Day 3
SOC maturity, threat intelligence (CTI) and vulnerability management
Participants can assess SOC maturity on evidence and turn CTI into a prioritised, controlled vulnerability and MISP decision.
- Training case
- D3-BALTNET-MAT-001
- Programme topics
- 5
- Assignments
- P1 · P2 · P3 · P4 · ID-03
Where this day sits in the chain
Sequence: policy, architecture, signal, decision. The morning tests whether SOC capabilities are proven by organisation, people, tools and process artefacts; the afternoon applies them to CTI and vulnerabilities.
Rule of the day
The teaching O/P/T/P evidence scale is not an official SIM3 assessment, score or certification result.
Schedule
How the day runs
| Time | Topic | Format | Output |
|---|---|---|---|
| 09:00–09:45 | SOC maturity. Structure of the SIM3 model | Theory | Maturity claim and evidence gate |
| 10:00–11:00 | O/P/T/P evidence map | Practical P1 | Dimension view |
| 11:00–12:00 | 90-day maturity improvement queue | Practical P2 | 5 work items with acceptance criteria |
| 13:00–13:45 | Managing threat intelligence (CTI) | Theory | PIR, source and sharing decision |
| 13:45–15:00 | Vulnerability prioritisation and MISP (I) | Practical P3 | Priority queue |
| 15:15–16:30 | CTI / MISP decision package (II) | Practical P4 | Controlled event draft |
| 16:30–16:55 | Review of results | Reflection | Conclusion: maturity, CTI, action |
| 17:00–19:00 | Independent work | ID-03 | 90-day improvement plan |
Learning outcomes
By the end of the day, participants can
- D3.1Separate a maturity claim from the evidence that supports it, and name the evidence's limit.
- D3.2Build an O/P/T/P (organisation, people, tools, processes) maturity view.
- D3.3Prioritise 90 days of improvement work by risk, value, dependencies and acceptance evidence.
- D3.4Write a priority intelligence requirement (PIR) tied to a specific decision and deadline.
- D3.5Assess source reliability, information confidence, IOC validity and false-positive risk.
- D3.6Prioritise vulnerabilities by applicability, CVSS, EPSS, known exploitation, exposure and asset criticality.
- D3.7Prepare a MISP event draft with TLP, distribution, to_ids, validity and publishing decisions.
- D3.8Deliver a traceable conclusion: fact, decision, owner, deadline, closure evidence.
Practice
Practical assignments
Every stage has a duration, a deliverable artefact and an acceptance criterion. Work is done on template copies; original evidence is never modified.
- P1
O/P/T/P maturity map
Rate 16 maturity claims on organisation, people, tools and process evidence, naming the limit of each piece of evidence.- Duration:
- 60 min
- Deliverable:
- ohtp_brandos_zemelapis.md
- P2
90-day improvement queue
Five work items with owners, dependencies and acceptance evidence.- Duration:
- 60 min
- Deliverable:
- brandos_gerinimo_planas.csv
- P3
Vulnerability prioritisation
Applicability plus at least six risk signals: CVSS, EPSS, known exploitation (KEV), exposure, asset criticality and compensating controls.- Duration:
- 75 min
- Deliverable:
- pazeidziamumu_prioritetai.csv
- P4
CTI and MISP decision package
PIR, source reliability, IOC validity, TLP, distribution and to_ids decisions. The training event is never published or synchronised.- Duration:
- 75 min
- Deliverable:
- MISP event draft (JSON)
Extra labs
For deeper practice
The extra 90-minute or two-academic-hour labs are not automatically added to a full day; the instructor sets their schedule and submission time.
LAB 5D3-BALTNET-CTI-002
IOC life cycle and testing exceptions
Update IOC decisions after a partner withdraws an indicator, and check that a narrow testing exception does not suppress other important signals.
LAB 6D3-BALTNET-FIX-003
Remediation validation and deadline control
Keep patch deployment, temporary control, non-applicability and confirmed closure apart; calculate delay and the re-verification deadline.
Carry on in your environment
Related tools
SIEM.LT
siem.ltLocal-first threat intelligence workstation
Explore MISP indicators, their geography and STIX 2.1 IOC export on SIEM.LT: locally, without sending data anywhere.
- MISP IOC and IP geography
- OSINT / RSS radar in Lithuanian
- IOC de-duplication and STIX 2.1 export
- Docker deployment in minutes