A security operations centre is the function that watches your systems continuously, decides which alerts matter, and starts the response, and in Indian banking the RBI gave it a name of its own.
The short answer
A security operations centre, usually shortened to SOC, is the combination of people, process and technology that monitors an environment for attacks around the clock. C-SOC is the RBI’s term for it. The Cyber Security Framework in Banks, issued on 2 June 2016, devotes an entire annex to setting one up and operationalising it. A SOC can be built in-house, outsourced, or shared, but accountability for what it misses never transfers.
The common mistake is treating it as a product. You cannot buy a security operations centre. You buy the telemetry and the detection engine, and then decide who watches them.
On this page
What a security operations centre does
Four jobs, in order. Collect signals from everything that generates them. Correlate those signals so a pattern is visible that no single tool would show. Triage what comes out, because most of it is noise. Then respond, or hand off to whoever can.
What C-SOC means specifically
C-SOC stands for Cyber Security Operations Centre and comes from the RBI Cyber Security Framework in Banks, circular RBI/2015-16/418 of 2 June 2016. One of the framework’s three annexes is given over entirely to setting up and operationalising it, which tells you how central the regulator considered it.
| What the framework expects | In practice |
|---|---|
| Continuous surveillance | Round-the-clock monitoring and real-time analysis, not a weekday review of yesterday’s logs |
| Correlated log collection | Aggregation from critical assets into a SIEM with threat intelligence feeding the rules |
| Detection and response capability | Anomaly detection, triage, and the authority to act rather than only to raise a ticket |
| Feeds the incident clock | Detection starts the reporting window to the RBI cyber security cell, measured in hours |
| Connected to the crisis plan | An escalation that activates the cyber crisis management plan rather than sitting in a queue |
Non-bank lenders are not covered by this circular but face a parallel obligation, scaled by where they sit in the NBFC regulatory layers. Securities and insurance regulators set comparable expectations for their sectors.
Build, outsource or share
In-house
Full control and full cost. Round-the-clock coverage means multiple shifts of trained analysts, which is why it stays out of reach for most companies below real scale.
Outsourced or managed
A provider runs monitoring against your telemetry. Cheaper and faster, but the arrangement has to be documented and the accountability stays with you.
Shared
Smaller regulated entities below a complexity threshold may use a shared facility. The regulator still expects a documented arrangement and a named owner for response.
Outsourcing does not outsource the obligation
Whichever model you pick, the regulated entity answers for detection failures. That is why the outsourcing route needs audit rights, defined escalation timelines and evidence you can produce yourself, rather than a monthly summary from a vendor.
What it takes to make one work
Auditors have learned not to ask whether a security operations centre exists. They ask for the operating records.
| What gets examined | What it proves |
|---|---|
| Log source coverage | Whether critical assets actually report in, or whether a system was onboarded and quietly stopped sending |
| Retention period and storage location | Compliance with retention rules and with data localisation where logs must stay in India |
| Mean time to detect and mean time to respond | That the function is measured, and that the numbers are moving in the right direction |
| Shift logs, alert queues and escalation tickets | That the process ran on ordinary days, not only during the audit window |
| Detection rule tuning | That alert fatigue is being managed rather than accumulating until nobody reads the queue |
| Integration with response | That an alert leads to endpoint containment and escalation, not to a spreadsheet |
What lean teams do instead
A staffed round-the-clock centre is out of reach for a company of thirty people, and pretending otherwise helps nobody. The workable version separates the two halves of the problem. The technology half, which is telemetry collection, correlation and alerting, is buyable now and produces evidence on its own. The human half is scaled to the risk: a named owner, defined escalation, and external support for the hours nobody is awake.
What fails is buying six point tools that each generate their own alerts into their own console. That is not a security operations centre. It is four dashboards and a hope that somebody notices the same name appearing in three of them.
How Osto covers the detection layer
Osto runs the technology half of a security operations centre by default rather than as separate purchases. Every module writes into the same stack, so correlated logging sees endpoint, cloud, identity, application and API activity together instead of in isolation. Endpoint detection, cloud posture management and web and API protection feed detections rather than sitting in separate consoles, which is what makes cross-domain patterns visible at all.
The evidence layer is purpose-built for the audit side. Retention, coverage and detection records map to ISO 27001, SOC 2, the DPDP Act and Indian sectoral frameworks from one place, so the reporting a CISO would otherwise assemble by hand comes out of one dashboard. Where an audit is mandated, it is performed by the accredited or CERT-In empanelled auditor.
Free security assessment
Detection across the stack, not six consoles
Osto correlates endpoint, cloud, identity and application signals in one platform, with the retention and records an examiner asks for. One owner, one dashboard.
Get a free security assessment Book a platform walkthroughAudit-ready in days · RBI, SEBI and DPDP mapped · One platform, everything
Frequently asked questions
What is a security operations centre?
The people, process and technology that continuously monitor an organisation for security threats. It collects telemetry from endpoints, cloud, identity and applications, correlates it, triages what matters, and drives the response. It can be in-house, outsourced or shared.
What does C-SOC stand for?
Cyber Security Operations Centre. It is the RBI’s terminology, introduced in the Cyber Security Framework in Banks issued on 2 June 2016, one annex of which is devoted to setting up and operationalising the function.
What is the difference between a security operations centre and a SIEM?
A SIEM is a tool that aggregates and correlates log data. A security operations centre is the function built around it, including the analysts, the triage process, the playbooks and the escalation path. Buying a SIEM does not create a SOC, though you cannot run a SOC without something doing that job.
Can a security operations centre be outsourced?
Yes, and for most organisations that is the practical route. Regulated entities may use a managed or shared facility, particularly below a complexity threshold, but the arrangement must be documented and accountability for detection failures remains with the regulated entity.
What do auditors ask for when reviewing a security operations centre?
Operating records rather than architecture. Log source coverage, retention period and storage location, mean time to detect and mean time to respond, shift logs, alert queues, escalation tickets, and evidence that detection rules are tuned rather than left to generate noise.

