← Book contents
APPENDIX D · CURRENT UTIOM.DE ALIGNMENT SUPPLEMENT Book · edition v1.2

Appendix D - Current utiom.de Alignment Supplement

This supplement makes the current public-site concepts explicit in the book rather than leaving them implied. It follows the substantive pages listed in the utiom.de sitemap in August 2026.

The six problems UTIOM solves#

Failure patternOperational consequenceUTIOM response
No defined purposeTeams optimise for different outcomes because success is undefined.Vision is the first operational control: purpose, ownership, protection scope and measures are defined before capability.
Fragmented silosIntelligence, hunting, detection, monitoring and response lose context at hand-offs.Treat them as expressions of one incident-response discipline at different distances from impact.
Alert fatigueAnalyst attention follows volume rather than business risk.Prioritise detections by crown jewel and threat profile; retire rules without a defensible trace.
Tool-driven engineeringVendor defaults create large libraries unrelated to relevant threats or critical assets.Require traceability from rule to behaviour, threat model, crown jewel and business consequence.
No defensible spendBudget discussions become renewals and headcount rather than risk reduction.Map investment and metrics to named risk priorities and business consequences.
Compliant on paper, exposed in realityDocumented controls pass audit without proving effectiveness against relevant adversaries.Operationalise NIST CSF, ISO 27001 and DORA through the lifecycle and validate behaviour in practice.

The seven SOC operating-model components#

ComponentRequired design decision
VisionWhy the SOC exists, what it protects, how success is measured and who owns the outcome.
StrategyWhich adversaries are realistic and what capability is built, in what order, with owners and dates.
Asset prioritisationCritical services, data and identities, with business owners, threat models and attack paths.
Visibility engineeringRequired telemetry, quality, attack-path coverage and formally accepted blind spots.
Detection engineeringHow analytics are built, tested, versioned, traced and retired.
ResponseCritical-asset playbooks, containment authority, escalation thresholds and decision gates.
Continuous improvementHow findings become engineering changes with owners, dates and refreshed models.

Internal, outsourced and hybrid structures#

StructureOperating-model requirement
InternalDefine on-call coverage, specialist depth, out-of-hours escalation and knowledge continuity.
OutsourcedRetain ownership of vision, strategy and crown jewels; define provider boundaries and containment authority.
HybridAssign an explicit owner to tuning, escalation, production containment and detection scope at every boundary.

Assessment instruments and current framework family#

ItemPublic-site state at Book edition v1.2
UTIOMFramework v1.3 at the time this edition was published; seven lifecycle phases, three pillars and four assessment instruments. Framework Book v1.2 is published online and as PDF. This consolidated book is v1.2.
Maturity Assessment50 gated criteria across six levels.
Capability Assessment105 indicators across ten lifecycle domains, scored 0-5.
Metrics Calculator70 metrics with explicit formulas, separating leading and lagging indicators.
Improvement RoadmapCombines completed assessments into a sequenced ninety-day plan.
Assessment privacyBrowser-only operation: no backend, database, analytics or signup; clearing site data removes results.
TID-CMMv1.5; eight domains, 58 sub-capabilities and ATT&CK v19.2.
TIR-CMMv1.0; 58 sub-capabilities and the current published response-capability model.

Live-site page coverage#

utiom.de pageBook coverage
What is UTIOM?Introduction; Chapters 1-3 and 22
What problem does UTIOM solve?Appendix D: six failure patterns
Standards alignmentChapters 4, 12-14 and corrected mapping table
SOC operating modelChapters 18-19 and Appendix D: seven components and delivery structures
MITRE ATT&CK in the SOCAppendix A and Chapters 2, 7-8
PhilosophyChapter 21 and Response Horizon
UTIOM in one minuteLifecycle, framework family and assessment-instrument sections
Traditional SOC vs UTIOMChapter 19
NIS2 and DORAChapter 20
Changelog and AboutRelease history, framework family, author and licence sections
Assessment toolsAppendices B and D; maturity, capability, metrics and roadmap
Cite this chapter: Adineh, R. (2026). Appendix D - Current utiom.de Alignment Supplement. UTIOM Framework Book, edition 1.2. utiom.de/book/appendix-d-alignment/
← Back to book contents

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →