{"id":1026,"date":"2026-08-24T20:26:29","date_gmt":"2026-08-24T20:26:29","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1026"},"modified":"2026-08-24T20:26:29","modified_gmt":"2026-08-24T20:26:29","slug":"resources-glossary-soc-market-soc","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/resources-glossary-soc-market-soc\/","title":{"rendered":"SOC and Market SOC: Meaning and SEBI Requirements"},"content":{"rendered":"\n<!-- OSTO GLOSSARY: SOC \/ Market SOC. Paste into one Custom HTML block. Page title is intentionally excluded. -->\n<style>\n.og{--navy:#1c267a;--text:#0f1538;--line:#eceef5;--white:#fff;--b0:#f4f5fd;--b1:#e9ecfa;--b2:#cfd5f2;--b7:#4a52a8;--s0:#f2f8f5;--s1:#e3f0e9;--s2:#c3ddce;--s7:#3a6f5d;--a0:#fdf6f0;--a1:#fbe9dc;--a2:#f2cdb2;--a7:#a2603a;--k0:#f1f7fb;--k1:#e2eff7;--k2:#bfd9e9;--k7:#2f6a89;--shadow:0 6px 22px rgba(15,21,56,.05);font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;font-size:17px;line-height:1.75;color:var(--text)}\n.og p{margin:0 0 22px}.og h2{font:700 clamp(25px,3vw,31px)\/1.25 'Inter',sans-serif;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}.og h2:after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--b2)}.og h2.s:after{background:var(--s2)}.og h2.a:after{background:var(--a2)}.og h2.k:after{background:var(--k2)}.og h3{font:700 20px\/1.4 'Inter',sans-serif;color:var(--navy);margin:28px 0 8px}.og ul,.og ol{padding-left:22px;margin:0 0 24px}.og li{margin-bottom:9px}.og strong{font-weight:600}.og a{color:var(--navy);text-underline-offset:3px}\n.og .dek{font-size:20px;line-height:1.6;margin:0 0 18px}.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}.og .tags li{margin:0}.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}.og .tb{background:var(--b1);color:var(--b7)}.og .ts{background:var(--s1);color:var(--s7)}.og .ta{background:var(--a1);color:var(--a7)}\n.og .short{background:linear-gradient(135deg,var(--b1),var(--s1));border-radius:22px;padding:28px 32px;margin:0 0 30px}.og .short .label,.og .toc .label{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--b7);margin:0 0 10px}.og .short p{font-size:19px;line-height:1.65;margin:0}.og .toc{background:var(--b0);border-radius:20px;padding:24px 28px;margin:0 0 34px}.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}.og .toc a{text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n.og .call{padding:24px 28px;margin:0 0 30px;background:#fff;border:2px solid var(--navy);border-radius:4px}.og .call.soft{border:none;border-radius:20px;background:var(--b0)}.og .call.ap{border:none;border-radius:20px;background:var(--a0)}.og .call .label{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}.og .call.ap .label{color:var(--a7)}.og .call p:last-child{margin-bottom:0}\n.og figure{margin:0 0 30px}.og .sx{overflow-x:auto;border-radius:20px;background:#fff;box-shadow:var(--shadow)}.og .sx svg{display:block;width:100%;height:auto;min-width:650px}.og figcaption{font-size:14px;line-height:1.6;margin-top:12px}.og .swipe{display:none}\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:#fff;border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}.og td{border-bottom:1px solid var(--line);padding:13px 16px;vertical-align:top;line-height:1.6}.og tr:last-child td{border-bottom:none}.og .hb th{background:var(--b1);color:var(--b7)}.og .hs th{background:var(--s1);color:var(--s7)}.og .ha th{background:var(--a1);color:var(--a7)}\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}.og .card{border-radius:18px;padding:20px 22px}.og .card .n{font-size:16px;font-weight:700;margin:0 0 4px}.og .card .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}.og .card p{font-size:14px;line-height:1.55;margin:0}.og .card.x{background:var(--k0)}.og .card.x .n,.og .card.x .g{color:var(--k7)}.og .card.y{background:var(--s0)}.og .card.y .n,.og .card.y .g{color:var(--s7)}.og .card.z{background:var(--b0)}.og .card.z .n,.og .card.z .g{color:var(--navy)}\n.og details{background:#fff;border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px}.og summary::-webkit-details-marker{display:none}.og summary:after{content:\"+\";font-size:22px;line-height:1;color:var(--b7)}.og details[open] summary:after{content:\"\\2013\"}.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}.og .related{font-size:15px;border-top:1px solid var(--line);padding-top:22px;margin-top:40px}\n@media(max-width:700px){.og{font-size:16px}.og .dek{font-size:18px}.og .short p{font-size:17px}.og .short,.og .toc,.og .call{padding:22px 20px}.og .toc ol{columns:1}.og .trio{grid-template-columns:1fr}.og .swipe{display:inline;font-weight:600;color:var(--b7)}.og table{font-size:14px}.og th,.og td{padding:11px 12px}}\n<\/style>\n\n<div class=\"og\">\n<p class=\"dek\">A Security Operations Centre watches an organisation\u2019s systems continuously; a Market SOC provides that monitoring as shared securities-market infrastructure for participating SEBI Regulated Entities.<\/p>\n<ul class=\"tags\"><li><span class=\"tag tb\">Glossary<\/span><\/li><li><span class=\"tag ts\">SEBI compliance<\/span><\/li><li><span class=\"tag ta\">Threat detection<\/span><\/li><\/ul>\n<div class=\"short\"><p class=\"label\">The short answer<\/p><p>A <strong>Security Operations Centre (SOC)<\/strong> combines people, processes and technology to monitor security events, investigate suspicious activity and coordinate response. Under SEBI\u2019s CSCRF, an RE may use its own or group SOC, the <strong>Market SOC<\/strong>, or another managed SOC. The Market SOC is shared infrastructure established mandatorily by NSE and BSE and optionally by NSDL or CDSL to give participating REs access to robust, cost-effective monitoring. Using it does not transfer the RE\u2019s compliance accountability.<\/p><\/div>\n<p>A SOC is not simply a room or a dashboard. Its value comes from continuous telemetry, detection logic, trained analysts, defined escalation, incident playbooks and evidence showing that alerts were investigated on time.<\/p>\n<div class=\"toc\"><p class=\"label\">On this page<\/p><ol><li><a href=\"#meaning\">What a SOC does<\/a><\/li><li><a href=\"#market\">What a Market SOC is<\/a><\/li><li><a href=\"#compare\">SOC models compared<\/a><\/li><li><a href=\"#coverage\">What monitoring covers<\/a><\/li><li><a href=\"#workflow\">How SOC operations work<\/a><\/li><li><a href=\"#responsibility\">Who remains responsible<\/a><\/li><li><a href=\"#evidence\">Evidence and efficacy<\/a><\/li><li><a href=\"#checklist\">Onboarding checklist<\/a><\/li><li><a href=\"#osto\">How Osto supports SOC readiness<\/a><\/li><li><a href=\"#faq\">FAQ<\/a><\/li><\/ol><\/div>\n\n<h2 id=\"meaning\">What does a Security Operations Centre do?<\/h2>\n<div class=\"trio\"><div class=\"card x\"><p class=\"n\">Observe<\/p><p class=\"g\">Continuous visibility<\/p><p>Collect security events from endpoints, networks, cloud, applications, identity systems and suppliers.<\/p><\/div><div class=\"card y\"><p class=\"n\">Decide<\/p><p class=\"g\">Detection and investigation<\/p><p>Correlate signals, filter noise and determine whether an anomaly is a real incident.<\/p><\/div><div class=\"card z\"><p class=\"n\">Act<\/p><p class=\"g\">Contain and escalate<\/p><p>Run playbooks, preserve evidence, notify owners and coordinate containment and reporting.<\/p><\/div><\/div>\n<p>The SOC turns raw telemetry into decisions. A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> may collect and correlate logs, while <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a>, WAF, cloud and identity controls provide signals and response actions. The SOC is the operating function that brings those tools, analysts and procedures together.<\/p>\n<table class=\"hb\"><thead><tr><th>Core function<\/th><th>Practical outcome<\/th><\/tr><\/thead><tbody><tr><td><strong>Continuous monitoring<\/strong><\/td><td>Watch endpoints and networks around the clock for abnormal or suspicious behaviour.<\/td><\/tr><tr><td><strong>Log management<\/strong><\/td><td>Collect, retain and review logs needed for detection, investigation and regulatory evidence.<\/td><\/tr><tr><td><strong>Detection and triage<\/strong><\/td><td>Prioritise alerts by severity, context and potential impact rather than treating every event equally.<\/td><\/tr><tr><td><strong>Investigation<\/strong><\/td><td>Reconstruct what happened, which assets or accounts were affected and whether the threat persists.<\/td><\/tr><tr><td><strong>Incident response<\/strong><\/td><td>Contain the event, coordinate remediation and trigger the RE\u2019s escalation and reporting process.<\/td><\/tr><tr><td><strong>Threat intelligence<\/strong><\/td><td>Use known attacker indicators and behaviour to improve detection rules and threat hunting.<\/td><\/tr><\/tbody><\/table>\n\n<h2 id=\"market\" class=\"s\">What is a Market SOC under SEBI?<\/h2>\n<p>The Market SOC is a shared SOC route created under CSCRF for the securities-market ecosystem. NSE and BSE must set up the service; NSDL and CDSL may also do so. Its purpose is to bridge the technology and capability gap for smaller REs and make robust monitoring available at a proportionate cost.<\/p>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 410\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Market SOC model connecting participating SEBI regulated entities to shared monitoring, investigation and response services.\"><defs><marker id=\"ma\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#4a52a8\"\/><\/marker><\/defs><rect x=\"250\" y=\"125\" width=\"280\" height=\"150\" rx=\"28\" fill=\"#1c267a\"\/><text x=\"390\" y=\"177\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"25\" font-weight=\"700\" fill=\"#fff\">MARKET SOC<\/text><text x=\"390\" y=\"205\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"12.5\" fill=\"#dfe2f4\">shared monitoring and response capability<\/text><g font-family=\"Inter\" font-size=\"12\" font-weight=\"700\" text-anchor=\"middle\"><rect x=\"276\" y=\"228\" width=\"95\" height=\"30\" rx=\"15\" fill=\"#fff\" opacity=\".16\"\/><text x=\"323\" y=\"248\" fill=\"#fff\">Detect<\/text><rect x=\"382\" y=\"228\" width=\"95\" height=\"30\" rx=\"15\" fill=\"#fff\" opacity=\".16\"\/><text x=\"429\" y=\"248\" fill=\"#fff\">Respond<\/text><rect x=\"35\" y=\"45\" width=\"170\" height=\"70\" rx=\"18\" fill=\"#e9ecfa\"\/><text x=\"120\" y=\"76\" fill=\"#1c267a\">Small-size REs<\/text><text x=\"120\" y=\"96\" font-size=\"11\" font-weight=\"400\" fill=\"#0f1538\">participating entities<\/text><rect x=\"575\" y=\"45\" width=\"170\" height=\"70\" rx=\"18\" fill=\"#e3f0e9\"\/><text x=\"660\" y=\"76\" fill=\"#3a6f5d\">Self-certification REs<\/text><text x=\"660\" y=\"96\" font-size=\"11\" font-weight=\"400\" fill=\"#0f1538\">participating entities<\/text><rect x=\"35\" y=\"295\" width=\"170\" height=\"70\" rx=\"18\" fill=\"#e2eff7\"\/><text x=\"120\" y=\"326\" fill=\"#2f6a89\">Other participating REs<\/text><text x=\"120\" y=\"346\" font-size=\"11\" font-weight=\"400\" fill=\"#0f1538\">as applicable<\/text><rect x=\"575\" y=\"295\" width=\"170\" height=\"70\" rx=\"18\" fill=\"#fbe9dc\"\/><text x=\"660\" y=\"326\" fill=\"#a2603a\">Market providers<\/text><text x=\"660\" y=\"346\" font-size=\"11\" font-weight=\"400\" fill=\"#0f1538\">NSE \u00b7 BSE \u00b7 NSDL\/CDSL<\/text><\/g><g stroke=\"#4a52a8\" stroke-width=\"2\" fill=\"none\" marker-end=\"url(#ma)\"><path d=\"M205 91L278 139\"\/><path d=\"M575 91L502 139\"\/><path d=\"M205 326L278 263\"\/><path d=\"M575 326L502 263\"\/><\/g><text x=\"390\" y=\"391\" text-anchor=\"middle\" font-family=\"Inter\" font-size=\"12.5\" fill=\"#0f1538\">Shared operations support the RE; accountability remains with the RE.<\/text><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>The Market SOC centralises capability while each RE retains ownership of its systems, decisions and compliance.<\/figcaption><\/figure>\n<div class=\"call soft\"><p class=\"label\">Market SOC is a delivery model, not a regulator<\/p><p>It supplies monitoring and related services within the CSCRF structure. The participating RE must still maintain governance, give the SOC appropriate visibility, respond to alerts, make regulatory decisions and prove compliance.<\/p><\/div>\n\n<h2 id=\"compare\" class=\"k\">The SOC models CSCRF permits<\/h2>\n<table class=\"hb\"><thead><tr><th>Model<\/th><th>Who operates it<\/th><th>Best fit and trade-off<\/th><\/tr><\/thead><tbody><tr><td><strong>RE\u2019s own SOC<\/strong><\/td><td>The regulated entity\u2019s internal team and technology.<\/td><td>Maximum control and context, with the highest staffing and operating burden.<\/td><\/tr><tr><td><strong>Group SOC<\/strong><\/td><td>A shared function within the RE\u2019s corporate group.<\/td><td>Centralises expertise across group entities, provided responsibilities, access and segregation are clear.<\/td><\/tr><tr><td><strong>Market SOC<\/strong><\/td><td>Market-level service established by NSE\/BSE and optionally NSDL\/CDSL.<\/td><td>Bridges the capability and cost gap for participating REs, especially smaller entities.<\/td><\/tr><tr><td><strong>Third-party managed SOC<\/strong><\/td><td>An external managed-security provider.<\/td><td>Provides specialist monitoring without a large internal team; oversight, contracts and integration remain essential.<\/td><\/tr><\/tbody><\/table>\n<p>Box Item 11 of CSCRF states that SOC is mandated for REs, with a stated exception for client-based stock brokers having fewer than 100 clients. It also states that Small-size and Self-certification REs are to be onboarded to the Market SOC model. The exact applicability should be confirmed against the entity\u2019s category and current SEBI instructions.<\/p>\n\n<h2 id=\"coverage\" class=\"a\">What must SOC monitoring cover?<\/h2>\n<p>CSCRF expects the SOC to be up and running <strong>24\u00d77\u00d7365<\/strong> and to monitor, prevent, predict, detect, investigate and respond to cyber threats. Coverage is wider than servers and firewall logs.<\/p>\n<table class=\"ha\"><thead><tr><th>Telemetry area<\/th><th>Examples of events the SOC should see<\/th><\/tr><\/thead><tbody><tr><td><strong>Network and security devices<\/strong><\/td><td>Connections, blocked traffic, unusual destinations, policy changes and segmentation violations.<\/td><\/tr><tr><td><strong>Endpoints<\/strong><\/td><td>Malware, suspicious processes, privilege escalation, device isolation and policy violations through <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a>.<\/td><\/tr><tr><td><strong>Identity and personnel activity<\/strong><\/td><td>Failed logins, impossible travel, new admins, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> anomalies and unauthorised access.<\/td><\/tr><tr><td><strong>Applications and APIs<\/strong><\/td><td>Attack attempts, authentication abuse, sensitive actions and unusual request patterns from <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API security<\/a>.<\/td><\/tr><tr><td><strong>Cloud and data<\/strong><\/td><td>Risky configuration changes, public exposure, excessive permissions and sensitive-data movement.<\/td><\/tr><tr><td><strong>Third parties<\/strong><\/td><td>Provider activity, remote access, service anomalies and events affecting outsourced systems or dependencies.<\/td><\/tr><tr><td><strong>Physical and unauthorised assets<\/strong><\/td><td>Unauthorised personnel, devices, connections, software or mobile code affecting the environment.<\/td><\/tr><\/tbody><\/table>\n<div class=\"call\"><p class=\"label\">Coverage must match the asset inventory<\/p><p>A SOC cannot detect an incident on an asset that never sends telemetry. Reconcile onboarding against current endpoints, systems, applications, APIs, cloud accounts, network devices and service providers\u2014and track blind spots to closure.<\/p><\/div>\n\n<h2 id=\"workflow\" class=\"s\">How a SOC turns an event into a response<\/h2>\n<figure><div class=\"sx\"><svg viewBox=\"0 0 780 275\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"SOC workflow from telemetry collection through correlation, triage, investigation, containment and improvement.\"><defs><marker id=\"wa\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#1c267a\"\/><\/marker><\/defs><g stroke=\"#1c267a\" stroke-width=\"2\" marker-end=\"url(#wa)\"><line x1=\"130\" y1=\"130\" x2=\"155\" y2=\"130\"\/><line x1=\"255\" y1=\"130\" x2=\"280\" y2=\"130\"\/><line x1=\"380\" y1=\"130\" x2=\"405\" y2=\"130\"\/><line x1=\"505\" y1=\"130\" x2=\"530\" y2=\"130\"\/><line x1=\"630\" y1=\"130\" x2=\"655\" y2=\"130\"\/><\/g><g font-family=\"Inter\" text-anchor=\"middle\"><rect x=\"20\" y=\"82\" width=\"110\" height=\"96\" rx=\"17\" fill=\"#e9ecfa\"\/><text x=\"75\" y=\"113\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">COLLECT<\/text><text x=\"75\" y=\"141\" font-size=\"11\" fill=\"#0f1538\">logs and<\/text><text x=\"75\" y=\"157\" font-size=\"11\" fill=\"#0f1538\">telemetry<\/text><rect x=\"155\" y=\"82\" width=\"100\" height=\"96\" rx=\"17\" fill=\"#e2eff7\"\/><text x=\"205\" y=\"113\" font-size=\"12\" font-weight=\"700\" fill=\"#2f6a89\">CORRELATE<\/text><text x=\"205\" y=\"141\" font-size=\"11\" fill=\"#0f1538\">join related<\/text><text x=\"205\" y=\"157\" font-size=\"11\" fill=\"#0f1538\">signals<\/text><rect x=\"280\" y=\"82\" width=\"100\" height=\"96\" rx=\"17\" fill=\"#e3f0e9\"\/><text x=\"330\" y=\"113\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">TRIAGE<\/text><text x=\"330\" y=\"141\" font-size=\"11\" fill=\"#0f1538\">severity and<\/text><text x=\"330\" y=\"157\" font-size=\"11\" fill=\"#0f1538\">priority<\/text><rect x=\"405\" y=\"82\" width=\"100\" height=\"96\" rx=\"17\" fill=\"#fbe9dc\"\/><text x=\"455\" y=\"113\" font-size=\"12\" font-weight=\"700\" fill=\"#a2603a\">INVESTIGATE<\/text><text x=\"455\" y=\"141\" font-size=\"11\" fill=\"#0f1538\">scope, cause<\/text><text x=\"455\" y=\"157\" font-size=\"11\" fill=\"#0f1538\">and impact<\/text><rect x=\"530\" y=\"82\" width=\"100\" height=\"96\" rx=\"17\" fill=\"#e9ecfa\"\/><text x=\"580\" y=\"113\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">RESPOND<\/text><text x=\"580\" y=\"141\" font-size=\"11\" fill=\"#0f1538\">contain and<\/text><text x=\"580\" y=\"157\" font-size=\"11\" fill=\"#0f1538\">escalate<\/text><rect x=\"655\" y=\"82\" width=\"105\" height=\"96\" rx=\"17\" fill=\"#f2f8f5\"\/><text x=\"707\" y=\"113\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">IMPROVE<\/text><text x=\"707\" y=\"141\" font-size=\"11\" fill=\"#0f1538\">tune rules and<\/text><text x=\"707\" y=\"157\" font-size=\"11\" fill=\"#0f1538\">playbooks<\/text><text x=\"390\" y=\"230\" font-size=\"12.5\" fill=\"#0f1538\">Every stage should leave a timestamped record, owner and outcome.<\/text><\/g><\/svg><\/div><figcaption><span class=\"swipe\">Swipe to see the full workflow. <\/span>Detection is effective only when an alert moves through a tested decision and response process.<\/figcaption><\/figure>\n<p>Roles and responsibilities for detection must be defined, and detection processes should be tested through playbooks and use cases. Threat hunting and compromise assessment complement automated alerts by looking for attacker behaviour that existing rules did not flag.<\/p>\n\n<h2 id=\"responsibility\">What the Market SOC does not transfer<\/h2>\n<table class=\"hb\"><thead><tr><th>Market SOC can provide<\/th><th>The participating RE still owns<\/th><\/tr><\/thead><tbody><tr><td>Monitoring infrastructure, analysts, alerting and shared detection capability.<\/td><td>Accurate asset onboarding, access, data classification and business context.<\/td><\/tr><tr><td>Alert triage, investigation support and recommended actions.<\/td><td>Decision rights, containment approval, operational remediation and continuity.<\/td><\/tr><tr><td>Records and dashboards supporting CSCRF monitoring evidence.<\/td><td>Governance review, risk acceptance, regulator communication and compliance submissions.<\/td><\/tr><tr><td>Cost-effective VAPT and cyber-audit access for applicable small and mid-size REs.<\/td><td>Correct scope, remediation, closure evidence and use of the prescribed auditor route.<\/td><\/tr><\/tbody><\/table>\n<div class=\"call ap\"><p class=\"label\">Outsourced operations, retained accountability<\/p><p>CSCRF states expressly that responsibility and accountability for compliance remain with the RE. Contracts and service levels should therefore define telemetry coverage, escalation, evidence access, incident cooperation and exit arrangements clearly.<\/p><\/div>\n\n<h2 id=\"evidence\" class=\"k\">How SOC efficacy is evidenced<\/h2>\n<p>SEBI expects the Market SOC provider to evolve with new controls and guidelines, ensure participating REs adhere to minimum IT and security protocols, undergo annual audit and report functional efficacy. Annexure N measures SOC efficacy across five broad domains.<\/p>\n<table class=\"hs\"><thead><tr><th>Efficacy domain<\/th><th>What it asks<\/th><\/tr><\/thead><tbody><tr><td><strong>Coverage of assets<\/strong><\/td><td>Are relevant assets actually monitored by the required SOC technologies?<\/td><\/tr><tr><td><strong>SOC operations<\/strong><\/td><td>Are events collected, alerts investigated, cases managed and service levels met?<\/td><\/tr><tr><td><strong>Personnel competency<\/strong><\/td><td>Do deployed analysts have sufficient skills, staffing and operating knowledge?<\/td><\/tr><tr><td><strong>SOC governance<\/strong><\/td><td>Are ownership, oversight, policies, escalation and assurance clearly defined?<\/td><\/tr><tr><td><strong>Enrichment and enhancement<\/strong><\/td><td>Does the SOC improve through intelligence, automation, tuning, hunting and lessons learned?<\/td><\/tr><\/tbody><\/table>\n<p>Useful operational evidence includes telemetry onboarding records, detection-rule inventories, alert timestamps, analyst notes, case severity, escalation records, response actions, false-positive tuning, playbook tests, threat-hunting results and incident reports.<\/p>\n\n<h2 id=\"checklist\" class=\"a\">Market SOC onboarding checklist<\/h2>\n<ol><li><strong>Confirm applicability.<\/strong> Record the RE category, SOC route and any stated exception or mandatory Market SOC requirement.<\/li><li><strong>Define accountability.<\/strong> Name the RE owner, technical contacts, incident decision-makers and regulatory reporting owner.<\/li><li><strong>Inventory the environment.<\/strong> Include endpoints, networks, cloud, applications, APIs, identities, data stores and third-party connections.<\/li><li><strong>Map telemetry.<\/strong> Identify the exact log or signal source for every in-scope asset and how collection failure is detected.<\/li><li><strong>Agree severity and service levels.<\/strong> Define priority, triage, escalation and response expectations before alerts begin.<\/li><li><strong>Connect playbooks.<\/strong> Align Market SOC actions with the RE\u2019s incident response, crisis management, continuity and reporting procedures.<\/li><li><strong>Test the route.<\/strong> Run scenarios that prove alert delivery, contact availability, investigation access, containment and decision-making.<\/li><li><strong>Review evidence.<\/strong> Make dashboards, cases, reports and retention accessible for IT Committee review, audit and inspection.<\/li><li><strong>Manage change.<\/strong> Add telemetry for every new system and remove or update retired assets without leaving monitoring gaps.<\/li><li><strong>Measure performance.<\/strong> Track coverage, detection time, response time, open cases, recurring alerts and improvement actions.<\/li><\/ol>\n\n<h2 id=\"osto\" class=\"s\">How Osto supports SOC and Market SOC readiness<\/h2>\n<p>Osto generates and correlates security telemetry across endpoints, identities, cloud, applications, APIs, code, networks and data. Because these controls sit in one platform, analysts receive joined context rather than isolated alerts from separate dashboards.<\/p>\n<p>For an RE using a Market SOC or another managed SOC, Osto can provide the preventive and detective control layer that supplies useful telemetry and evidence. Findings from WAF, API protection, endpoint security, CSPM, VAPT and SIEM can be tracked to an owner, response and verified closure.<\/p>\n<p class=\"related\"><strong>Primary source:<\/strong> <a href=\"https:\/\/www.sebi.gov.in\/legal\/circulars\/aug-2024\/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html\" target=\"_blank\" rel=\"noopener\">SEBI Cybersecurity and Cyber Resilience Framework, 20 August 2024<\/a>, particularly section 4.5, standard DE.CM and Box Item 11. This glossary is an operational overview, not legal advice.<\/p>\n\n<div style=\"background:#1C267A;border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.22);text-align:center\"><p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#fff;font:700 11px Inter,sans-serif;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px\">Continuous security monitoring<\/p><p style=\"color:#fff;font:700 26px\/1.3 Inter,sans-serif;letter-spacing:-.4px;margin:0 0 12px\">Give the SOC signals it can act on<\/p><p style=\"color:#dfe2f4;font:16px\/1.65 Inter,sans-serif;margin:0 auto 26px;max-width:540px\">Connect endpoint, cloud, application, API and identity activity with the evidence needed to investigate and respond.<\/p><a href=\"https:\/\/www.osto.one\/contact\" style=\"display:inline-block;background:#fff;color:#1c267a;font:700 16px Inter,sans-serif;text-decoration:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px\" target=\"_blank\" rel=\"noopener\">Get a free security assessment<\/a><p style=\"color:#cfd3ea;font:13px Inter,sans-serif;margin:14px 0 0\">Connected telemetry \u00b7 Faster investigation \u00b7 One platform, everything<\/p><\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n<details><summary>What does SOC stand for?<\/summary><p>SOC stands for Security Operations Centre. It combines analysts, procedures and security technology to monitor, investigate and respond to cyber threats.<\/p><\/details>\n<details><summary>What is a Market SOC under SEBI?<\/summary><p>It is shared market-level SOC infrastructure established under CSCRF to provide participating regulated entities with robust and cost-effective security monitoring.<\/p><\/details>\n<details><summary>Who sets up the Market SOC?<\/summary><p>CSCRF requires NSE and BSE to set it up and allows NSDL and CDSL to do so optionally.<\/p><\/details>\n<details><summary>Can an RE use its own SOC instead?<\/summary><p>CSCRF recognises an RE\u2019s own or group SOC, the Market SOC and another third-party managed SOC as delivery models, subject to the entity\u2019s category and applicable Market SOC onboarding requirement.<\/p><\/details>\n<details><summary>Which REs must onboard to the Market SOC?<\/summary><p>Box Item 11 states that Small-size and Self-certification category REs are mandated to onboard to the Market SOC. Applicability should be checked against the RE\u2019s current classification and subsequent SEBI instructions.<\/p><\/details>\n<details><summary>Does the Market SOC take over the RE\u2019s compliance responsibility?<\/summary><p>No. CSCRF expressly keeps responsibility and accountability for compliance with the participating RE.<\/p><\/details>\n<details><summary>Does a SOC need to operate continuously?<\/summary><p>CSCRF describes the SOC as a 24\u00d77\u00d7365 function for monitoring, preventing, predicting, detecting, investigating and responding to cyber threats.<\/p><\/details>\n<details><summary>What is the difference between a SOC and a SIEM?<\/summary><p>A SIEM is technology for collecting and correlating security events. A SOC is the broader operating function containing people, processes, playbooks and multiple technologies, often including a SIEM.<\/p><\/details>\n<details><summary>What should a SOC monitor?<\/summary><p>Coverage includes networks, endpoints, physical environment, personnel activity, malicious code, third-party activity and unauthorised personnel, devices, connections and software, along with relevant cloud, application, API and identity signals.<\/p><\/details>\n<details><summary>How is Market SOC effectiveness assessed?<\/summary><p>CSCRF measures functional efficacy across asset coverage, SOC operations, personnel competency, governance, and enrichment and enhancement. Market SOC providers also undergo audit and periodic reporting.<\/p><\/details>\n<p class=\"related\"><strong>Continue reading:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">EDR<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/api-security\/\">API Security<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> \u00b7 <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A Security Operations Centre watches an organisation\u2019s systems continuously; a Market SOC provides that monitoring as shared securities-market infrastructure for\u2026<\/p>\n","protected":false},"author":8,"featured_media":1027,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[476],"class_list":["post-1026","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-sebi-soc-and-market-soc-model-for-continuous-monitoring-of-regulated-entities"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1026","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1026"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1026\/revisions"}],"predecessor-version":[{"id":1028,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1026\/revisions\/1028"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1027"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1026"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1026"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1026"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}