Kit · Governance
SOC mandate builder
A section-by-section drafting template for a SOC charter, taken from a real approved instrument. Work down it in order; every line is a decision someone will otherwise make for you during an incident.
- Output
- Approved SOC mandate
- Length
- 2–3 pages
- Approved by
- Executive management
Establishing a mandate from scratch
Take a SOC from having no formal standing to holding an approved, enforceable charter.
The four authorities and their load-bearing clauses
| Authority | What it grants | The clause not to cut |
|---|---|---|
| Monitor and analyse | Continuous monitoring of the entire estate — networks, servers, endpoints, cloud | Name all four environment classes. Omitting cloud is how cloud ends up unmonitored. |
| Respond to incidents | Technical action to contain the threat and limit impact | The confirmed-incident precondition, and the non-exhaustive framing of the action list. |
| Demand information | Access to logs, configurations and technical information for investigation | The obligation on all units to cooperate. Without it, the authority is a request. |
| Initiate change | Recommendations to system owners on gaps, configuration and controls | That the recommendations are mandatory to act on or formally decline — and addressed to named system owners. |
Annual mandate review
Confirm the mandate still describes the organisation it governs.
Keep the operational detail out
The mandate is deliberately short so that it can be read by executives and cited in disputes. Response times, service lines, playbooks, tool names and staffing all belong in the service catalogue and the SOPs — documents that can change without a board meeting.
Next kit
Triage & escalation kit
The L1/L2/L3 decision gates, the severity model, mandatory intake fields, and the escalation triggers written so an analyst can apply them at 03:00.