← Book contents
03 · CAPABILITY LAYER MODEL Book · edition v1.2

Capability Layer Model

UTIOM operates across three mutually reinforcing planes. Each layer represents both a technical depth and an organizational perspective.

Layer/PillarFocusMain GoalPrimary ActivitiesKey Frameworks
Foundational (Leadership & Governance)
  • Vision,
  • Strategy,Missions,
  • Operations Model,
  • Governance, Architecture,
  • Know The related Threat
  • Know yourself
Strategic planning,Role definition,Threat Profiling,Risk alignmentNIST CSF (Identify), ISO 27001, TOGAF Standard, 10th Edition
Operational & Analysis
  • Telemetry,
  • Visibility
  • Detection,
  • Analysis,
  • Response,
  • Feedback & Optimization
Analysis & ResponseThreat modelling,Log onboarding,Analysis,SIEM/EDR operations, playbook executionATT&CK, ISO/IEC 27035-1:2023, STRATA Resilience
Engineering & Enablement
  • Protection,
  • Visibility,
  • Detection,Automation & QA,
  • Feedback & Optimization
  • Build Detection Rules
  • Build Response Plan
Detection-as-Code, CI/CD,purple team validation,Kaizen loops,hunting,benchmarkingGitOps, DeTT&CT, TID-CMM Detection QA,SOC-CMM, PDCA, STRATA Adaptability

“Layers aren’t hierarchies they are symbiotic perspectives.”

Cite this chapter: Adineh, R. (2026). Capability Layer Model. UTIOM Framework Book, edition 1.2. utiom.de/book/capability-layer/
← Back to book contents

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →