Skip to content

Day 3

SOC maturity, threat intelligence (CTI) and vulnerability management

Participants can assess SOC maturity on evidence and turn CTI into a prioritised, controlled vulnerability and MISP decision.

Training case
D3-BALTNET-MAT-001
Programme topics
5
Assignments
P1 · P2 · P3 · P4 · ID-03

Where this day sits in the chain

Sequence: policy, architecture, signal, decision. The morning tests whether SOC capabilities are proven by organisation, people, tools and process artefacts; the afternoon applies them to CTI and vulnerabilities.

Rule of the day

The teaching O/P/T/P evidence scale is not an official SIM3 assessment, score or certification result.

Schedule

How the day runs

TimeTopicFormatOutput
09:00–09:45SOC maturity. Structure of the SIM3 modelTheoryMaturity claim and evidence gate
10:00–11:00O/P/T/P evidence mapPractical P1Dimension view
11:00–12:0090-day maturity improvement queuePractical P25 work items with acceptance criteria
13:00–13:45Managing threat intelligence (CTI)TheoryPIR, source and sharing decision
13:45–15:00Vulnerability prioritisation and MISP (I)Practical P3Priority queue
15:15–16:30CTI / MISP decision package (II)Practical P4Controlled event draft
16:30–16:55Review of resultsReflectionConclusion: maturity, CTI, action
17:00–19:00Independent workID-0390-day improvement plan
Breaks: 09:45–10:00, 12:00–13:00 (lunch) and 15:00–15:15. Sessions run online.

Learning outcomes

By the end of the day, participants can

  1. D3.1Separate a maturity claim from the evidence that supports it, and name the evidence's limit.
  2. D3.2Build an O/P/T/P (organisation, people, tools, processes) maturity view.
  3. D3.3Prioritise 90 days of improvement work by risk, value, dependencies and acceptance evidence.
  4. D3.4Write a priority intelligence requirement (PIR) tied to a specific decision and deadline.
  5. D3.5Assess source reliability, information confidence, IOC validity and false-positive risk.
  6. D3.6Prioritise vulnerabilities by applicability, CVSS, EPSS, known exploitation, exposure and asset criticality.
  7. D3.7Prepare a MISP event draft with TLP, distribution, to_ids, validity and publishing decisions.
  8. D3.8Deliver a traceable conclusion: fact, decision, owner, deadline, closure evidence.

Practice

Practical assignments

Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.

  1. P1

    O/P/T/P maturity map

    Rate 16 maturity claims on organisation, people, tools and process evidence, naming the limit of each piece of evidence.
    Duration:
    60 min
    Deliverable:
    ohtp_brandos_zemelapis.md
  2. P2

    90-day improvement queue

    Five work items with owners, dependencies and acceptance evidence.
    Duration:
    60 min
    Deliverable:
    brandos_gerinimo_planas.csv
  3. P3

    Vulnerability prioritisation

    Applicability plus at least six risk signals: CVSS, EPSS, known exploitation (KEV), exposure, asset criticality and compensating controls.
    Duration:
    75 min
    Deliverable:
    pazeidziamumu_prioritetai.csv
  4. P4

    CTI and MISP decision package

    PIR, source reliability, IOC validity, TLP, distribution and to_ids decisions. The training event is never published or synchronised.
    Duration:
    75 min
    Deliverable:
    MISP event draft (JSON)

Extra labs

For deeper practice

The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.

  • LAB 5D3-BALTNET-CTI-002

    IOC life cycle and testing exceptions

    Update IOC decisions after a partner withdraws an indicator, and check that a narrow testing exception does not suppress other important signals.

  • LAB 6D3-BALTNET-FIX-003

    Remediation validation and deadline control

    Keep patch deployment, temporary control, non-applicability and confirmed closure apart; calculate delay and the re-verification deadline.

Carry on in your environment

Related tools

  • SIEM.LT

    siem.lt

    Local-first threat intelligence workstation

    Explore MISP indicators, their geography and STIX 2.1 IOC export on SIEM.LT: locally, without sending data anywhere.

    • MISP IOC and IP geography
    • OSINT / RSS radar in Lithuanian
    • IOC de-duplication and STIX 2.1 export
    • Docker deployment in minutes

Previous day

Day 2: Security policy and SOC technical architecture

Day 2

Next day

Day 4: Incident investigation, threat hunting, playbooks and SOAR

Day 4