Skip to content

Kit · Governance

SOC build kit

The programme work breakdown for standing up a SOC. The ordering matters more than the speed: every phase gate below exists because skipping it produces a SOC that cannot explain what it does.

Track
Programme build
Gate 1
Baseline before model
Gate 2
Model before tooling
All kits

The gate nobody wants to hold

Technical requirements come after the operating model, not before. A SOC that buys the platform first ends up defining its services as whatever the platform happens to do, and then discovers at the first supervisory conversation that it cannot explain why it monitors what it monitors.

Phases and their gates

PhaseObjectiveDeliverablesGate to the next phase
P0: Baseline intakeUnderstand the regulatory and policy landscape before designing anythingDocument inventory; gap analysis against the requirementsThe document baseline is received and read
P1: Mandate and operating modelDefine what the SOC is, what it answers for, and what it will deliverSOC mandate; operating model; organisational structure; initial service catalogue; reviewed job descriptions and incident management planA prepared and approved SOC model exists
P2: Processes and policiesTurn the model into working procedures and defined rolesIncident management procedure; external cooperation plan; skills list; job descriptions; training plan; the organisational document register populatedThe minimum viable document set is approved
P3: Performance measurementMake the SOC measurable before it goes liveInternal and external metric sets with targets; measurement procedure; report audience and cadence mapMetrics are defined and their data sources identified
P4: Technical requirementsDerive tooling from committed services, not the reverseTechnical measures requirements specification; infrastructure requirementsRequirements are written and traceable to services
P5: Technical build and integrationsStand up the platform and connect it to the national ecosystemWorking threat-intelligence exchange; real-time feed; baseline correlation rule setTelemetry flows and a baseline rule set is live
P6: Detection scenarios, stagedCover priority attack paths incrementally, proving each stageScenario catalogue; scenario one proven in production; then the next tranchesScenario one is proven before the rest begin

The lean three-month stand-up

For a small SOC that must be operational quickly. Prioritised by capability weight: what buys the most protection per unit of effort.

One-off
0/11

Minimum viable document set before go-live

The documents without which the SOC cannot demonstrate that it operates as a controlled function.

One-off
0/11

Next kit

Outsourced SOC oversight kit

What to require, measure and inspect when detection and response are delivered by a provider; accountability does not transfer with the service.

Open: Outsourced SOC oversight kit