Technology

Security Operations Center

The team and function responsible for monitoring, detecting and responding to security events, often around the clock.

Definition

A security operations center (SOC) is the team, process and tooling responsible for continuously monitoring an organisation's systems for security events, investigating what is detected, and coordinating the response.

A SOC is a function rather than a room. Many organisations picture a wall of screens, but what matters is whether someone is watching, whether they can tell a real incident from noise, and whether they have authority to act. A small team with clear escalation paths outperforms an impressive facility without them.

SOCs are commonly tiered. Tier 1 triages alerts and closes false positives. Tier 2 investigates what survives triage. Tier 3 handles complex intrusions and threat hunting. The purpose is to keep expensive expertise focused on hard problems rather than routine noise.

The delivery model is a genuine decision, not a formality. An in-house SOC gives context and control but is expensive to staff around the clock, which is the constraint most Indonesian organisations hit. A managed provider gives coverage immediately but knows less about your environment. Hybrid models, with a provider covering nights and an internal team owning business hours and context, are increasingly common.

At a glance

Type
Security function
Also known as
SOC, security operation center, pusat operasi keamanan

How it works

  1. 1

    Monitor: telemetry from SIEM, endpoint and network tooling is watched continuously

  2. 2

    Triage: alerts are assessed and false positives closed, usually at Tier 1

  3. 3

    Investigate: surviving alerts are examined for scope and impact

  4. 4

    Respond: containment and remediation are coordinated with system owners

  5. 5

    Improve: detections are tuned and lessons fed back so the same alert does not recur

Key points

  • A SOC is a function, not a facility; coverage and authority matter more than screens
  • Tiering keeps senior expertise on hard problems instead of routine triage
  • In-house, managed and hybrid are all valid; around-the-clock staffing is the usual constraint
  • Mean time to detect and mean time to respond are the meaningful metrics, not alert volume
  • Much of a SOC's workload originates in human error, so reducing that inflow reduces load

Best practices

  • Define severity levels and escalation authority before an incident, not during one
  • Track mean time to detect and respond rather than counting alerts handled
  • Manage analyst fatigue deliberately, since alert overload is why real detections get missed
  • Give the SOC authority to contain, or agree in advance who can approve it out of hours
  • Run the phishing reporting channel into the SOC, since staff reports are a fast early signal

Real-world example

An Indonesian insurer runs a two-person SOC covering business hours with a managed provider overnight. The provider escalates an out-of-hours alert but nobody internal is authorised to disable an account until morning, and the attacker has seven hours. The gap was not detection, it was pre-agreed authority.

How Claro helps

A SOC spends much of its time on the consequences of human error: phishing that succeeded, credentials that were entered, files that were installed. Reducing that inflow lowers SOC load directly. Claro also feeds staff phishing reports in as a detection source, giving the SOC signal earlier than logs typically provide.

Frequently asked questions

What is a security operations center?

A SOC is the team, process and tooling responsible for continuously monitoring systems for security events, investigating detections, and coordinating response. It is a function rather than a physical room.

What is the difference between a SOC and a SIEM?

A SIEM is a platform that collects and correlates log data and raises alerts. A SOC is the human function that acts on those alerts. The SIEM is a tool the SOC uses, and a SIEM without a SOC produces alerts nobody triages.

Should we build a SOC or use a managed provider?

It depends on scale and whether you can realistically staff around the clock. In-house gives context and control at high cost; managed gives immediate coverage with less environmental knowledge. Hybrid, with a provider on nights and internal staff owning business hours, suits many mid-sized Indonesian organisations.

What metrics should a SOC report?

Mean time to detect and mean time to respond are the meaningful ones, alongside coverage of critical log sources and false-positive rate. Alert volume handled measures activity rather than effectiveness.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo