This supplement makes the current public-site concepts explicit in the book rather than leaving them implied. It follows the substantive pages listed in the utiom.de sitemap in August 2026.
The six problems UTIOM solves#
| Failure pattern | Operational consequence | UTIOM response |
|---|
| No defined purpose | Teams optimise for different outcomes because success is undefined. | Vision is the first operational control: purpose, ownership, protection scope and measures are defined before capability. |
| Fragmented silos | Intelligence, hunting, detection, monitoring and response lose context at hand-offs. | Treat them as expressions of one incident-response discipline at different distances from impact. |
| Alert fatigue | Analyst attention follows volume rather than business risk. | Prioritise detections by crown jewel and threat profile; retire rules without a defensible trace. |
| Tool-driven engineering | Vendor defaults create large libraries unrelated to relevant threats or critical assets. | Require traceability from rule to behaviour, threat model, crown jewel and business consequence. |
| No defensible spend | Budget discussions become renewals and headcount rather than risk reduction. | Map investment and metrics to named risk priorities and business consequences. |
| Compliant on paper, exposed in reality | Documented controls pass audit without proving effectiveness against relevant adversaries. | Operationalise NIST CSF, ISO 27001 and DORA through the lifecycle and validate behaviour in practice. |
The seven SOC operating-model components#
| Component | Required design decision |
|---|
| Vision | Why the SOC exists, what it protects, how success is measured and who owns the outcome. |
| Strategy | Which adversaries are realistic and what capability is built, in what order, with owners and dates. |
| Asset prioritisation | Critical services, data and identities, with business owners, threat models and attack paths. |
| Visibility engineering | Required telemetry, quality, attack-path coverage and formally accepted blind spots. |
| Detection engineering | How analytics are built, tested, versioned, traced and retired. |
| Response | Critical-asset playbooks, containment authority, escalation thresholds and decision gates. |
| Continuous improvement | How findings become engineering changes with owners, dates and refreshed models. |
Internal, outsourced and hybrid structures#
| Structure | Operating-model requirement |
|---|
| Internal | Define on-call coverage, specialist depth, out-of-hours escalation and knowledge continuity. |
| Outsourced | Retain ownership of vision, strategy and crown jewels; define provider boundaries and containment authority. |
| Hybrid | Assign an explicit owner to tuning, escalation, production containment and detection scope at every boundary. |
Assessment instruments and current framework family#
| Item | Public-site state at Book edition v1.2 |
|---|
| UTIOM | Framework v1.3 at the time this edition was published; seven lifecycle phases, three pillars and four assessment instruments. Framework Book v1.2 is published online and as PDF. This consolidated book is v1.2. |
| Maturity Assessment | 50 gated criteria across six levels. |
| Capability Assessment | 105 indicators across ten lifecycle domains, scored 0-5. |
| Metrics Calculator | 70 metrics with explicit formulas, separating leading and lagging indicators. |
| Improvement Roadmap | Combines completed assessments into a sequenced ninety-day plan. |
| Assessment privacy | Browser-only operation: no backend, database, analytics or signup; clearing site data removes results. |
| TID-CMM | v1.5; eight domains, 58 sub-capabilities and ATT&CK v19.2. |
| TIR-CMM | v1.0; 58 sub-capabilities and the current published response-capability model. |
Live-site page coverage#
| utiom.de page | Book coverage |
|---|
| What is UTIOM? | Introduction; Chapters 1-3 and 22 |
| What problem does UTIOM solve? | Appendix D: six failure patterns |
| Standards alignment | Chapters 4, 12-14 and corrected mapping table |
| SOC operating model | Chapters 18-19 and Appendix D: seven components and delivery structures |
| MITRE ATT&CK in the SOC | Appendix A and Chapters 2, 7-8 |
| Philosophy | Chapter 21 and Response Horizon |
| UTIOM in one minute | Lifecycle, framework family and assessment-instrument sections |
| Traditional SOC vs UTIOM | Chapter 19 |
| NIS2 and DORA | Chapter 20 |
| Changelog and About | Release history, framework family, author and licence sections |
| Assessment tools | Appendices B and D; maturity, capability, metrics and roadmap |
Cite this chapter: Adineh, R. (2026). Appendix D - Current utiom.de Alignment Supplement. UTIOM Framework
Book, edition 1.2. utiom.de/book/appendix-d-alignment/
← Back to book contents