SOC, SIEM and SOAR explained: how they fit, and in-house vs managed SOC
What a SOC, SIEM and SOAR are, how they work together, in-house vs managed SOC, and how CERT-In's 180-day log rule shapes SIEM sizing.
Ahuva Electronic Technologies · Published
Key points
- A security operations centre (SOC) is the team and process that watches an organisation's systems for attacks and responds to them. A SIEM is the software that collects and correlates logs. SOAR is the software that automates response steps.
- NIST SP 800-92, from the US National Institute of Standards and Technology, describes security information and event management (SIEM) software as centralised logging software that collects logs from many sources, normalises them and analyses and correlates them.
- Security orchestration, automation and response (SOAR) automates parts of incident response, such as enriching an alert, blocking an address or opening a case, using playbooks that link security tools together.
- NIST SP 800-61 Revision 3, published in April 2025, recognises that incident handlers may be on staff, on contract through a managed security services provider (MSSP), or a mix of both.
- CERT-In's directions of 28 April 2022 require logs of all information and communication technology (ICT) systems to be kept for a rolling 180 days within Indian jurisdiction. That sets the minimum retention a SIEM or its log store must hold.
- SIEM storage is sized from events per second, average event size, retention period and compression. Counting devices alone does not size it.
What is a SOC?
A SOC is the function that monitors an organisation's networks, systems and applications for security events, decides which are real incidents, and leads the response. It is people and procedures first. The tools support them.
NIST SP 800-215 describes handling security alerts and threat intelligence feeds as part of the incident response process carried out by SOC members. A SOC usually triages alerts, investigates the ones that matter, contains incidents with the IT team, and reports to management and, where the law requires, to CERT-In. A SOC that runs around the clock needs enough trained analysts to cover every shift, holidays and leave. That staffing, not the software, is usually the largest cost.
What does a SIEM do?
A SIEM collects logs from many systems into one place, puts them into a common format and looks for patterns that point to an attack. NIST SP 800-92, the Guide to Computer Security Log Management, describes SIEM products as having log servers that analyse logs and database servers that store them.
NIST SP 800-92 describes two ways a SIEM collects logs. Agentless collection pulls or receives logs over the network without installing software on the source. Agent-based collection installs a small program on the source that filters and normalises logs before sending them. NIST notes SIEMs support many source types, including operating systems, security software, application servers and physical security devices such as badge readers. That last point matters for campuses and public buildings, where access-control and camera systems are log sources too.
The value is in correlation. One failed login means little. Failed logins across many accounts from one address, followed by a success and a large data transfer, is an incident. NIST SP 800-61 Revision 3 recommends using SIEM and SOAR tools to monitor log events continuously and to correlate related data from multiple sources.
What does SOAR add?
SOAR automates the repeatable steps of a response, so analysts spend time on judgment rather than copying data between tools. NIST SP 800-215 describes SOAR as a security strategy to automate the incident response process, with uses in threat detection and response, vulnerability prioritisation, compliance checks and security audits.
A SOAR platform runs playbooks: sequences of steps triggered by an alert. A playbook can look up an address in threat intelligence, pull the related logs, ask the firewall to block the address, disable a user account and open a case with the evidence attached. High-impact steps, such as isolating a server that runs a hospital system, should wait for a person to approve them. SOAR only works as well as its integrations, so every tool it must control needs a supported interface.
How do SOC, SIEM and SOAR fit together?
The SIEM finds and correlates events, SOAR runs the routine response, and the SOC team decides and acts on the rest. Logs flow from firewalls, servers, endpoints and applications into the SIEM. The SIEM raises alerts. SOAR enriches them and runs playbooks. Analysts investigate what remains and lead containment and recovery.
| Part | What it is | Main output |
|---|---|---|
| SOC | Team, shifts and procedures | Decisions, containment, reports |
| SIEM | Log collection and correlation software | Alerts and searchable log history |
| SOAR | Automation and case management software | Playbook actions and case records |
| Log sources | Firewalls, servers, endpoints, applications | Raw events with timestamps |
Should a SOC be in-house or managed?
It depends on whether the organisation can staff every shift and keep skilled analysts. NIST SP 800-61 Revision 3 lists three options for incident handlers: on staff, on contract (for example a SOC outsourced to an MSSP), or available when needed. It notes many organisations combine them, such as handling basic response in-house and bringing in outside help for some incidents.
Two Indian rules shape the contract. CERT-In's FAQ on its 2022 directions says any entity that notices a cyber incident must report it, and that the duty cannot be transferred by contract. So the contract must say who tells whom, and how fast, for the owner to meet the 6-hour deadline. Under the Digital Personal Data Protection Act, 2023, an MSSP that handles personal data in logs is a Data Processor, and section 8(2) requires a valid contract.
| In-house SOC | Managed SOC (MSSP) | Hybrid | |
|---|---|---|---|
| Staffing | Owner hires and trains | Provider supplies analysts | Owner team by day, provider off-hours |
| Control of data | Full | Shared; set by contract | Shared; set by contract |
| Time to start | Long | Short | Medium |
| Main risk | Hiring and retention | Limited knowledge of the site | Unclear hand-offs |
How does CERT-In's 180-day log rule affect SIEM sizing?
It sets the minimum retention the SIEM or its log store must hold. The CERT-In directions of 28 April 2022 require all covered entities, including Government organisations, to enable logs of all ICT systems and keep them securely for a rolling 180 days within Indian jurisdiction. For Central Government bodies, CERT-In's Guidelines on Information Security Practices for Government Entities, released on 30 June 2023, also ask for perimeter device and SIEM logs to be kept for a rolling 180 days, with perimeter and endpoint logs integrated into the SIEM.
Storage follows from four numbers: events per second (EPS) at peak and on average, average event size, days of retention, and the compression the product achieves. As a worked example with assumed inputs, not a benchmark, 2,000 EPS at 500 bytes per event is about 86 GB of raw log a day, or about 15.5 TB over 180 days before compression. Many designs keep recent weeks on fast searchable storage and the rest in cheaper archive that can still be restored and produced to CERT-In. Where logs record access to personal data, rule 6 of the DPDP Rules, 2025 asks for such logs to be kept for one year from May 2027, unless another law requires otherwise, so the longer period may apply.
Time matters as much as space. The CERT-In directions require clocks to be synchronised to National Informatics Centre (NIC) or National Physical Laboratory (NPL) time, and correlation across sources fails without it.
What should a SOC or SIEM tender specify?
A tender should specify what must be watched, how long evidence is kept, and how fast people respond, rather than only a licence count.
- An inventory of log sources, with peak and average EPS measured or estimated for each
- Retention: at least 180 days in India, with how much must be searchable online and how much may be archived
- The detection use cases and correlation rules to be delivered at go-live
- SOAR playbooks, with which steps need human approval
- Triage and escalation times that let the owner report to CERT-In within 6 hours
- Network Time Protocol (NTP) synchronisation to NIC or NPL time for every source
- Monthly reporting, and a named contact on both sides
- Exit terms: logs, rules and playbooks handed back in an open format
How Ahuva approaches security operations
Ahuva's cybersecurity scope covers SOC, SIEM and SOAR, alongside network, endpoint and application security, NGFW, IDS/IPS, WAF and zero-trust, and VAPT and compliance. Ahuva entered cybersecurity in 2025. It holds ISO 27001:2022 for information security management and ISO 20000-1:2018 for service management.
Frequently asked questions
- What is the difference between a SIEM and a SOC?
- A SIEM is software that collects and correlates logs and raises alerts. A SOC is the team and process that investigates those alerts and responds to incidents.
- Does SOAR replace SOC analysts?
- No. SOAR automates routine steps such as enrichment, blocking and case creation, so analysts can focus on investigation and decisions. High-impact actions should still need human approval.
- How long must SIEM logs be kept in India?
- The CERT-In directions of 28 April 2022 require logs of all ICT systems to be kept for a rolling 180 days within Indian jurisdiction. Some logs of access to personal data may need one year under the DPDP Rules from May 2027.
- Can a managed SOC provider report incidents to CERT-In for us?
- CERT-In's FAQ says the reporting duty falls on any entity that notices an incident and cannot be transferred by contract. The contract should set how fast the provider alerts the owner so both can meet the 6-hour deadline.
- What is EPS in SIEM sizing?
- EPS means events per second, the rate at which log sources send events to the SIEM. Combined with event size and retention days, it sets the storage and processing the SIEM needs.
Sources
- SP 800-92: Guide to Computer Security Log Management (September 2006) · National Institute of Standards and Technology (NIST)
- SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cyber Risk Management (April 2025) · National Institute of Standards and Technology (NIST)
- SP 800-215: Guide to a Secure Enterprise Network Landscape (November 2022) · National Institute of Standards and Technology (NIST)
- Directions under sub-section (6) of section 70B of the IT Act, 2000 (28 April 2022) · CERT-In
- Frequently Asked Questions on Cyber Security Directions of 28.04.2022 (May 2022) · CERT-In
- Guidelines on Information Security Practices for Government Entities · CERT-In
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) · Ministry of Electronics and Information Technology
Related
Scoping a system like this? Talk to the team that designs, builds and maintains it.
Contact us