← UTIOM
UTIOM Framework Bookedition v1.2

The UTIOM Framework Book

Unified Threat-Informed Operations Model. Why security operations should be designed as one system rather than assembled from parts: the seven-phase lifecycle, the three pillars, the models that measure them, and how it all maps onto NIST CSF, SOC-CMM, NIS2 and DORA. Free to read in full.

By Reza Adineh · Framework methodology v1.4 · Book edition v1.2 · Creative Commons BY-SA 4.0

Start reading →

Download PDF v1.2 ↓

Contents

Front matter
·How to read this book?Who the book is for, how to use it, and what it deliberately is not.Read →·PrefaceSecurity operations have reached a defining moment. Across industries, SOCs overflow with alerts and dashboards, yet the people behind them struggle to…Read →·Why UTIOM Exists?Security operations are at a crossroads. The traditional model focused on isolated monitoring and reactive incident response, no longer meets the demands…Read →·Terminology and ScopeSecurity Operations (SecOps): The overall organizational capability to detect, respond, and continuously reduce cyber risk in operational reality.Read →
Sections
01The FoundationsSecurity Operation is like a product and this product need a product designer and a product owner. UTIOM assumes clear ownership of…Read →02The Unified LifecycleSecurity operations become effective only when they are cyclical, not linear. UTIOM defines seven connected domains that together describe the full life…Read →03Capability Layer ModelUTIOM operates across three mutually reinforcing planes. Each layer represents both a technical depth and an organizational perspective.Read →04Standards and Framework IntegrationUTIOM deliberately aligns to recognised standards to support traceability, standards alignment and operational evidence across the security operations lifecycle of a security…Read →05Threat-Informed Maturity ModelUTIOM’s maturity ladder measures integration, threat realism, and engineering discipline.Read →06Implementation BlueprintA five-phase rollout from vision and governance through visibility, detection engineering, response and continuous improvement.Read →07Engineering ExtensionsDetection-as-Code pipelines, SOAR orchestration, deception fabric and the engineering practices that extend the lifecycle.Read →08Metrics and Performance IndicatorsSeventy metrics with explicit formulas across visibility, detection, response and improvement.Read →09Industry Use Cases SamplesReduce operational and systemic risk across critical payment services while maintaining availability and regulatory trust. (*Reduce Operation Risk of Payment services)Read →10Outcomes and BenefitsWhat a UTIOM operation produces: traceability from vision to execution, engineered detection, and metrics aligned to business risk.Read →11Community and GovernanceUTIOM is an open, living framework licensed under CC BY-SA, intended to evolve through transparent sharing and peer review.Read →12Alignment with NIST Cybersecurity Framework (NIST CSF)How UTIOM maps onto the six CSF 2.0 Functions as an operational execution layer, function by function.Read →13Alignment with SOC Capability Maturity Models (SOC-CMM)UTIOM is designed to accelerate SOC maturity progression by structuring operations around outcomes rather than tools or team silos.Read →14Alignment with the Digital Operational Resilience Act (DORA)UTIOM directly supports DORA’s objectives by embedding operational resilience into day-to-day security operations.Read →15ConclusionUTIOM is a unifying language for modern defence strategic in vision, engineering in method, and human in execution. It translates intent into…Read →16The Framework FamilyUTIOM is the operating model. Two capability maturity models measure its pillars in depth, and both rest on the same premise: everything…Read →17The Response HorizonAsk a SOC manager when incident response begins and most will say: when something is detected. That answer is the reason so…Read →18Design and Validation: the UTIOM V-ModelEvery design decision in UTIOM carries a matching activity that proves it. Drawn as a V, the left arm descends through design…Read →19Traditional SOC Operating Model Compared with UTIOMThe difference is not tooling. Both models can run the same platforms. The difference is what drives the work, what counts as…Read →
Why UTIOM is different
IIt Starts With Management, Not ToolsWhy UTIOM begins with management science: vision, strategy, decision tempo, prioritisation and continuous improvement before tooling.Read →IIDetection Is Engineering, Not ImprovisationHow UTIOM turns detection into an engineering discipline through requirements, telemetry, testing, traceability and evidence.Read →IIIResponse Is the Operating Mode, Not the EmergencyWhy UTIOM treats response as continuous operations through containment margin, pre-authorised decisions, rehearsal and learning.Read →
Sections
20UTIOM for NIS2 and DORAEuropean regulation has moved from asking whether controls exist to asking whether they work. NIS2 requires policies on assessing effectiveness. DORA requires…Read →21Philosophy and Core PrinciplesUTIOM is built on the belief that effective security operations are not the result of more tools, more alerts, or more activity,…Read →22A Note on What Strategy Means in UTIOMStrategy in UTIOM means the security operations strategy, not the business strategy. The two are distinct and must not be confused.Read →23Release HistoryVersion 1.2, August 2026. Standards mapping corrected to NIST CSF 2.0 and ISO/IEC 27001:2022 + Amd 1:2024. Framework family, Response Horizon, V-Model,…Read →24GlossaryTerms as they are used in UTIOM, defined precisely to avoid ambiguity across the lifecycle.Read →25Further Reading and SourcesThe works and standards this framework draws on, grouped by the part of the lifecycle they inform.Read →
About
·About the AuthorReza Adineh is a German-based cybersecurity architect and visionary with over 15 years of experience designing and leading Security Operations Centres across…Read →
Appendices
AAppendix A - Operational Use of MITRE ATT&CKATT&CK is a shared vocabulary, not an operating model and not a coverage target. UTIOM turns it into capability through five steps:Read →BAppendix B - UTIOM Measurement InstrumentsA framework that mandates measurement must provide instruments. The UTIOM assessment suite operationalises the model through four complementary instruments:Read →CAppendix C - Content Preservation and utiom.de CoverageThis final v1.2 uses the author's authoritative source edition as its master so that all footnotes, hyperlinks and the approved black cover…Read →DAppendix D - Current utiom.de Alignment SupplementThis supplement makes the current public-site concepts explicit in the book rather than leaving them implied. It follows the substantive pages listed…Read →EAppendix E - Archival Original Lifecycle DiagramThe main lifecycle diagram is presented in the harmonised dark-green publication theme. The unmodified original artwork from the v1.0/v1.1 manuscript is reproduced…Read →

Edition history

AuthorVersion & Date of releaseDescription
Reza AdinehPublic release · August 2025UTIOM published publicly for the first time: lifecycle, three pillars, seven laws and incident response as the operating mode of security operations.
V1.0 · February 2026First edition of the framework book: lifecycle, capability layer model, maturity model, implementation blueprint, metrics and worked examples.
V1.1 · August 2026Four assessment instruments published; validation and adversary emulation established as a first-class domain; automation and lifecycle metrics extended.
V1.2 · August 2026Book consolidation: corrected standards mapping; framework family, Response Horizon, V-Model, SOC comparison, NIS2/DORA, philosophy, current-site alignment and preservation audit; and the Why UTIOM Is Different three-part synthesis with supporting editorial figures.
Development · From 2022Four years of building and testing against real security-operations work before public release.
Origin · Circa 2018Core idea surfaced while the author was writing his first book: security operations should be designed as one system rather than assembled from disconnected parts.

Previous edition

Book v1.2 is available now as the complete online edition. A matching v1.2 PDF is available now as a downloadable PDF. The previous v1.1 PDF remains available below.

UTIOM Framework Book v1.1
The last edition released as a PDF, from August 2026. Download previous edition →

Editions

Book edition v1.2
This online edition. The complete text, figures and notes, readable and linkable section by section.
Framework v1.4
The site, instruments and tools move faster than the book. The framework is at v1.4 and this book edition is v1.2. Both are true at once.

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →