{"id":987,"date":"2026-08-24T14:41:45","date_gmt":"2026-08-24T14:41:45","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=987"},"modified":"2026-08-24T14:41:45","modified_gmt":"2026-08-24T14:41:45","slug":"security-operations-centre","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/security-operations-centre\/","title":{"rendered":"Security Operations Centre (C-SOC)"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: SECURITY OPERATIONS CENTRE (C-SOC)\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A security operations centre is the function that watches your systems continuously, decides which alerts matter, and starts the response, and in Indian banking the RBI gave it a name of its own.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Governance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A security operations centre, usually shortened to SOC, is the combination of people, process and technology that monitors an environment for attacks around the clock. C-SOC is the RBI&#8217;s term for it. The Cyber Security Framework in Banks, issued on 2 June 2016, devotes an entire annex to setting one up and operationalising it. A SOC can be built in-house, outsourced, or shared, but accountability for what it misses never transfers.<\/p>\n<\/div>\n\n<p>The common mistake is treating it as a product. You cannot buy a security operations centre. You buy the telemetry and the detection engine, and then decide who watches them.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#what\">What a security operations centre does<\/a><\/li>\n    <li><a href=\"#csoc\">What C-SOC means specifically<\/a><\/li>\n    <li><a href=\"#models\">Build, outsource or share<\/a><\/li>\n    <li><a href=\"#works\">What it takes to make one work<\/a><\/li>\n    <li><a href=\"#lean\">What lean teams do instead<\/a><\/li>\n    <li><a href=\"#osto\">How Osto covers the detection layer<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"what\">What a security operations centre does<\/h2>\n\n<p>Four jobs, in order. Collect signals from everything that generates them. Correlate those signals so a pattern is visible that no single tool would show. Triage what comes out, because most of it is noise. Then respond, or hand off to whoever can.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 280\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Telemetry sources feed a security operations centre, which correlates, triages and responds, then reports to the CISO.\">\n  <defs><marker id=\"soA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <text x=\"14\" y=\"26\" font-family=\"Inter,sans-serif\" font-size=\"11\" font-weight=\"700\" fill=\"#4a52a8\">TELEMETRY IN<\/text>\n\n  <rect x=\"14\" y=\"36\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e9ecfa\"\/>\n  <text x=\"89\" y=\"58\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Endpoints and devices<\/text>\n  <rect x=\"14\" y=\"76\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e9ecfa\"\/>\n  <text x=\"89\" y=\"98\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Cloud and infrastructure<\/text>\n  <rect x=\"14\" y=\"116\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e9ecfa\"\/>\n  <text x=\"89\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Identity and access<\/text>\n  <rect x=\"14\" y=\"156\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e9ecfa\"\/>\n  <text x=\"89\" y=\"178\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Applications and APIs<\/text>\n\n  <line x1=\"170\" y1=\"113\" x2=\"196\" y2=\"113\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#soA)\"\/>\n\n  <rect x=\"202\" y=\"36\" width=\"196\" height=\"154\" rx=\"15\" fill=\"#1c267a\"\/>\n  <text x=\"300\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Security<\/text>\n  <text x=\"300\" y=\"96\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">operations centre<\/text>\n  <text x=\"300\" y=\"124\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Correlate, triage, escalate<\/text>\n  <text x=\"300\" y=\"142\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">People, process, technology<\/text>\n  <text x=\"300\" y=\"166\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Round the clock<\/text>\n\n  <line x1=\"404\" y1=\"113\" x2=\"430\" y2=\"113\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#soA)\"\/>\n\n  <rect x=\"436\" y=\"36\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e3f0e9\"\/>\n  <text x=\"511\" y=\"58\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Containment<\/text>\n  <rect x=\"436\" y=\"76\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e3f0e9\"\/>\n  <text x=\"511\" y=\"98\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Crisis plan activation<\/text>\n  <rect x=\"436\" y=\"116\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e3f0e9\"\/>\n  <text x=\"511\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Regulatory notification<\/text>\n  <rect x=\"436\" y=\"156\" width=\"150\" height=\"34\" rx=\"11\" fill=\"#e3f0e9\"\/>\n  <text x=\"511\" y=\"178\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Forensics and review<\/text>\n\n  <line x1=\"592\" y1=\"113\" x2=\"618\" y2=\"113\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#soA)\"\/>\n  <rect x=\"624\" y=\"86\" width=\"122\" height=\"54\" rx=\"14\" fill=\"#f0e6f3\"\/>\n  <text x=\"685\" y=\"110\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">Reports to<\/text>\n  <text x=\"685\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#6b4576\">the CISO<\/text>\n\n  <rect x=\"14\" y=\"210\" width=\"732\" height=\"52\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"234\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Signals that look unremarkable in four separate tools form one obvious pattern when they land in the same place.<\/text>\n  <text x=\"380\" y=\"252\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">Correlation is the whole point. Volume of alerts is not.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>A centre without correlated inputs is a team reading four dashboards and hoping.<\/figcaption>\n<\/figure>\n\n<h2 id=\"csoc\" class=\"c-sage\">What C-SOC means specifically<\/h2>\n\n<p>C-SOC stands for Cyber Security Operations Centre and comes from the RBI Cyber Security Framework in Banks, circular RBI\/2015-16\/418 of 2 June 2016. One of the framework&#8217;s three annexes is given over entirely to setting up and operationalising it, which tells you how central the regulator considered it.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>What the framework expects<\/th><th>In practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Continuous surveillance<\/td><td>Round-the-clock monitoring and real-time analysis, not a weekday review of yesterday&#8217;s logs<\/td><\/tr>\n    <tr><td>Correlated log collection<\/td><td>Aggregation from critical assets into a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> with threat intelligence feeding the rules<\/td><\/tr>\n    <tr><td>Detection and response capability<\/td><td>Anomaly detection, triage, and the authority to act rather than only to raise a ticket<\/td><\/tr>\n    <tr><td>Feeds the incident clock<\/td><td>Detection starts the reporting window to the RBI cyber security cell, measured in hours<\/td><\/tr>\n    <tr><td>Connected to the crisis plan<\/td><td>An escalation that activates the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cyber-crisis-management-plan\/\">cyber crisis management plan<\/a> rather than sitting in a queue<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Non-bank lenders are not covered by this circular but face a parallel obligation, scaled by where they sit in the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nbfc-regulatory-layers\/\">NBFC regulatory layers<\/a>. Securities and insurance regulators set comparable expectations for their sectors.<\/p>\n\n<h2 id=\"models\" class=\"c-apri\">Build, outsource or share<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">In-house<\/p>\n    <p>Full control and full cost. Round-the-clock coverage means multiple shifts of trained analysts, which is why it stays out of reach for most companies below real scale.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Outsourced or managed<\/p>\n    <p>A provider runs monitoring against your telemetry. Cheaper and faster, but the arrangement has to be documented and the accountability stays with you.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Shared<\/p>\n    <p>Smaller regulated entities below a complexity threshold may use a shared facility. The regulator still expects a documented arrangement and a named owner for response.<\/p>\n  <\/div>\n<\/div>\n\n<div class=\"callout\">\n  <p class=\"k\">Outsourcing does not outsource the obligation<\/p>\n  <p>Whichever model you pick, the regulated entity answers for detection failures. That is why the outsourcing route needs audit rights, defined escalation timelines and evidence you can produce yourself, rather than a monthly summary from a vendor.<\/p>\n<\/div>\n\n<h2 id=\"works\" class=\"c-plum\">What it takes to make one work<\/h2>\n\n<p>Auditors have learned not to ask whether a security operations centre exists. They ask for the operating records.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>What gets examined<\/th><th>What it proves<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Log source coverage<\/td><td>Whether critical assets actually report in, or whether a system was onboarded and quietly stopped sending<\/td><\/tr>\n    <tr><td>Retention period and storage location<\/td><td>Compliance with retention rules and with <a href=\"https:\/\/www.osto.one\/resources\/glossary\/data-localisation\/\">data localisation<\/a> where logs must stay in India<\/td><\/tr>\n    <tr><td>Mean time to detect and mean time to respond<\/td><td>That the function is measured, and that the numbers are moving in the right direction<\/td><\/tr>\n    <tr><td>Shift logs, alert queues and escalation tickets<\/td><td>That the process ran on ordinary days, not only during the audit window<\/td><\/tr>\n    <tr><td>Detection rule tuning<\/td><td>That alert fatigue is being managed rather than accumulating until nobody reads the queue<\/td><\/tr>\n    <tr><td>Integration with response<\/td><td>That an alert leads to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">endpoint containment<\/a> and escalation, not to a spreadsheet<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"lean\">What lean teams do instead<\/h2>\n\n<p>A staffed round-the-clock centre is out of reach for a company of thirty people, and pretending otherwise helps nobody. The workable version separates the two halves of the problem. The technology half, which is telemetry collection, correlation and alerting, is buyable now and produces evidence on its own. The human half is scaled to the risk: a named owner, defined escalation, and external support for the hours nobody is awake.<\/p>\n\n<p>What fails is buying six point tools that each generate their own alerts into their own console. That is not a security operations centre. It is four dashboards and a hope that somebody notices the same name appearing in three of them.<\/p>\n\n<h2 id=\"osto\" class=\"c-sage\">How Osto covers the detection layer<\/h2>\n\n<p>Osto runs the technology half of a security operations centre by default rather than as separate purchases. Every module writes into the same stack, so <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">correlated logging<\/a> sees endpoint, cloud, identity, application and API activity together instead of in isolation. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/edr\/\">Endpoint detection<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture management<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">web and API protection<\/a> feed detections rather than sitting in separate consoles, which is what makes cross-domain patterns visible at all.<\/p>\n\n<p>The evidence layer is purpose-built for the audit side. Retention, coverage and detection records map to <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-for-startups\/\" target=\"_blank\" rel=\"noopener\">SOC 2<\/a>, the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dpdp-act\/\">DPDP Act<\/a> and Indian sectoral frameworks from one place, so the reporting a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ciso\/\">CISO<\/a> would otherwise assemble by hand comes out of one dashboard. Where an audit is mandated, it is performed by the accredited or <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cert-in-empanelment\/\">CERT-In empanelled auditor<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Detection across the stack, not six consoles<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto correlates endpoint, cloud, identity and application signals in one platform, with the retention and records an examiner asks for. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Audit-ready in days &middot; RBI, SEBI and DPDP mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a security operations centre?<\/summary>\n  <p>The people, process and technology that continuously monitor an organisation for security threats. It collects telemetry from endpoints, cloud, identity and applications, correlates it, triages what matters, and drives the response. It can be in-house, outsourced or shared.<\/p>\n<\/details>\n\n<details>\n  <summary>What does C-SOC stand for?<\/summary>\n  <p>Cyber Security Operations Centre. It is the RBI&#8217;s terminology, introduced in the Cyber Security Framework in Banks issued on 2 June 2016, one annex of which is devoted to setting up and operationalising the function.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between a security operations centre and a SIEM?<\/summary>\n  <p>A SIEM is a tool that aggregates and correlates log data. A security operations centre is the function built around it, including the analysts, the triage process, the playbooks and the escalation path. Buying a SIEM does not create a SOC, though you cannot run a SOC without something doing that job.<\/p>\n<\/details>\n\n<details>\n  <summary>Can a security operations centre be outsourced?<\/summary>\n  <p>Yes, and for most organisations that is the practical route. Regulated entities may use a managed or shared facility, particularly below a complexity threshold, but the arrangement must be documented and accountability for detection failures remains with the regulated entity.<\/p>\n<\/details>\n\n<details>\n  <summary>What do auditors ask for when reviewing a security operations centre?<\/summary>\n  <p>Operating records rather than architecture. Log source coverage, retention period and storage location, mean time to detect and mean time to respond, shift logs, alert queues, escalation tickets, and evidence that detection rules are tuned rather than left to generate noise.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> SIEM &middot; EDR &middot; CISO &middot; Cyber Crisis Management Plan &middot; CERT-In Empanelment &middot; NBFC Regulatory Layers &middot; Data Localisation &middot; ISO 27001<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A security operations centre is the function that watches your systems continuously, decides which alerts matter, and starts the response,\u2026<\/p>\n","protected":false},"author":8,"featured_media":988,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[441,440],"class_list":["post-987","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-c-soc-rbi","tag-security-operations-centre"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=987"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/987\/revisions"}],"predecessor-version":[{"id":989,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/987\/revisions\/989"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/988"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}