Security Operations Center-as-a-Service (SOCaaS)
Fortinet Security Operations Center-as-a-Service (SOCaaS) offers a cloud-based security monitoring service that analyzes security events generated from your FortiAppSec Cloud, performs alert triage, and escalates confirmed threat notifications. Its key services include:
-
Real-time web application and API security monitoring
-
Clear Call to Action on detected Web Attacks
-
Noise reduction of False Positives and Information alerts
-
Weekly FortiAppSec Cloud executive and threat protection report
To allow the SOCaaS team to perform essential security operations, grant them access to retrieve attack logs from Threat Analytics on FortiCloud.
Step 1 Create an IAM user for the SOCaaS team
Step 2 Wait for the SOCaaS team to complete configuration
Step 3 Onboard your application on SOCaaS
Step 1 Create an IAM user for the SOCaaS team
Step 1.1 Set permission profile for SOCaaS IAM
- Log in to FortiCloud: https://support.fortinet.com/welcome/#/
- Select service from top menu and click “IAM” as following:

- You will see the following page:

- Select Permission Profiles and click Add New:

- Enter permission profile name and optional description and click Add Portal.

- Check FortiAppSec Cloud box and click Add.

- Set WAF - Application, General and Threat Analytics to Read & Write. Click Submit.

- A new permission profile is added successfully.

Step 1.2 Create a user for SOCaaS team
- Select Users, click Add New, then then click IAM User.

- Input the Username, Full Name, Email and Phone, then click Next. For the email address, use “
socaas-noreply@fortinet-us.com”.

- select a Asset Folder. then select the permission profile created in the last step. Click Next.

- Click Confirm, the IAM user is created successfully.
- Click Generate Password. The link will be displayed and click Copy Reset Link to copy the link.


Step 1.3 Share the password link with SOCaaS team
-
Copy and share the Generate password link with the SOCaaSTeam over email
socaas@fortinet.com. The SOCaaS team will set their own password. - Verify 2FA setting and make sure it is set to Email, not FortiToken. As shown below, you need to switch on the Email button.

Step 2 Wait for the SOCaaS team to complete configuration
When onboarding FortiAppSec Cloud to SOCaaS, the process typically involves a waiting period for configuration and service preparation.
Once the configurations are complete, the SOCaaS team will contact you via email to confirm that the SOCaaS service for your FortiAppSec Cloud service is ready.
Step 3 Onboard your application on SOCaaS
The final step is to onboard your application on Fortinet SOCaaS. For detailed instructions, please refer to the following article: Onboarding FortiWeb or FortiAppSec Cloud.