← UTIOM
UTIOMv1.4

Think smarter. Stay secure.

SOC operating model

How a security operations centre is structured, governed, staffed, measured and improved. The design that architecture implements and maturity models measure.

Definition

A SOC operating model defines how a security operations centre is structured, governed, staffed, measured and improved. It answers who does what, how work is prioritised, who holds decision authority, and what success means.

It is distinct from two things it gets confused with. A SOC architecture describes tooling and data flows. A SOC maturity model measures how well the operating model is executed. The operating model sits between them: the design that architecture implements and maturity measures.

Most organisations have an architecture and, increasingly, a maturity score. Far fewer have a written operating model. That absence is why architecture drifts toward whatever the tooling supports, and why maturity improves in the domains that are easiest to improve rather than the ones that matter.

The seven components

A complete operating model addresses all seven. Most cover four or five, and the gaps are remarkably consistent across organisations.

1. Vision
Why the SOC exists, what it protects, how success is measured, who owns the outcome. Most commonly absent entirely, which is why every downstream decision inherits the ambiguity.
2. Strategy
The security operations strategy: which adversaries are realistic, what capability gets built in what order, with owners and dates. Distinct from business strategy, which is an input to it.
3. Asset prioritisation
Which services, data and identities carry disproportionate business consequence. Crown jewels with named business owners, threat models and documented attack paths.
4. Visibility engineering
What telemetry exists, at what quality, covering which attack paths. Blind spots documented and formally accepted rather than discovered mid-incident.
5. Detection engineering
How analytics are built, tested, versioned and retired. Whether a rule traces to an adversary behaviour and a business consequence.
6. Response
Playbooks per critical asset, containment authority defined in advance with named individuals, escalation thresholds and decision gates set before the incident.
7. Continuous improvement
How experience becomes capability. Findings converted into engineering change with owners and dates, rules retired systematically, threat models refreshed on cadence.

Internal, outsourced or hybrid

All three structures work. The operating model must define responsibilities at each boundary, and this is where outsourced and hybrid arrangements most often fail.

Internal
Full control over priorities and content, at the cost of coverage and specialist depth. The model must address on-call, out-of-hours escalation and knowledge continuity when people leave.
Outsourced
Coverage and scale, at the cost of context. A provider can operate detection content but cannot decide which of your assets carry business consequence. Vision, strategy and crown jewel definition cannot be delegated, and assuming they have been is the most common failure in managed security arrangements.
Hybrid
The most common and the most demanding. Every boundary needs an explicit owner: who tunes, who escalates, who authorises containment on production, and who decides what gets detected at all.

A complete operating model, free

UTIOM is a SOC operating model covering all seven components across three pillars, published free with four assessment instruments.

The model
Seven phases across leadership, engineering and operations, connected as one lifecycle
Maturity assessment
50 staged criteria across six levels, gated so advanced practice on an incomplete foundation does not count
Capability assessment
105 indicators across ten domains, returning where effort buys the most risk reduction
Metrics calculator
70 metrics with explicit formulas, leading and lagging separated
Improvement roadmap
All three combined into one sequenced ninety-day plan

This page is a summary. The full treatment is in the book: The Foundations →

Join the UTIOM community. Discuss, contribute evidence and share implementation experience. About the community →