Security Operations Centre (C-SOC)

Security operations centre telemetry inputs and response outputs

A security operations centre is the function that watches your systems continuously, decides which alerts matter, and starts the response, and in Indian banking the RBI gave it a name of its own.

  • Glossary
  • Governance

The short answer

A security operations centre, usually shortened to SOC, is the combination of people, process and technology that monitors an environment for attacks around the clock. C-SOC is the RBI’s term for it. The Cyber Security Framework in Banks, issued on 2 June 2016, devotes an entire annex to setting one up and operationalising it. A SOC can be built in-house, outsourced, or shared, but accountability for what it misses never transfers.

The common mistake is treating it as a product. You cannot buy a security operations centre. You buy the telemetry and the detection engine, and then decide who watches them.

What a security operations centre does

Four jobs, in order. Collect signals from everything that generates them. Correlate those signals so a pattern is visible that no single tool would show. Triage what comes out, because most of it is noise. Then respond, or hand off to whoever can.

TELEMETRY IN Endpoints and devices Cloud and infrastructure Identity and access Applications and APIs Security operations centre Correlate, triage, escalate People, process, technology Round the clock Containment Crisis plan activation Regulatory notification Forensics and review Reports to the CISO Signals that look unremarkable in four separate tools form one obvious pattern when they land in the same place. Correlation is the whole point. Volume of alerts is not.
Swipe to see the full diagram. A centre without correlated inputs is a team reading four dashboards and hoping.

What C-SOC means specifically

C-SOC stands for Cyber Security Operations Centre and comes from the RBI Cyber Security Framework in Banks, circular RBI/2015-16/418 of 2 June 2016. One of the framework’s three annexes is given over entirely to setting up and operationalising it, which tells you how central the regulator considered it.

What the framework expectsIn practice
Continuous surveillanceRound-the-clock monitoring and real-time analysis, not a weekday review of yesterday’s logs
Correlated log collectionAggregation from critical assets into a SIEM with threat intelligence feeding the rules
Detection and response capabilityAnomaly detection, triage, and the authority to act rather than only to raise a ticket
Feeds the incident clockDetection starts the reporting window to the RBI cyber security cell, measured in hours
Connected to the crisis planAn escalation that activates the cyber crisis management plan rather than sitting in a queue

Non-bank lenders are not covered by this circular but face a parallel obligation, scaled by where they sit in the NBFC regulatory layers. Securities and insurance regulators set comparable expectations for their sectors.

Build, outsource or share

In-house

Full control and full cost. Round-the-clock coverage means multiple shifts of trained analysts, which is why it stays out of reach for most companies below real scale.

Outsourced or managed

A provider runs monitoring against your telemetry. Cheaper and faster, but the arrangement has to be documented and the accountability stays with you.

Shared

Smaller regulated entities below a complexity threshold may use a shared facility. The regulator still expects a documented arrangement and a named owner for response.

Outsourcing does not outsource the obligation

Whichever model you pick, the regulated entity answers for detection failures. That is why the outsourcing route needs audit rights, defined escalation timelines and evidence you can produce yourself, rather than a monthly summary from a vendor.

What it takes to make one work

Auditors have learned not to ask whether a security operations centre exists. They ask for the operating records.

What gets examinedWhat it proves
Log source coverageWhether critical assets actually report in, or whether a system was onboarded and quietly stopped sending
Retention period and storage locationCompliance with retention rules and with data localisation where logs must stay in India
Mean time to detect and mean time to respondThat the function is measured, and that the numbers are moving in the right direction
Shift logs, alert queues and escalation ticketsThat the process ran on ordinary days, not only during the audit window
Detection rule tuningThat alert fatigue is being managed rather than accumulating until nobody reads the queue
Integration with responseThat an alert leads to endpoint containment and escalation, not to a spreadsheet

What lean teams do instead

A staffed round-the-clock centre is out of reach for a company of thirty people, and pretending otherwise helps nobody. The workable version separates the two halves of the problem. The technology half, which is telemetry collection, correlation and alerting, is buyable now and produces evidence on its own. The human half is scaled to the risk: a named owner, defined escalation, and external support for the hours nobody is awake.

What fails is buying six point tools that each generate their own alerts into their own console. That is not a security operations centre. It is four dashboards and a hope that somebody notices the same name appearing in three of them.

How Osto covers the detection layer

Osto runs the technology half of a security operations centre by default rather than as separate purchases. Every module writes into the same stack, so correlated logging sees endpoint, cloud, identity, application and API activity together instead of in isolation. Endpoint detection, cloud posture management and web and API protection feed detections rather than sitting in separate consoles, which is what makes cross-domain patterns visible at all.

The evidence layer is purpose-built for the audit side. Retention, coverage and detection records map to ISO 27001, SOC 2, the DPDP Act and Indian sectoral frameworks from one place, so the reporting a CISO would otherwise assemble by hand comes out of one dashboard. Where an audit is mandated, it is performed by the accredited or CERT-In empanelled auditor.

Free security assessment

Detection across the stack, not six consoles

Osto correlates endpoint, cloud, identity and application signals in one platform, with the retention and records an examiner asks for. One owner, one dashboard.

Get a free security assessment Book a platform walkthrough

Audit-ready in days · RBI, SEBI and DPDP mapped · One platform, everything

Frequently asked questions

What is a security operations centre?

The people, process and technology that continuously monitor an organisation for security threats. It collects telemetry from endpoints, cloud, identity and applications, correlates it, triages what matters, and drives the response. It can be in-house, outsourced or shared.

What does C-SOC stand for?

Cyber Security Operations Centre. It is the RBI’s terminology, introduced in the Cyber Security Framework in Banks issued on 2 June 2016, one annex of which is devoted to setting up and operationalising the function.

What is the difference between a security operations centre and a SIEM?

A SIEM is a tool that aggregates and correlates log data. A security operations centre is the function built around it, including the analysts, the triage process, the playbooks and the escalation path. Buying a SIEM does not create a SOC, though you cannot run a SOC without something doing that job.

Can a security operations centre be outsourced?

Yes, and for most organisations that is the practical route. Regulated entities may use a managed or shared facility, particularly below a complexity threshold, but the arrangement must be documented and accountability for detection failures remains with the regulated entity.

What do auditors ask for when reviewing a security operations centre?

Operating records rather than architecture. Log source coverage, retention period and storage location, mean time to detect and mean time to respond, shift logs, alert queues, escalation tickets, and evidence that detection rules are tuned rather than left to generate noise.