Skip to content

Programme

Information and Cyber Security Governance for SOC Teams

To give the theory and build the practical skills needed to organise and run a SOC team: monitoring security events, managing vulnerabilities and threat intelligence, incident triage and threat hunting, collecting and preserving digital evidence, applying response playbooks and recovering systems after incidents, within Lithuanian and EU law.

Duration
5 days
Workload
90 academic hours · 3 credits
Format
Online (MS Teams / Zoom)
Author
dr. Šarūnas Grigaliūnas

Content

Ten programme topics

Workload in academic hours: theory (T), practical (P) and independent work (SD). Practice gets three times as much time as theory.

No.TopicT / P / SDDay
1SOC role and operating modelSOC processes, roles, responsibilities, escalation, and how the SOC works with the CISO, IT, management and CSIRT/CERT.1 / 1 / 2Day 1
2SOC legal requirementsNIS2 and national notification duties, working with NKSC, personal data protection, and the legal side of collecting, preserving and handing over digital evidence.2 / 2 / 3Day 1
3SOC governance and processesService catalogue, process descriptions, responsibility matrix, escalation rules, SLA/OLA, performance indicators and accountability.1 / 3 / 3Day 2
4SOC technology architectureSIEM, EDR/XDR, NDR, IDS/IPS, log collection and normalisation; deploying and integrating Suricata, Zeek and other tools in line with NKSC recommendations.2 / 6 / 4Day 2
5Threat intelligence and vulnerability managementVulnerability prioritisation, IOC and TTP analysis, source evaluation, MISP, STIX/TAXII and integration with SIEM and incident processes.2 / 6 / 4Day 3
6Incident triage and threat huntingIdentifying, classifying and prioritising incidents; log and network traffic analysis; MITRE ATT&CK; hypothesis-driven hunting; separating anomalies from false positives.2 / 10 / 5Day 4
7SOC playbooks and SOARWriting, testing, versioning and automating response playbooks; integration with SIEM, EDR and CTI; fast containment that keeps a human in the decision.1 / 7 / 4Day 4
8SOC culture and teamworkShift handover, shared situational awareness, documenting decisions, resilience under load, and blameless review.1 / 1 / 1Day 5
9SOC training and exercisesTabletop, purple-team and incident simulations, testing detection rules, the knowledge base and individual competence development.1 / 3 / 2Day 5
10Recovery and post-incident activityContainment, eradication and recovery; recovery priorities; evidence preservation; technical and regulatory reports; lessons learned.2 / 6 / 2Day 5
Total15 / 45 / 301–5
Contact learning: 60 academic hours (15 T + 45 P); independent work: 30 academic hours.

Learning outcomes

What participants can do after five days

The programme objectives are written as working capabilities, not as a list of topics.

  • U01

    The SOC in the organisation

    Operating models, roles, responsibilities, escalation and working with the CISO, IT, management and CSIRT / CERT.

  • U02

    Law and regulation

    NIS2 and the Lithuanian Cybersecurity Law, notification to NKSC, personal data protection and handling digital evidence.

  • U03

    SOC technology architecture

    Designing, configuring and integrating SIEM, EDR/XDR, NDR, IDS/IPS and log management.

  • U04

    Vulnerabilities and threat intelligence

    Prioritisation, IOC and TTP analysis, source evaluation, MISP and STIX / TAXII.

  • U05

    Incident investigation

    Triage, log and network traffic analysis, MITRE ATT&CK, hypothesis-driven hunting and fewer false positives.

  • U06

    Response and recovery

    Playbooks and SOAR, containment, system recovery, technical and regulatory reports, lessons learned.

How the work is done

Fact, decision, owner, deadline, evidence

The same formula repeats across all five days. It forces a separation between what the data shows and what one would like it to show.

  1. 01

    Fact

    Every claim rests on a file, a record ID and a time, not on instinct or a tool's label.

  2. 02

    Decision

    What the data supports, what it does not, and what is still missing are kept apart.

  3. 03

    Owner

    Legal, technical and business decisions belong to different people, and they are named.

  4. 04

    Deadline

    The notification clock, RTO / RPO, remediation and review dates are calculated traceably.

  5. 05

    Evidence

    Work counts as done only when there is verifiable acceptance or closure evidence.

Every conclusion carries a file, a record ID, a time, a justification and a next step. You never modify original evidence; you fill in copies of the templates.

Lab safety boundaries

  • All data is synthetic: .example domains and documentation IP ranges (RFC 5737).
  • No action on production systems; commands found in logs are never executed and addresses are never looked up online.
  • Original evidence is never modified: work is done on copies and integrity is checked with SHA-256.
  • Isolation, account blocking and SOAR actions are simulated only, with mandatory human gates.
  • Training MISP events are never published or synchronised.

Workstation

The participant workstation is Windows 11 x64. A PowerShell script installs eight packages via WinGet, creates a Python .venv (with tzdata) and runs a pinned local CyberChef 11.4.0 on loopback only. Security Onion and MISP practice uses a separate training environment accepted by the instructor.

Google Chrome
Kahoot, local CyberChef and training servers
PowerShell 7
UTF-8, CSV, JSON, SHA-256 and automation
Python 3.13
Normalisation, correlation and a local server
Visual Studio Code
Editing Markdown, JSON, JSONL, YAML and Python
Wireshark · TShark
Analysing the supplied PCAP
LibreOffice
CSV calculations, DOCX, XLSX and PPTX
7-Zip
Training archives
Git
Version history for your own rules and playbooks

Assessment

A pass means at least 70 %

What gets marked is work that can be checked: practical artefacts, individual documents and knowledge tests.

45 %
Practical work17 core practical stages (P1–P4) across the five days, marked against rubrics.
30 %
Individual workFive independent assignments ID-01–ID-05: each day's result carried into your own organisation.
25 %
TestsA daily 12-question Kahoot knowledge check and a final five-day test.

Pass conditions

A pass requires at least 70 % overall and every mandatory assignment submitted. The 70 % Kahoot benchmark means at least 9 of 12 correct answers. Attendance is recorded; completion earns a non-formal education certificate.

After the course

Tools to carry the work into your organisation

The course outputs (a notification draft, a policy card, IOC decisions, a recovery plan) should not stay in the classroom. These two projects help move them into daily work.

  • CISO.lt

    ciso.lt

    Information security officer's assistant

    An AI assistant for Lithuanian organisations: security policies and procedures, incident management plans, risk assessment, and NIS2 and GDPR compliance. In the course it helps turn the Day 1, 2 and 5 outputs into your own organisation's documents.

    • Security policy and procedures
    • Incident management plan and notification
    • Risk assessment
    • NIS2 / GDPR compliance checklists
  • SIEM.LT

    siem.lt

    Local-first threat intelligence workstation

    An open-source, locally run threat intelligence workstation: MISP indicators, interactive IP geolocation, a Lithuanian news radar, and IOC export to CSV or STIX 2.1. In the course it lets you carry the Day 2–4 SIEM, CTI and MISP work into your own environment.

    • MISP IOC and IP geography
    • OSINT / RSS radar in Lithuanian
    • IOC de-duplication and STIX 2.1 export
    • Docker deployment in minutes

Author

Programme author

  • dr. Šarūnas Grigaliūnas

    Programme author

    Cybersecurity researcher in financial-technology businesses and consultant in ICT and security risk management: e-crime management, digital content monitoring and incident response.

Core and further reading

The SOC Officer manual

This site is also a procedural manual for the head of a SOC: mandate, operating model, incident procedure, NIS2 and Lithuanian law compliance, and working kits. It serves as reference material before and after the course.

Open the manual

Start with day one.

Before the first day, set up a Windows 11 workstation using the instructions in the participant pack. The instructor provides the participant pack and the Kahoot PIN.