UTIOM operates across three mutually reinforcing planes. Each layer represents both a technical depth and an organizational perspective.
| Layer/Pillar | Focus | Main Goal | Primary Activities | Key Frameworks |
|---|---|---|---|---|
| Foundational (Leadership & Governance) |
|
| Strategic planning,Role definition,Threat Profiling,Risk alignment | NIST CSF (Identify), ISO 27001, TOGAF Standard, 10th Edition |
| Operational & Analysis |
| Analysis & Response | Threat modelling,Log onboarding,Analysis,SIEM/EDR operations, playbook execution | ATT&CK, ISO/IEC 27035-1:2023, STRATA Resilience |
| Engineering & Enablement |
|
| Detection-as-Code, CI/CD,purple team validation,Kaizen loops,hunting,benchmarking | GitOps, DeTT&CT, TID-CMM Detection QA,SOC-CMM, PDCA, STRATA Adaptability |
“Layers aren’t hierarchies they are symbiotic perspectives.”
Cite this chapter:
← Back to book contents
Adineh, R. (2026). Capability Layer Model. UTIOM Framework
Book, edition 1.2. utiom.de/book/capability-layer/