Security Operations Center
The team and function responsible for monitoring, detecting and responding to security events, often around the clock.
Definition
A security operations center (SOC) is the team, process and tooling responsible for continuously monitoring an organisation's systems for security events, investigating what is detected, and coordinating the response.
A SOC is a function rather than a room. Many organisations picture a wall of screens, but what matters is whether someone is watching, whether they can tell a real incident from noise, and whether they have authority to act. A small team with clear escalation paths outperforms an impressive facility without them.
SOCs are commonly tiered. Tier 1 triages alerts and closes false positives. Tier 2 investigates what survives triage. Tier 3 handles complex intrusions and threat hunting. The purpose is to keep expensive expertise focused on hard problems rather than routine noise.
The delivery model is a genuine decision, not a formality. An in-house SOC gives context and control but is expensive to staff around the clock, which is the constraint most Indonesian organisations hit. A managed provider gives coverage immediately but knows less about your environment. Hybrid models, with a provider covering nights and an internal team owning business hours and context, are increasingly common.
At a glance
- Type
- Security function
- Also known as
- SOC, security operation center, pusat operasi keamanan
How it works
- 1
Monitor: telemetry from SIEM, endpoint and network tooling is watched continuously
- 2
Triage: alerts are assessed and false positives closed, usually at Tier 1
- 3
Investigate: surviving alerts are examined for scope and impact
- 4
Respond: containment and remediation are coordinated with system owners
- 5
Improve: detections are tuned and lessons fed back so the same alert does not recur
Key points
- A SOC is a function, not a facility; coverage and authority matter more than screens
- Tiering keeps senior expertise on hard problems instead of routine triage
- In-house, managed and hybrid are all valid; around-the-clock staffing is the usual constraint
- Mean time to detect and mean time to respond are the meaningful metrics, not alert volume
- Much of a SOC's workload originates in human error, so reducing that inflow reduces load
Best practices
- Define severity levels and escalation authority before an incident, not during one
- Track mean time to detect and respond rather than counting alerts handled
- Manage analyst fatigue deliberately, since alert overload is why real detections get missed
- Give the SOC authority to contain, or agree in advance who can approve it out of hours
- Run the phishing reporting channel into the SOC, since staff reports are a fast early signal
Real-world example
An Indonesian insurer runs a two-person SOC covering business hours with a managed provider overnight. The provider escalates an out-of-hours alert but nobody internal is authorised to disable an account until morning, and the attacker has seven hours. The gap was not detection, it was pre-agreed authority.
How Claro helps
A SOC spends much of its time on the consequences of human error: phishing that succeeded, credentials that were entered, files that were installed. Reducing that inflow lowers SOC load directly. Claro also feeds staff phishing reports in as a detection source, giving the SOC signal earlier than logs typically provide.
Frequently asked questions
What is a security operations center?
A SOC is the team, process and tooling responsible for continuously monitoring systems for security events, investigating detections, and coordinating response. It is a function rather than a physical room.
What is the difference between a SOC and a SIEM?
A SIEM is a platform that collects and correlates log data and raises alerts. A SOC is the human function that acts on those alerts. The SIEM is a tool the SOC uses, and a SIEM without a SOC produces alerts nobody triages.
Should we build a SOC or use a managed provider?
It depends on scale and whether you can realistically staff around the clock. In-house gives context and control at high cost; managed gives immediate coverage with less environmental knowledge. Hybrid, with a provider on nights and internal staff owning business hours, suits many mid-sized Indonesian organisations.
What metrics should a SOC report?
Mean time to detect and mean time to respond are the meaningful ones, alongside coverage of critical log sources and false-positive rate. Alert volume handled measures activity rather than effectiveness.
Related terms
SIEM
A platform that centralises log data from across an estate, correlates it, and raises alerts on suspicious patterns.
Incident Response
The structured process an organization follows to detect, contain, investigate, and recover from a security incident.
Phish-Prone Rate
The percentage of employees who fail a simulated phishing test by clicking a link, opening an attachment, or submitting credentials.
Human Risk Management
A security discipline that identifies, measures, and reduces the risk that people introduce through their everyday behavior.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo