Terms as they are used in this book. Where a term has a broader industry meaning, the UTIOM usage is given first and the distinction noted.
24.1 UTIOM lifecycle terms#
Vision. The first operational control. A documented statement of why the security operation exists, what it protects, how success is measured and who owns the outcome. Not a mission statement; an active constraint on everything built downstream.
Strategy. The security operations strategy, distinct from the business strategy. Threat profiling, risk prioritisation and a capability roadmap with owners and dates. Business strategy is an input to it, not a synonym for it.
Crown jewel. An asset, service, dataset or identity whose compromise would cause disproportionate damage relative to everything else. Determined by business consequence, not technical sensitivity. The anchor for all downstream prioritisation.
Crown jewel registry. The documented set of crown jewels with named business owners, business impact mapping, threat models, attack paths and dependency matrices.
Threat visibility. The engineering discipline of deciding what telemetry must exist to observe modelled attack paths against crown jewels, then building it. Distinct from log collection, which is volume without direction.
Visibility gap report. A documented statement of what cannot currently be seen, formally accepted by leadership. Turns blind spots from accidents into recorded architectural decisions.
Threat detection. The engineering of analytics that recognise adversary behaviour within available telemetry. In UTIOM, every rule must trace to a threat model, a technique and a crown jewel.
Response. Pre-engineered containment, eradication and recovery, with authority and escalation thresholds defined before the incident rather than during it.
Continuous improvement. The feedback loop that converts incidents, exercises and near-misses into engineering change across telemetry, detection, playbooks and strategy.
24.2 UTIOM concepts#
Threat-informed. Designed around documented adversary behaviour rather than generic indicators, vendor content or assumption. The opposite of coverage-driven.
Detection-as-code. Treating detection content as software: version controlled, peer reviewed, tested before production, deployed through a pipeline and systematically retired.
Trace completion rate. The proportion of live detection rules that can be walked from rule to threat model to technique to crown jewel to business consequence. A rule that cannot complete the chain is waste.
The Response Horizon. The observation that the leverage of a decision falls and its cost rises as the moment of impact approaches. The crossing point separates designing from reacting.
The V-Model. The pairing of each design activity with the activity that validates it. Purple team proves attack paths, detection QA proves telemetry, response outcomes prove the threat profile.
Systematic abandonment. Drucker's principle applied to detection: every improvement cycle must retire rules that no longer protect a crown jewel. A detection library is perishable inventory, not an asset.
Meta-detection. A detection that monitors the health of the detection and telemetry pipeline itself, so that silent failures surface before an incident does.
Alert fatigue. Treated in UTIOM as a system design failure rather than a staffing problem. If analysts are overwhelmed, fidelity is too low or operational cost per rule is too high.
Operational cost per rule. Analyst minutes consumed per detection rule per period. The metric that exposes alert fatigue as an engineering problem with an engineering fix.
Quiet operations. The mature state in which noise decreases because intent is clear, response accelerates because paths are predefined, and learning compounds. Well-designed security operations are deliberate, predictable and boring.
24.3 The framework family#
UTIOM. Unified Threat-Informed Operations Model. The operating model that connects leadership intent, engineering discipline and operational execution into one lifecycle.
TID-CMM. Threat-Informed Detection Capability Maturity Model. Measures the engineering pillar in depth: whether detection is genuinely driven by adversary behaviour, whether the telemetry exists to see it, and whether any of it has been proven. Published at tid-cmm.com.
TIR-CMM. Threat-Informed Response Capability Maturity Model. Measures the operations pillar: whether containment authority exists before the incident and whether you can act inside the adversary breakout window. Published at tir-cmm.com.
RSMM. Realistic SIEM Maturity Model. Five levels from Blame Collector to Outcome-Driven SIEM, measuring the platform that detection runs on.
STRATA. Strategy, Talent, Resilience, Automation, Telemetry and Adaptability. A refinement of the People, Process and Technology triad, supplying the organisational dimension of UTIOM.
Containment Margin. A TIR-CMM metric: adversary breakout time minus the sum of detect, decide and contain. Negative margin means the adversary reaches the objective first.
24.4 Metrics#
MTTD. Mean Time to Detect. In UTIOM, measured against top-priority TTPs rather than as an aggregate, because an average hides the cases that matter.
MTTC. Mean Time to Contain. From confirmed incident to contained adversary activity.
MTTR. Mean Time to Recover. From containment to validated return to service.
Detection validation rate. The proportion of live detection rules that have actually been tested by emulation or simulation. Untested detection is an assumption.
Response readiness validation. The proportion of playbooks exercised within the review period.
Leading indicator. A measure of what will happen: coverage per threat modelled, validation rate, playbook coverage. What a programme should steer by.
Lagging indicator. A measure of what already happened: MTTD, MTTC, incidents handled. Useful for reporting, arriving too late to steer by.
Breakout time. The interval between an adversary's initial access and their first lateral movement. The clock against which response tempo should be measured.
24.5 Standards and external frameworks#
NIST CSF 2.0. The Cybersecurity Framework, revised in 2024 to add GOVERN as a first-class function alongside Identify, Protect, Detect, Respond and Recover. Defines outcomes; UTIOM defines the operating model that delivers them.
ISO/IEC 27001:2022/Amd 1:2024. Information security management standard. Annex A was restructured into 93 controls across four themes: Organizational A.5, People A.6, Physical A.7 and Technological A.8. The 2013 fourteen-domain numbering is retired.
SOC-CMM. Security Operations Centre Capability Maturity Model by Rob van Os. Measures maturity across business, people, process, technology and services. Measures how mature a SOC is; UTIOM provides the mechanism to become mature.
MITRE ATT&CK. A curated knowledge base of adversary tactics and techniques observed in real intrusions. In UTIOM, a shared vocabulary scoped to crown jewels rather than a coverage checklist.
MITRE DeTT&CT. An open methodology for scoring detection coverage against ATT&CK using data source quality and visibility. Where ATT&CK describes adversary behaviour, DeTT&CT measures whether you could see it.
MITRE Engage. A framework for adversary engagement, deception and denial operations. Used in UTIOM to place deception along modelled crown jewel attack paths.
Sigma. A generic, platform-agnostic signature format for detection rules, translatable to most SIEM query languages. Supports the portability principle in detection engineering.
NIS2. Directive (EU) 2022/2555. Cybersecurity obligations for essential and important entities across most critical sectors. Article 21 requires risk management measures including assessment of their effectiveness; Article 20 makes management bodies accountable; Article 23 sets 24-hour early warning, 72-hour incident notification and a final report not later than one month after the incident notification.
DORA. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. Five pillars covering ICT risk management, incident reporting, digital operational resilience testing, with advanced threat-led penetration testing (TLPT) under Article 26 for identified financial entities, third-party risk and information sharing.
TIBER-EU 2025. The European framework for threat intelligence-based ethical red teaming, updated by the Eurosystem in 2025 to align with DORA’s TLPT regulatory technical standards; it provides operational guidance for TLPT where used consistently with DORA and the applicable RTS.
GDPR Article 33. Where notification is required, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the personal data breach, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
24.6 Method and engineering terms#
OODA loop. Observe, Orient, Decide, Act. Boyd's decision cycle, applied in UTIOM at incident tempo between engineering and operations.
PDCA. Plan, Do, Check, Act. Deming's improvement cycle, the operational structure behind UTIOM's continuous improvement phase.
Kaizen. Japanese term for continuous improvement through small, consistent changes rather than periodic overhauls.
DRY principle. Don't Repeat Yourself. A software principle applied to detection: shared logic, exclusion lists and normalisation belong in shared configuration objects, not duplicated across rules.
Common Information Model. A normalised schema that detection logic sits on top of, so that content survives a change of platform or data source.
Purple team. A collaborative exercise where offensive emulation and defensive engineering work together, with the objective of improving detection rather than proving compromise.
Adversary emulation. Executing the specific techniques of a profiled adversary against your own environment to validate whether telemetry, detection and analyst decisions perform as designed.
Living off the land. Adversary tradecraft that uses legitimate credentials, tools and platform APIs rather than deploying detectable malware.
Adineh, R. (2026). Glossary. UTIOM Framework
Book, edition 1.2. utiom.de/book/glossary/