Kit · Governance
SOC build kit
The programme work breakdown for standing up a SOC. The ordering matters more than the speed: every phase gate below exists because skipping it produces a SOC that cannot explain what it does.
- Track
- Programme build
- Gate 1
- Baseline before model
- Gate 2
- Model before tooling
The gate nobody wants to hold
Technical requirements come after the operating model, not before. A SOC that buys the platform first ends up defining its services as whatever the platform happens to do — and then discovers at the first supervisory conversation that it cannot explain why it monitors what it monitors.
Phases and their gates
| Phase | Objective | Deliverables | Gate to the next phase |
|---|---|---|---|
| P0 — Baseline intake | Understand the regulatory and policy landscape before designing anything | Document inventory; gap analysis against the requirements | The document baseline is received and read |
| P1 — Mandate and operating model | Define what the SOC is, what it answers for, and what it will deliver | SOC mandate; operating model; organisational structure; initial service catalogue; reviewed job descriptions and incident management plan | A prepared and approved SOC model exists |
| P2 — Processes and policies | Turn the model into working procedures and defined roles | Incident management procedure; external cooperation plan; skills list; job descriptions; training plan; the organisational document register populated | The minimum viable document set is approved |
| P3 — Performance measurement | Make the SOC measurable before it goes live | Internal and external metric sets with targets; measurement procedure; report audience and cadence map | Metrics are defined and their data sources identified |
| P4 — Technical requirements | Derive tooling from committed services, not the reverse | Technical measures requirements specification; infrastructure requirements | Requirements are written and traceable to services |
| P5 — Technical build and integrations | Stand up the platform and connect it to the national ecosystem | Working threat-intelligence exchange; real-time feed; baseline correlation rule set | Telemetry flows and a baseline rule set is live |
| P6 — Detection scenarios, staged | Cover priority attack paths incrementally, proving each stage | Scenario catalogue; scenario one proven in production; then the next tranches | Scenario one is proven before the rest begin |
The lean three-month stand-up
For a small SOC that must be operational quickly. Prioritised by capability weight — what buys the most protection per unit of effort.
Minimum viable document set before go-live
The documents without which the SOC cannot demonstrate that it operates as a controlled function.
Next kit
Outsourced SOC oversight kit
What to require, measure and inspect when detection and response are delivered by a provider — accountability does not transfer with the service.