Kits
Instruction and help kits
Fifteen working kits for the person running the SOC. Each is a procedure you can execute, not a description of one: checklists that keep their state, reference tables you can put in front of an auditor, and templates you can lift straight into your own document set.
- Kits
- 15
- Format
- Checklists, tables, templates
- State
- Saved in your browser
- Export
- Copy as Markdown · Print
How to use these
Nothing here is a standard you must adopt whole. Take a kit, cut what does not apply to your estate, and put the remainder into your own controlled document set with a version and an owner. A checklist that lives only on this site is not a control — it becomes one when it is approved, dated, and someone is accountable for running it.
Leadership
03First 90 days as SOC Officer
A sequenced plan for taking over a SOC: what to establish in week one, what to measure by day 30, and what must be signed by day 90.
Use when: You have just taken the role, or inherited a SOC with no written baseline.
Board communication kit
The arguments that land with a management body, the numbers to bring, and how to ask for resource in terms of accepted risk.
Use when: Budget cycles, post-incident briefings, and annual measure re-approval.
Team & competency kit
Roles and minimum qualifications per tier, the skills matrix, the training plan, and segregation of duties inside a small team.
Use when: Hiring, appraisal, and whenever one person has become a single point of failure.
Governance
04SOC mandate builder
The section-by-section skeleton of a formal SOC charter — authorities, scope boundary, reporting line, review triggers — plus the approval checklist.
Use when: Standing up a SOC, or discovering that yours has been operating without a signed mandate.
Service catalogue kit
Define what the SOC actually offers: service lines, tiers, coverage windows, response targets, and the demarcation from IT service desk.
Use when: When expectations and delivery have drifted apart, or before contracting.
SOC build kit
The programme work breakdown for standing up a SOC — organisational measures, technical measures, detection scenarios and staffing.
Use when: Greenfield build, or rebuilding a SOC that grew without a plan.
Outsourced SOC oversight kit
What to require, measure and inspect when detection and response are delivered by a provider — accountability does not transfer with the service.
Use when: Selecting, contracting or reviewing an external SOC or MDR provider.
Operations
02Shift & handover kit
Start-of-shift verification, the handover record that survives an audit, on-call rules, and the escalation contact matrix.
Use when: Every shift change, and when standing up out-of-hours coverage.
Environment onboarding kit
The step-by-step plan for bringing a new environment or log source under monitoring, and the verification that proves coverage is real.
Use when: Any new client, subsidiary, cloud tenancy or major system going live.
Incident
02Triage & escalation kit
The L1/L2/L3 decision gates, the severity model, mandatory intake fields, and the escalation triggers written so an analyst can apply them at 03:00.
Use when: Every shift. Also when escalations are arriving too late or too often.
Evidence & forensics kit
Collection order, chain of custody, integrity verification and retention — the discipline that decides whether your investigation stands up later.
Use when: The moment an incident may become legal, regulatory or HR business.
Compliance
02Regulatory notification kit
The significant-incident test in operational language, the 24h / 72h / one-month submission pack, and the notification clock.
Use when: The moment an incident looks like it might be significant — not after you are sure.
Monthly report & KPI kit
A complete report table of contents, the KPI catalogue with definitions and targets, and the production procedure that gets it out on time.
Use when: Monthly, and whenever the board asks what the SOC actually delivered.