes and technology. It is a set of standard services, including log management, real-time monitoring, incident response and investigation. The next generation of security operations needs to be data-driven, implement situational awareness and adaptive security architecture for environment, as well as advanced discovery, analysis and response abilities through machine learning.