Skip to content

Day 2

Security policy and SOC technical architecture

Participants can turn a policy requirement into a measurable SOC data and decision path, from the source to a decision in the incident management system.

Training case
D2-BALTNET-ARCH-001
Programme topics
3, 4
Assignments
P1 · P2 · P3 · P4 · ID-02

Where this day sits in the chain

Mandate, notification and evidence continue into the operational framework: what is mandatory, which signals are collected, how they are correlated and where the decision is recorded.

Rule of the day

There is no “magic SIEM”: every step of the data path has a purpose, an owner and quality gates.

Schedule

How the day runs

TimeTopicFormatOutput
09:00–09:45Information and cybersecurity policyTheoryPolicy control card
10:00–11:00SOC technical stack architectureTheory + mini tasksData path and quality gates
11:00–12:00Incident management system (IMS)Practical P1Traceable case
13:00–13:45SIEMPractical P2Source onboarding plan
13:45–15:00NIDSPractical P3Network evidence correlation
15:15–16:30HIDSPractical P4Endpoint timeline
16:30–16:55Results and reflectionDiscussionThree-layer conclusion
17:00–19:00Independent workID-02SOC architecture decision record
Breaks: 09:45–10:00, 12:00–13:00 (lunch) and 15:00–15:15. Sessions run online.

Learning outcomes

By the end of the day, participants can

  1. D2.1Tell policy, standard, procedure, playbook and record apart.
  2. D2.2Write a measurable policy requirement with an owner, an exception and a review date.
  3. D2.3Explain the data path from source to IMS decision.
  4. D2.4Assign responsibilities and limits to SIEM, NIDS, HIDS and IMS.
  5. D2.5Check the time, normalisation, coverage, packet-loss and retention gates.
  6. D2.6Correlate network and endpoint telemetry into an argued timeline.
  7. D2.7Write an SOC architecture decision record (ADR) grounded in acceptance criteria.

Practice

Practical assignments

Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.

  1. P1

    IMS case

    A traceable case: owner, observables, events and a decision log.
    Duration:
    60 min
    Deliverable:
    ims_byla.md
  2. P2

    SIEM onboarding plan

    For each source: owner, value, time, fields, retention and an acceptance test.
    Duration:
    45 min
    Deliverable:
    siem_prijungimo_planas.csv
  3. P3

    NIDS correlation

    Suricata alert claims kept apart from Zeek connection facts; time, coverage and packet-loss quality gates checked.
    Duration:
    75 min
    Deliverable:
    nids_analize.md
  4. P4

    HIDS timeline

    A Sysmon and Linux authentication timeline tied to the network evidence in a three-layer conclusion.
    Duration:
    75 min
    Deliverable:
    hids_analize.md

Extra labs

For deeper practice

The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.

  • LAB 5D2-BALTNET-CAP-002

    Retention capacity and policy exceptions

    Size 180-day search capacity (GB per day, indexing, replicas, headroom) and justify which requested exceptions deserve consideration, each with an end date and a risk owner.

  • LAB 6D2-BALTNET-QA-003

    Telemetry quality and reliable correlation

    Separate time zone, clock skew and transport delay, find duplicate delivery, and decide which data can be relied on before changing a detection.

Carry on in your environment

Related tools

  • CISO.lt

    ciso.lt

    Information security officer's assistant

    Turn the policy control card into an organisational policy with CISO.lt, and try the threat intelligence data path on the locally run SIEM.LT.

    • Security policy and procedures
    • Incident management plan and notification
    • Risk assessment
    • NIS2 / GDPR compliance checklists
  • SIEM.LT

    siem.lt

    Local-first threat intelligence workstation

    Turn the policy control card into an organisational policy with CISO.lt, and try the threat intelligence data path on the locally run SIEM.LT.

    • MISP IOC and IP geography
    • OSINT / RSS radar in Lithuanian
    • IOC de-duplication and STIX 2.1 export
    • Docker deployment in minutes

Previous day

Day 1: SOC mandate, incident notification and digital evidence

Day 1

Next day

Day 3: SOC maturity, threat intelligence (CTI) and vulnerability management

Day 3