Kit · Governance
SOC build kit
The programme work breakdown for standing up a SOC. The ordering matters more than the speed: every phase gate below exists because skipping it produces a SOC that cannot explain what it does.
- Track
- Programme build
- Gate 1
- Baseline before model
- Gate 2
- Model before tooling
The gate nobody wants to hold
Technical requirements come after the operating model, not before. A SOC that buys the platform first ends up defining its services as whatever the platform happens to do, and then discovers at the first supervisory conversation that it cannot explain why it monitors what it monitors.
Phases and their gates
| Phase | Objective | Deliverables | Gate to the next phase |
|---|---|---|---|
| P0: Baseline intake | Understand the regulatory and policy landscape before designing anything | Document inventory; gap analysis against the requirements | The document baseline is received and read |
| P1: Mandate and operating model | Define what the SOC is, what it answers for, and what it will deliver | SOC mandate; operating model; organisational structure; initial service catalogue; reviewed job descriptions and incident management plan | A prepared and approved SOC model exists |
| P2: Processes and policies | Turn the model into working procedures and defined roles | Incident management procedure; external cooperation plan; skills list; job descriptions; training plan; the organisational document register populated | The minimum viable document set is approved |
| P3: Performance measurement | Make the SOC measurable before it goes live | Internal and external metric sets with targets; measurement procedure; report audience and cadence map | Metrics are defined and their data sources identified |
| P4: Technical requirements | Derive tooling from committed services, not the reverse | Technical measures requirements specification; infrastructure requirements | Requirements are written and traceable to services |
| P5: Technical build and integrations | Stand up the platform and connect it to the national ecosystem | Working threat-intelligence exchange; real-time feed; baseline correlation rule set | Telemetry flows and a baseline rule set is live |
| P6: Detection scenarios, staged | Cover priority attack paths incrementally, proving each stage | Scenario catalogue; scenario one proven in production; then the next tranches | Scenario one is proven before the rest begin |
The lean three-month stand-up
For a small SOC that must be operational quickly. Prioritised by capability weight: what buys the most protection per unit of effort.
Minimum viable document set before go-live
The documents without which the SOC cannot demonstrate that it operates as a controlled function.
Next kit
Outsourced SOC oversight kit
What to require, measure and inspect when detection and response are delivered by a provider; accountability does not transfer with the service.