← Book contents
02 · THE UNIFIED LIFECYCLE Book · edition v1.2

The Unified Lifecycle

Security operations become effective only when they are cyclical, not linear. UTIOM defines seven connected domains that together describe the full life of defence and Threat Informed Incident Response.

Each domain is:

A decision space

A feedback loop

A measurable capability24

First missing point in many organization is not having the right vision for their Cyber Security Operation or their Risk management. Defining the Vision must lead to define the right strategy. And the strategy should be aligned with the business/company Crown Jewels25, and knowing the business critical assets (Crown Jewels)26,27 will provide the threat visibility through threat modelling, and with having threat visibility we can continuously develop meaningful, aligned threat detection rules that actually matters, not random detection from different source that has nothing to do about our real world cyber risk. While we know what we are looking to detect, then we can develop our response plan based on that and at the final phase of this process we will have a Continuous Improvement to revise and use the lessons learned.

2.1 Vision Defining Purpose#

While we considers Security Operations as a engineered system we must define how this system would be successful. All engineered systems begin with purpose. In SecOps, purpose answers why we defend and what success means. Without it, SOCs default to counting alerts instead of outcomes.

Core Activities

Define the business intent of the SOC.

Align Security Operation Vision with Business CJs.

Establish governance and accountability.

Identify success metrics (e.g., availability, confidentiality, safety, continuity).

Outputs

Long Term and short Term Security Operation Vision.

Vision statement and policy charter.

Stakeholder map and alignment workshop results.

Baseline metrics (e.g., detection confidence, time-to-resolution).

Referenced Frameworks

TOGAF Standard, 10th Edition Vision

ISO/IEC 27001:2022/Amd 1:2024 Clauses 5.1–5.3

NIST CSF 2.0 (GV.OC, GV.RR).

“Vision is the compass; tools are merely instruments.”

2.2 Strategy Translating Vision into Design#

Vision without strategy is intention without motion. UTIOM views strategy as a capability-building system rather than a document. Every decision must connect a risk to a measurable improvement.

Core Activities

Threat and risk prioritization. (Threat Profiling28 as a core function).

Resource planning and capability road-mapping.

Defining measurable KPIs and KRIs tied to crown jewels.

Outputs

SOC Master Plan and quarterly objectives.

Threat profile and prioritization model.

Capability increment schedule.

Stakeholder scorecards.

Referenced Frameworks

COBIT 2019 Governance.

ISO 27001 6.1–6.2, 8.2–8.3

STRATA29 Strategy.

TID-CMM30 Strategic Alignment.

2.3 Crown Jewels Focusing on What Matters#

No organization can protect everything equally. Crown Jewel Analysis (CJA) identifies critical assets, processes, and data whose compromise would create disproportionate damage.

Core Activities

Asset inventory and classification.

Mapping Threat profile with CJ.

Business impact mapping.

Threat modelling for identified Crown Jewel (CJ).

Critical Asset mapping to the high risk Threats.

Outputs

CJ registry with owners.

Threat profile mapped with CJ and defined high priority TTPs.

Attack-path diagrams for CJs.

Checklist of Protection, Detection, Visibility and Response capability readiness for CJs based on top priority TTPs.

Mapped related MITRE ATT&CK TTP with CJs.

Dependency matrix linking CJ to data sources.

Threat Detection rules logic.

Referenced Frameworks

MITRE Engage

MITRE Engage

ISO 27001 Clause 8

TID-CMM Threat Prioritization.

“You can’t build meaningful visibility without knowing what deserves to be seen.”

2.4 Threat Visibility Engineering Telemetry#

Visibility is the bloodstream of detection. UTIOM designs visibility from the CJs outward, ensuring telemetry covers what matters first.

Core Activities

Map ATT&CK tactics to data sources.31

Map Threat Modelling to data sources.32

Define logging, retention, and access standards.

Implement data quality and normalization checks.

Implementation of Deception variation aligned with CJ.33

Outputs

Visibility Blueprint and Gap Report.

Mapped Threat models to required data sources.

Telemetry onboarding roadmap. (Defined required data pipeline for CJs high priority Threats)

Threat Activity visibility.

Metrics: % CJ coverage per Threat, log quality index.

Referenced Frameworks

NIST SP 800-137

MITRE DeTT&CT

CIS Critical Security Controls v8.1

STRATA Telemetry

2.5 Threat Detection Engineering Awareness#

You can’t detect what you can’t observe, but observation without interpretation is noise. Detection must be engineered, version-controlled, and threat-informed.

Core Activities

Develop Detection rules referenced by Thread modelling in previous steps.

Develop rules mapped to ATT&CK TTPs.

Apply Detection-as-Code practices (Git, CI/CD, testing).

Measure fidelity, coverage, and operational cost.

Automate QA and regression testing.

Red/Purple Teaming planning for Detection Verifications.

Outputs

Detection Repository with traceability.

QA Reports with coverage metrics.

% of implemented and tuned detection rules per Threat Modelled

% of implemented deception in each operational zone

False positive and false negative monitoring.

Mean Time to Detect (MTTD) evaluation based on top TTPs.

Referenced Frameworks

MITRE ATT&CK Enterprise v19.2

DeTT&CT

Sigma

STRATA Automation.

TID-CMM Detection QA.

“Detection built from behaviours lasts longer than detection built from indicators.”

2.6 Response Executing with Precision#

Response is the natural continuation of detection. UTIOM positions incident handling as an engineered workflow, not an improvisation.

Core Activities

Developing Response plan, Playbooks aligned with defined Threats.( prioritized threats and crown jewels)

Automate containment through SOAR.(In case of absence of SOAR, consider containment plan without SOAR)

Define escalation paths34 and CJ-specific playbooks.

Track MTTR, MTTC and containment SLA.

Outputs

Playbook Library and Response Matrix.

Incident Records with contextual tags.

Lessons Learned Repository.

Referenced Frameworks

NIST SP 800-61

ISO/IEC 27035-1:2023

FIRST CSIRT

STRATA Resilience

TID-CMM Process Execution.

2.7 Continuous Improvement Learning Systems#

No design remains optimal forever. Continuous Improvement is the intelligence loop that converts experience into new strategy.

Core Activities

Post-incident reviews and Kaizen sessions.

Red/Purple team validation of detection coverage.

Update threat models and roadmaps.

Conduct periodic benchmarking and maturity assessments.

Outputs

Updated Vision and Strategy documents.

Proper aligned input for protection, Detection and Response.

Action plans with owners and timelines.

Maturity scorecards (UTIOM / TID-CMM / SOC-CMM).

Referenced Frameworks

Deming PDCA

Kaizen

SOC-CMM

STRATA Adaptability.

TID-CMM Feedback.

“Learning is the final deliverable of every incident.”

Notes

  1. Mainly qualitatvie, some quantitavie ↩
  2. Each role in a security Operation must be aware of their operational vission and mission, and this vision and missison are defined based on business operational critical assets. ↩
  3. It is super crucial for defence team to know the CJs, check the endnotes for more details. ↩
  4. from Sun Tzu’s The Art of War:"If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle." Key Takeaways from the TextSun Tzu doesn't just mention "strengths and weaknesses" in passing; he dedicates an entire chapter (Chapter 6: Weak Points and Strong) to how you should apply that knowledge.Self-Knowledge: This is about "knowing yourself"—understanding your own resources, morale, and limitations.In cyber security, applying Sun Tzu via a SWOT lens means moving from reactive "firefighting" to proactive defense. Knowing yourself involves rigorous asset discovery and vulnerability management—identifying your "Weaknesses" (unpatched software) and "Strengths" (i.g.,robust encryption). Knowing the enemy means utilizing Threat Intelligence to understand the "Threats" (specific hacker groups/TTPs) and "Opportunities" (gaps in the attacker's own infrastructure). By aligning these, a CISO ensures that security controls aren't just a wall, but a strategic maneuver that makes the cost of an attack higher than the potential reward. ↩
  5. Threat profiling is a proactive cybersecurity process that involves identifying, analyzing, and documenting the specific, relevant adversaries and threats targeting an organization. (https://www.linkedin.com/pulse/cyber-threat-profiling-understanding-different-actors-reza-adineh/?trackingId=NkWFdbDGToWs8KNuWh51Rw%3D%3D), (https://www.linkedin.com/pulse/crowdstrike-mandiant-red-canary-reza-adineh-qrcgf/) ↩
  6. https://www.linkedin.com/pulse/from-ppt-strata-reza-adineh-ysqhf/?trackingId=%2FkSuK87cQRGkLDSGcxcCsw%3D%3D ↩
  7. Threat Informed Detection Capability Maturity Model ↩
  8. Means those TTPS which are mapped to CJs. ↩
  9. We can leverage Threat-Informed Detection Capability Maturity Model in this activity. ↩
  10. Deploy deception selectively where it increases adversary cost. ↩
  11. And decision gates. ↩
Cite this chapter: Adineh, R. (2026). The Unified Lifecycle. UTIOM Framework Book, edition 1.2. utiom.de/book/unified-lifecycle/
← Back to book contents

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →