Security operations become effective only when they are cyclical, not linear. UTIOM defines seven connected domains that together describe the full life of defence and Threat Informed Incident Response.
Each domain is:
A decision space
A feedback loop
A measurable capability24
First missing point in many organization is not having the right vision for their Cyber Security Operation or their Risk management. Defining the Vision must lead to define the right strategy. And the strategy should be aligned with the business/company Crown Jewels25, and knowing the business critical assets (Crown Jewels)26,27 will provide the threat visibility through threat modelling, and with having threat visibility we can continuously develop meaningful, aligned threat detection rules that actually matters, not random detection from different source that has nothing to do about our real world cyber risk. While we know what we are looking to detect, then we can develop our response plan based on that and at the final phase of this process we will have a Continuous Improvement to revise and use the lessons learned.
2.1 Vision Defining Purpose#
While we considers Security Operations as a engineered system we must define how this system would be successful. All engineered systems begin with purpose. In SecOps, purpose answers why we defend and what success means. Without it, SOCs default to counting alerts instead of outcomes.
Core Activities
Define the business intent of the SOC.
Align Security Operation Vision with Business CJs.
Establish governance and accountability.
Identify success metrics (e.g., availability, confidentiality, safety, continuity).
Outputs
Long Term and short Term Security Operation Vision.
Vision statement and policy charter.
Stakeholder map and alignment workshop results.
Baseline metrics (e.g., detection confidence, time-to-resolution).
Referenced Frameworks
TOGAF Standard, 10th Edition Vision
ISO/IEC 27001:2022/Amd 1:2024 Clauses 5.1–5.3
NIST CSF 2.0 (GV.OC, GV.RR).
“Vision is the compass; tools are merely instruments.”
2.2 Strategy Translating Vision into Design#
Vision without strategy is intention without motion. UTIOM views strategy as a capability-building system rather than a document. Every decision must connect a risk to a measurable improvement.
Core Activities
Threat and risk prioritization. (Threat Profiling28 as a core function).
Resource planning and capability road-mapping.
Defining measurable KPIs and KRIs tied to crown jewels.
Outputs
SOC Master Plan and quarterly objectives.
Threat profile and prioritization model.
Capability increment schedule.
Stakeholder scorecards.
Referenced Frameworks
COBIT 2019 Governance.
ISO 27001 6.1–6.2, 8.2–8.3
STRATA29 Strategy.
TID-CMM30 Strategic Alignment.
2.3 Crown Jewels Focusing on What Matters#
No organization can protect everything equally. Crown Jewel Analysis (CJA) identifies critical assets, processes, and data whose compromise would create disproportionate damage.
Core Activities
Asset inventory and classification.
Mapping Threat profile with CJ.
Business impact mapping.
Threat modelling for identified Crown Jewel (CJ).
Critical Asset mapping to the high risk Threats.
Outputs
CJ registry with owners.
Threat profile mapped with CJ and defined high priority TTPs.
Attack-path diagrams for CJs.
Checklist of Protection, Detection, Visibility and Response capability readiness for CJs based on top priority TTPs.
Mapped related MITRE ATT&CK TTP with CJs.
Dependency matrix linking CJ to data sources.
Threat Detection rules logic.
Referenced Frameworks
MITRE Engage
MITRE Engage
ISO 27001 Clause 8
TID-CMM Threat Prioritization.
“You can’t build meaningful visibility without knowing what deserves to be seen.”
2.4 Threat Visibility Engineering Telemetry#
Visibility is the bloodstream of detection. UTIOM designs visibility from the CJs outward, ensuring telemetry covers what matters first.
Core Activities
Map ATT&CK tactics to data sources.31
Map Threat Modelling to data sources.32
Define logging, retention, and access standards.
Implement data quality and normalization checks.
Implementation of Deception variation aligned with CJ.33
Outputs
Visibility Blueprint and Gap Report.
Mapped Threat models to required data sources.
Telemetry onboarding roadmap. (Defined required data pipeline for CJs high priority Threats)
Threat Activity visibility.
Metrics: % CJ coverage per Threat, log quality index.
Referenced Frameworks
NIST SP 800-137
MITRE DeTT&CT
CIS Critical Security Controls v8.1
STRATA Telemetry
2.5 Threat Detection Engineering Awareness#
You can’t detect what you can’t observe, but observation without interpretation is noise. Detection must be engineered, version-controlled, and threat-informed.
Core Activities
Develop Detection rules referenced by Thread modelling in previous steps.
Develop rules mapped to ATT&CK TTPs.
Apply Detection-as-Code practices (Git, CI/CD, testing).
Measure fidelity, coverage, and operational cost.
Automate QA and regression testing.
Red/Purple Teaming planning for Detection Verifications.
Outputs
Detection Repository with traceability.
QA Reports with coverage metrics.
% of implemented and tuned detection rules per Threat Modelled
% of implemented deception in each operational zone
False positive and false negative monitoring.
Mean Time to Detect (MTTD) evaluation based on top TTPs.
Referenced Frameworks
MITRE ATT&CK Enterprise v19.2
DeTT&CT
Sigma
STRATA Automation.
TID-CMM Detection QA.
“Detection built from behaviours lasts longer than detection built from indicators.”
2.6 Response Executing with Precision#
Response is the natural continuation of detection. UTIOM positions incident handling as an engineered workflow, not an improvisation.
Core Activities
Developing Response plan, Playbooks aligned with defined Threats.( prioritized threats and crown jewels)
Automate containment through SOAR.(In case of absence of SOAR, consider containment plan without SOAR)
Define escalation paths34 and CJ-specific playbooks.
Track MTTR, MTTC and containment SLA.
Outputs
Playbook Library and Response Matrix.
Incident Records with contextual tags.
Lessons Learned Repository.
Referenced Frameworks
NIST SP 800-61
ISO/IEC 27035-1:2023
FIRST CSIRT
STRATA Resilience
TID-CMM Process Execution.
2.7 Continuous Improvement Learning Systems#
No design remains optimal forever. Continuous Improvement is the intelligence loop that converts experience into new strategy.
Core Activities
Post-incident reviews and Kaizen sessions.
Red/Purple team validation of detection coverage.
Update threat models and roadmaps.
Conduct periodic benchmarking and maturity assessments.
Outputs
Updated Vision and Strategy documents.
Proper aligned input for protection, Detection and Response.
Action plans with owners and timelines.
Maturity scorecards (UTIOM / TID-CMM / SOC-CMM).
Referenced Frameworks
Deming PDCA
Kaizen
SOC-CMM
STRATA Adaptability.
TID-CMM Feedback.
“Learning is the final deliverable of every incident.”
Notes
- Mainly qualitatvie, some quantitavie ↩
- Each role in a security Operation must be aware of their operational vission and mission, and this vision and missison are defined based on business operational critical assets. ↩
- It is super crucial for defence team to know the CJs, check the endnotes for more details. ↩
- from Sun Tzu’s The Art of War:"If you know the enemy and know yourself, you need not fear the result of a hundred battles. If you know yourself but not the enemy, for every victory gained you will also suffer a defeat. If you know neither the enemy nor yourself, you will succumb in every battle." Key Takeaways from the TextSun Tzu doesn't just mention "strengths and weaknesses" in passing; he dedicates an entire chapter (Chapter 6: Weak Points and Strong) to how you should apply that knowledge.Self-Knowledge: This is about "knowing yourself"—understanding your own resources, morale, and limitations.In cyber security, applying Sun Tzu via a SWOT lens means moving from reactive "firefighting" to proactive defense. Knowing yourself involves rigorous asset discovery and vulnerability management—identifying your "Weaknesses" (unpatched software) and "Strengths" (i.g.,robust encryption). Knowing the enemy means utilizing Threat Intelligence to understand the "Threats" (specific hacker groups/TTPs) and "Opportunities" (gaps in the attacker's own infrastructure). By aligning these, a CISO ensures that security controls aren't just a wall, but a strategic maneuver that makes the cost of an attack higher than the potential reward. ↩
- Threat profiling is a proactive cybersecurity process that involves identifying, analyzing, and documenting the specific, relevant adversaries and threats targeting an organization. (https://www.linkedin.com/pulse/cyber-threat-profiling-understanding-different-actors-reza-adineh/?trackingId=NkWFdbDGToWs8KNuWh51Rw%3D%3D), (https://www.linkedin.com/pulse/crowdstrike-mandiant-red-canary-reza-adineh-qrcgf/) ↩
- https://www.linkedin.com/pulse/from-ppt-strata-reza-adineh-ysqhf/?trackingId=%2FkSuK87cQRGkLDSGcxcCsw%3D%3D ↩
- Threat Informed Detection Capability Maturity Model ↩
- Means those TTPS which are mapped to CJs. ↩
- We can leverage Threat-Informed Detection Capability Maturity Model in this activity. ↩
- Deploy deception selectively where it increases adversary cost. ↩
- And decision gates. ↩
Adineh, R. (2026). The Unified Lifecycle. UTIOM Framework
Book, edition 1.2. utiom.de/book/unified-lifecycle/