Skip to content

Mandate

Two pages that decide whether the SOC can act

A mandate is the instrument that turns responsibility into authority. It is short by design — two to three pages — because it is written to be read by executives and cited in disputes. Everything that changes often lives elsewhere: in the service catalogue, the procedures and the playbooks.

Drafted by
CISO
Approved by
Executive management
Length
2–3 pages
Reviewed
≥ annually + on change

Why it exists

Responsibility without authority is a trap

A SOC without a mandate can watch a host being encrypted and still have to find someone with the standing to authorise pulling it off the network. By the time that call connects, the containment window has closed. The mandate is what removes that phone call from the critical path.

It also does something less obvious but equally valuable: it bounds the SOC. A written out-of-scope column, with a named owner against each exclusion, is the defence against the slow accretion of work that turns a detection team into a second-line IT function.

Note the deliberate split in authorship. The security function drafts the powers it needs; only the business can grant them. A mandate approved by IT, or by the security function itself, binds nobody.

Control fieldPurposeValue
TitleNames the instrumentSecurity Operations Centre (SOC) Mandate
Document numberStable reference for citation and audite.g. SOC-MANDATE-001
VersionTracks revisions across reviews1.0 for the initial instrument
Approval dateThe date the mandate enters into force[approval date]
Valid untilTies validity to review rather than to a calendar expiryUntil the review date
Prepared byAuthor of the instrumentChief Information Security Officer
Approved byThe body that can bind other departments to the SOC's authoritiesExecutive management
Signature blockFormal execution[Name, Surname, Position], [Date]
The header block is what makes a mandate an auditable instrument rather than a memo. Note that validity is tied to the review date, not to a calendar expiry — a mandate should never lapse silently.

Section 2

Four authorities, and the clause that makes each one real

Every authority below has a qualifying phrase that people are tempted to cut for brevity. Each of those phrases is the reason the authority works. Keep them.

01

Monitor and analyse

Conduct continuous monitoring of the entire IT infrastructure — networks, servers, endpoint devices and cloud environments — to identify potential threats and security breaches in good time.

Why the wording matters

The grant is continuous and estate-wide. Naming the four environment classes explicitly is what prevents a later argument that cloud, or endpoints, were never in scope.

02

Respond to incidents

On a confirmed cybersecurity incident, take the technical actions necessary to contain the threat and limit its impact.

Why the wording matters

Two things make this clause work: the confirmed-incident precondition, which stops it being an open-ended power, and the enumerated action list framed as 'including, but not limited to', which stops it being read as exhaustive.

03

Demand information

Obtain access to all system logs, configurations and other technical information required for incident investigation and analysis.

Why the wording matters

This authority is only real because of its second half: all IT and other units are obliged to cooperate and provide what the SOC requires. Without that obligation stated, the authority is a request.

04

Initiate change

Issue recommendations to the owners of IT infrastructure and systems on remediating security gaps, changing configurations and deploying additional security controls.

Why the wording matters

The word that carries the weight is 'mandatory'. A recommendation the recipient may ignore without record is not an authority — it is correspondence. Name the addressee: system owners, not 'IT'.

The enumerated containment actions

  • Isolation of affected systems or network segments
  • Termination of malicious processes
  • Blocking or restricting access rights
  • Quarantine of malicious files, held securely for investigation

Keep the “including, but not limited to” framing. An exhaustive list is an invitation to argue that the specific action you took at 02:00 was not on it.

What you offer in return

Ask for pre-authorised containment and bring its conditions with you: the triggers that permit it, an immediate notification duty, a named approver informed after the fact, and a documented rollback. That package is what turns the request from a power grab into a control that a board can approve.

Section 4

The boundary, in two columns

The right-hand column is the one that gets skipped, and it is the more important of the two. Every exclusion must name the unit accountable instead — otherwise the exclusion reads as 'nobody', and it will come back to you.

In scope

  • All managed network segments — LAN, WLAN, WAN
  • All physical and virtual servers in internal data centres
  • All organisation-managed endpoints, including mobile devices
  • Cloud services in use — IaaS, PaaS and SaaS
  • All business applications and databases

Not in scope — and who owns it instead

  • Personal employee devices not connected to the organisation's networkCovered by the BYOD policy
  • Third-party and supplier-managed IT infrastructureSupplier / contract owner
  • Physical building security — access control, video surveillanceFacilities / physical security
  • General IT fault resolution and user supportIT service desk
  • Software licensing and managementIT asset management

Section 6

Reporting line and collaboration

The SOC reports to the CISO and is accountable to them for its activity and its results. Everything else is collaboration — and each collaboration needs its subject matter named, or it will not happen under pressure.

CounterpartSubject matter
IT infrastructure and operationsIncident management, configuration changes, technical information
Legal and complianceLegal aspects of incidents, data protection, cooperation with law enforcement
Human resourcesInternal incidents involving employee conduct
The national cybersecurity centre (NKSC)Statutory incident notification, national coordination, and requests for technical support. CERT-LT is the operational identity under which the same body acts as the national response team — one addressee, two names.
Peer organisations and sector groupsThreat information exchange and coordinated response to wide-scale incidents

Section 7

Review and re-approval

A mandate that is never revisited slowly stops describing the organisation it governs. Write the triggers into the document so that review is an obligation rather than an intention.

  • 01Not less than once a year, regardless of whether anything changed
  • 02On material organisational change — restructuring, merger, new business line
  • 03On material technological change — new estate, new platform, new delivery model
  • 04On material legal change — new or amended legislation, new supervisory guidance
  • 05After a major incident that exposed a gap between the mandate and reality

Circulate before you submit

Send the draft to the units that acquire obligations under authorities 03 and 04 — IT infrastructure and operations, and the system owners — before it goes for approval. Those are the parties whose behaviour the mandate binds. Surprising them at the approval meeting is how a mandate gets diluted into uselessness.