Programme
Information and Cyber Security Governance for SOC Teams
To give the theory and build the practical skills needed to organise and run a SOC team: monitoring security events, managing vulnerabilities and threat intelligence, incident triage and threat hunting, collecting and preserving digital evidence, applying response playbooks and recovering systems after incidents, within Lithuanian and EU law.
- Duration
- 5 days
- Workload
- 90 academic hours · 3 credits
- Format
- Online (MS Teams / Zoom)
- Author
- dr. Šarūnas Grigaliūnas
Five days
One chain, from mandate to lessons
Every day has its own synthetic BALTNET case, theory, two to four practical stages, a Kahoot check and independent work. Each day builds on the previous day's output.
Day 1
Day planSOC mandate, incident notification and digital evidence
Mandate, the NIS2 24 / 72 h clock, evidence provenance and integrity.
D1-BALTNET-001Topics 1, 2P1 · P2 · P3 · ID-01
Day 2
Day planSecurity policy and SOC technical architecture
Policy, the data path, IMS, SIEM, NIDS and HIDS.
D2-BALTNET-ARCH-001Topics 3, 4P1 · P2 · P3 · P4 · ID-02
Day 3
Day planSOC maturity, threat intelligence (CTI) and vulnerability management
O/P/T/P maturity, PIRs, CVSS / EPSS / KEV prioritisation and MISP.
D3-BALTNET-MAT-001Topic 5P1 · P2 · P3 · P4 · ID-03
Day 4
Day planIncident investigation, threat hunting, playbooks and SOAR
Triage, hypothesis-driven hunting, a playbook with human gates, a safe SOAR simulation.
D4-BALTNET-HUNT-001Topics 6, 7P1 · P2 · P3 · P4 · ID-04
Day 5
Day planCulture, exercises, system recovery and lessons learned
Behaviour metrics, tabletop exercises, GO / NO-GO recovery and reporting.
D5-BALTNET-REC-001Topics 8, 9, 10P1 · P2 · ID-05
Content
Ten programme topics
Workload in academic hours: theory (T), practical (P) and independent work (SD). Practice gets three times as much time as theory.
| No. | Topic | T / P / SD | Day |
|---|---|---|---|
| 1 | SOC role and operating modelSOC processes, roles, responsibilities, escalation, and how the SOC works with the CISO, IT, management and CSIRT/CERT. | 1 / 1 / 2 | Day 1 |
| 2 | SOC legal requirementsNIS2 and national notification duties, working with NKSC, personal data protection, and the legal side of collecting, preserving and handing over digital evidence. | 2 / 2 / 3 | Day 1 |
| 3 | SOC governance and processesService catalogue, process descriptions, responsibility matrix, escalation rules, SLA/OLA, performance indicators and accountability. | 1 / 3 / 3 | Day 2 |
| 4 | SOC technology architectureSIEM, EDR/XDR, NDR, IDS/IPS, log collection and normalisation; deploying and integrating Suricata, Zeek and other tools in line with NKSC recommendations. | 2 / 6 / 4 | Day 2 |
| 5 | Threat intelligence and vulnerability managementVulnerability prioritisation, IOC and TTP analysis, source evaluation, MISP, STIX/TAXII and integration with SIEM and incident processes. | 2 / 6 / 4 | Day 3 |
| 6 | Incident triage and threat huntingIdentifying, classifying and prioritising incidents; log and network traffic analysis; MITRE ATT&CK; hypothesis-driven hunting; separating anomalies from false positives. | 2 / 10 / 5 | Day 4 |
| 7 | SOC playbooks and SOARWriting, testing, versioning and automating response playbooks; integration with SIEM, EDR and CTI; fast containment that keeps a human in the decision. | 1 / 7 / 4 | Day 4 |
| 8 | SOC culture and teamworkShift handover, shared situational awareness, documenting decisions, resilience under load, and blameless review. | 1 / 1 / 1 | Day 5 |
| 9 | SOC training and exercisesTabletop, purple-team and incident simulations, testing detection rules, the knowledge base and individual competence development. | 1 / 3 / 2 | Day 5 |
| 10 | Recovery and post-incident activityContainment, eradication and recovery; recovery priorities; evidence preservation; technical and regulatory reports; lessons learned. | 2 / 6 / 2 | Day 5 |
| Total | 15 / 45 / 30 | 1–5 |
Learning outcomes
What participants can do after five days
The programme objectives are written as working capabilities, not as a list of topics.
- U01
The SOC in the organisation
Operating models, roles, responsibilities, escalation and working with the CISO, IT, management and CSIRT / CERT.
- U02
Law and regulation
NIS2 and the Lithuanian Cybersecurity Law, notification to NKSC, personal data protection and handling digital evidence.
- U03
SOC technology architecture
Designing, configuring and integrating SIEM, EDR/XDR, NDR, IDS/IPS and log management.
- U04
Vulnerabilities and threat intelligence
Prioritisation, IOC and TTP analysis, source evaluation, MISP and STIX / TAXII.
- U05
Incident investigation
Triage, log and network traffic analysis, MITRE ATT&CK, hypothesis-driven hunting and fewer false positives.
- U06
Response and recovery
Playbooks and SOAR, containment, system recovery, technical and regulatory reports, lessons learned.
How the work is done
Fact, decision, owner, deadline, evidence
The same formula repeats across all five days. It forces a separation between what the data shows and what one would like it to show.
- 01
Fact
Every claim rests on a file, a record ID and a time, not on instinct or a tool's label.
- 02
Decision
What the data supports, what it does not, and what is still missing are kept apart.
- 03
Owner
Legal, technical and business decisions belong to different people, and they are named.
- 04
Deadline
The notification clock, RTO / RPO, remediation and review dates are calculated traceably.
- 05
Evidence
Work counts as done only when there is verifiable acceptance or closure evidence.
Every conclusion carries a file, a record ID, a time, a justification and a next step. You never modify original evidence; you fill in copies of the templates.
Lab safety boundaries
- All data is synthetic: .example domains and documentation IP ranges (RFC 5737).
- No action on production systems; commands found in logs are never executed and addresses are never looked up online.
- Original evidence is never modified: work is done on copies and integrity is checked with SHA-256.
- Isolation, account blocking and SOAR actions are simulated only, with mandatory human gates.
- Training MISP events are never published or synchronised.
Workstation
The participant workstation is Windows 11 x64. A PowerShell script installs eight packages via WinGet, creates a Python .venv (with tzdata) and runs a pinned local CyberChef 11.4.0 on loopback only. Security Onion and MISP practice uses a separate training environment accepted by the instructor.
- Google Chrome
- Kahoot, local CyberChef and training servers
- PowerShell 7
- UTF-8, CSV, JSON, SHA-256 and automation
- Python 3.13
- Normalisation, correlation and a local server
- Visual Studio Code
- Editing Markdown, JSON, JSONL, YAML and Python
- Wireshark · TShark
- Analysing the supplied PCAP
- LibreOffice
- CSV calculations, DOCX, XLSX and PPTX
- 7-Zip
- Training archives
- Git
- Version history for your own rules and playbooks
Assessment
A pass means at least 70 %
What gets marked is work that can be checked: practical artefacts, individual documents and knowledge tests.
- 45 %
- Practical work17 core practical stages (P1–P4) across the five days, marked against rubrics.
- 30 %
- Individual workFive independent assignments ID-01–ID-05: each day's result carried into your own organisation.
- 25 %
- TestsA daily 12-question Kahoot knowledge check and a final five-day test.
Pass conditions
A pass requires at least 70 % overall and every mandatory assignment submitted. The 70 % Kahoot benchmark means at least 9 of 12 correct answers. Attendance is recorded; completion earns a non-formal education certificate.
After the course
Tools to carry the work into your organisation
The course outputs (a notification draft, a policy card, IOC decisions, a recovery plan) should not stay in the classroom. These two projects help move them into daily work.
CISO.lt
ciso.ltInformation security officer's assistant
An AI assistant for Lithuanian organisations: security policies and procedures, incident management plans, risk assessment, and NIS2 and GDPR compliance. In the course it helps turn the Day 1, 2 and 5 outputs into your own organisation's documents.
- Security policy and procedures
- Incident management plan and notification
- Risk assessment
- NIS2 / GDPR compliance checklists
SIEM.LT
siem.ltLocal-first threat intelligence workstation
An open-source, locally run threat intelligence workstation: MISP indicators, interactive IP geolocation, a Lithuanian news radar, and IOC export to CSV or STIX 2.1. In the course it lets you carry the Day 2–4 SIEM, CTI and MISP work into your own environment.
- MISP IOC and IP geography
- OSINT / RSS radar in Lithuanian
- IOC de-duplication and STIX 2.1 export
- Docker deployment in minutes
Author
Programme author
dr. Šarūnas Grigaliūnas
Programme author
Cybersecurity researcher in financial-technology businesses and consultant in ICT and security risk management: e-crime management, digital content monitoring and incident response.
Core and further reading
- Kibernetinio saugumo įstatymas (e-seimas)
- NKSC: KSIS
- Directive (EU) 2022/2555 (NIS2)
- Regulation (EU) 2016/679 (GDPR)
- NIST SP 800-61 Rev. 3
- MITRE ATT&CK Enterprise
- FIRST CSIRT Services Framework v2.1
- MISP Project Documentation
- Suricata User Guide
- Zeek Documentation
- OASIS STIX / TAXII 2.1
The SOC Officer manual
This site is also a procedural manual for the head of a SOC: mandate, operating model, incident procedure, NIS2 and Lithuanian law compliance, and working kits. It serves as reference material before and after the course.
Open the manualStart with day one.
Before the first day, set up a Windows 11 workstation using the instructions in the participant pack. The instructor provides the participant pack and the Kahoot PIN.