Day 2
Security policy and SOC technical architecture
Participants can turn a policy requirement into a measurable SOC data and decision path, from the source to a decision in the incident management system.
- Training case
- D2-BALTNET-ARCH-001
- Programme topics
- 3, 4
- Assignments
- P1 · P2 · P3 · P4 · ID-02
Where this day sits in the chain
Mandate, notification and evidence continue into the operational framework: what is mandatory, which signals are collected, how they are correlated and where the decision is recorded.
Rule of the day
There is no “magic SIEM”: every step of the data path has a purpose, an owner and quality gates.
Schedule
How the day runs
| Time | Topic | Format | Output |
|---|---|---|---|
| 09:00–09:45 | Information and cybersecurity policy | Theory | Policy control card |
| 10:00–11:00 | SOC technical stack architecture | Theory + mini tasks | Data path and quality gates |
| 11:00–12:00 | Incident management system (IMS) | Practical P1 | Traceable case |
| 13:00–13:45 | SIEM | Practical P2 | Source onboarding plan |
| 13:45–15:00 | NIDS | Practical P3 | Network evidence correlation |
| 15:15–16:30 | HIDS | Practical P4 | Endpoint timeline |
| 16:30–16:55 | Results and reflection | Discussion | Three-layer conclusion |
| 17:00–19:00 | Independent work | ID-02 | SOC architecture decision record |
Learning outcomes
By the end of the day, participants can
- D2.1Tell policy, standard, procedure, playbook and record apart.
- D2.2Write a measurable policy requirement with an owner, an exception and a review date.
- D2.3Explain the data path from source to IMS decision.
- D2.4Assign responsibilities and limits to SIEM, NIDS, HIDS and IMS.
- D2.5Check the time, normalisation, coverage, packet-loss and retention gates.
- D2.6Correlate network and endpoint telemetry into an argued timeline.
- D2.7Write an SOC architecture decision record (ADR) grounded in acceptance criteria.
Practice
Practical assignments
Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.
- P1
IMS case
A traceable case: owner, observables, events and a decision log.- Duration:
- 60 min
- Deliverable:
- ims_byla.md
- P2
SIEM onboarding plan
For each source: owner, value, time, fields, retention and an acceptance test.- Duration:
- 45 min
- Deliverable:
- siem_prijungimo_planas.csv
- P3
NIDS correlation
Suricata alert claims kept apart from Zeek connection facts; time, coverage and packet-loss quality gates checked.- Duration:
- 75 min
- Deliverable:
- nids_analize.md
- P4
HIDS timeline
A Sysmon and Linux authentication timeline tied to the network evidence in a three-layer conclusion.- Duration:
- 75 min
- Deliverable:
- hids_analize.md
Extra labs
For deeper practice
The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.
LAB 5D2-BALTNET-CAP-002
Retention capacity and policy exceptions
Size 180-day search capacity (GB per day, indexing, replicas, headroom) and justify which requested exceptions deserve consideration, each with an end date and a risk owner.
LAB 6D2-BALTNET-QA-003
Telemetry quality and reliable correlation
Separate time zone, clock skew and transport delay, find duplicate delivery, and decide which data can be relied on before changing a detection.
Carry on in your environment
Related tools
CISO.lt
ciso.ltInformation security officer's assistant
Turn the policy control card into an organisational policy with CISO.lt, and try the threat intelligence data path on the locally run SIEM.LT.
- Security policy and procedures
- Incident management plan and notification
- Risk assessment
- NIS2 / GDPR compliance checklists
SIEM.LT
siem.ltLocal-first threat intelligence workstation
Turn the policy control card into an organisational policy with CISO.lt, and try the threat intelligence data path on the locally run SIEM.LT.
- MISP IOC and IP geography
- OSINT / RSS radar in Lithuanian
- IOC de-duplication and STIX 2.1 export
- Docker deployment in minutes