Eight figures that explain particular aspects of UTIOM, with two appendix tables. The V-Model on the home page stays the canonical model; nothing here replaces it. Colours follow the three pillars used across the site: purple is Leadership & Governance, green is Engineering & Enablement and UTIOM itself, amber is Operations & Analysis, and rust is the alert-driven model and the validation rail.
From a siloed security operations centre and reactive incident response to UTIOM
The main transformation: separate SOC functions and a disconnected incident-response workflow become one operating model. On the right, the canonical V-shape with its three pillars, and beneath it the same functions placed on a conceptual distance-to-impact scale — all of them run continuously; what differs is their distance from impact and their intensity.
NIST SP 800-61 and SANS PICERL mapped onto the seven UTIOM phases
Classic NIST and SANS models aggregate preparation into one broad phase. UTIOM decomposes it into Vision, Strategy and threat profiling, and Crown Jewels and attack paths — then explicitly engineers the visibility and detection capabilities required before operational response. Phases 1–3 are preparation and strategic threat orientation, 4–5 engineering and enablement, 6 operational analysis and response, and 7 continuous improvement across the whole lifecycle.
The operating model in detail
The same three pillars and seven phases as the home page, with what each phase consumes, what it produces, and the outcome it is accountable for. The side panels carry three things the simplified view leaves out: the scope of the priority lens, the guardrails around crown jewels, and the decision-making loop that returns operational reality to leadership.
Threat-to-outcome traceability chain
How threats, crown jewels and attack paths generate evidence requirements, and how missing telemetry becomes a Telemetry Engineering requirement before any detection logic is written. This is why TID-CMM is not a framework for writing SIEM rules.
Yes · Assure it
Measure coverage, completeness, timeliness, parsing, schema conformance, retention and health.No · Engineer it
Missing evidence becomes a prioritised Telemetry Engineering requirement.Normalise → Enrich → Validate → Maintain
The validation rail across Threat Visibility, Threat Detection and Response
Purple teaming, detection QA and response exercising are not sub-capabilities of phase 5. Together they validate the complete chain from attack path to response, which is why each phase on the left arm of the V has a validation partner on the right.
Who pulls the trigger: a conceptual authority progression
Containment authority is designed before the incident, not negotiated during it. This is a conceptual progression of how that authority matures; it is deliberately not numbered and must not be read as the UTIOM maturity scale, which is assessed through its own staged criteria.
UTIOM, TID-CMM and TIR-CMM framework family
UTIOM is the complete operating model. TID-CMM and TIR-CMM add measurement depth on the engineering and response sides and share one end-to-end evidence trail.
TID-CMM
Would we actually see it? · phases 2–5 plus the detection side of 6 and 7TIR-CMM
Could we actually stop it? · phase 6 plus the response side of 5 and 7The incident response continuum in a security operations centre
The doctrine drawn as a single scale. Threat intelligence, engineering, monitoring, hunting, containment and improvement are not separate functions that hand work to each other. They are incident response at different distances from impact, which is why UTIOM removes the silos rather than coordinating between them.
Process view: inputs, outputs and decisions per phase (BPMN-style)
A second view of the same canonical model, redrawn from the original input-flow sketch with the corrections applied. Swimlanes are the three pillars; rounded blocks are the seven phases; documents are the inputs and outputs each block consumes or produces; the diamond is the telemetry decision; dashed message flows are inputs that can arrive from outside the SOC. Nothing here changes the V — it explains how work moves through it.
Per-phase inputs, outputs and validation partner
The same information as A1 in tabular form, for the page where the V-shape is explained. Each row is one block of the process view; the last column is the phase's partner on the right arm of the V.