Skip to content

Kit · Governance

SOC build kit

The programme work breakdown for standing up a SOC. The ordering matters more than the speed: every phase gate below exists because skipping it produces a SOC that cannot explain what it does.

Track
Programme build
Gate 1
Baseline before model
Gate 2
Model before tooling
All kits

The gate nobody wants to hold

Technical requirements come after the operating model, not before. A SOC that buys the platform first ends up defining its services as whatever the platform happens to do — and then discovers at the first supervisory conversation that it cannot explain why it monitors what it monitors.

Phases and their gates

PhaseObjectiveDeliverablesGate to the next phase
P0 — Baseline intakeUnderstand the regulatory and policy landscape before designing anythingDocument inventory; gap analysis against the requirementsThe document baseline is received and read
P1 — Mandate and operating modelDefine what the SOC is, what it answers for, and what it will deliverSOC mandate; operating model; organisational structure; initial service catalogue; reviewed job descriptions and incident management planA prepared and approved SOC model exists
P2 — Processes and policiesTurn the model into working procedures and defined rolesIncident management procedure; external cooperation plan; skills list; job descriptions; training plan; the organisational document register populatedThe minimum viable document set is approved
P3 — Performance measurementMake the SOC measurable before it goes liveInternal and external metric sets with targets; measurement procedure; report audience and cadence mapMetrics are defined and their data sources identified
P4 — Technical requirementsDerive tooling from committed services, not the reverseTechnical measures requirements specification; infrastructure requirementsRequirements are written and traceable to services
P5 — Technical build and integrationsStand up the platform and connect it to the national ecosystemWorking threat-intelligence exchange; real-time feed; baseline correlation rule setTelemetry flows and a baseline rule set is live
P6 — Detection scenarios, stagedCover priority attack paths incrementally, proving each stageScenario catalogue; scenario one proven in production; then the next tranchesScenario one is proven before the rest begin

The lean three-month stand-up

For a small SOC that must be operational quickly. Prioritised by capability weight — what buys the most protection per unit of effort.

One-off
0/11

Minimum viable document set before go-live

The documents without which the SOC cannot demonstrate that it operates as a controlled function.

One-off
0/11

Next kit

Outsourced SOC oversight kit

What to require, measure and inspect when detection and response are delivered by a provider — accountability does not transfer with the service.

Open Outsourced SOC oversight kit