Skip to main content

Pro audit program · v1.0

SOC Maturity Quick Check

Whether you run a SOC in-house or use an MSSP — a quick check on coverage, tooling, response time and reporting.

  • General target area
  • NIST CSF framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Whether you run a SOC in-house or use an MSSP — a quick check on coverage, tooling, response time and reporting.

Risks addressed

  • High No coverage outside business hours
  • Critical Alert fatigue u2014 real incidents missed
  • High No documented runbooks for top incident types

Controls (7)

  1. 24x7 coverage (in-house or MSSP)

    Critical

    This control establishes continuous monitoring and incident response capabilities through dedicated personnel or a Managed Security Service Provider (MSSP) available around the clock, every day of the year. Coverage includes real-time security event triage, alert investigation, escalation of confirmed incidents,…

    How to test + evidence

    Testing procedure: Documented rota / MSSP SLA covering nights + weekends + holidays.

    Evidence to collect: Rota / contract.

  2. Mean-Time-To-Detect tracked + trending

    High

    Mean-Time-To-Detect (MTTD) is a key performance indicator measuring the average elapsed time between the onset of a security incident or anomalous activity and its detection by security monitoring systems or personnel. Organizations systematically track MTTD across incidents, categorize by attack…

    How to test + evidence

    Testing procedure: MTTD metric reported monthly with trend.

    Evidence to collect: SOC dashboard.

  3. Mean-Time-To-Respond tracked

    High

    Mean-Time-To-Respond (MTTR) is a key performance indicator that measures the elapsed time from when a security incident is detected to when containment, eradication, or recovery actions are completed. Organizations establish baseline MTTR targets for different incident severity levels, continuously track…

    How to test + evidence

    Testing procedure: MTTR per severity reported.

    Evidence to collect: SOC dashboard.

  4. Runbooks for top 10 alert types

    High

    This control requires the Security Operations Center (SOC) to maintain documented runbooks for the ten most frequently triggered alert types in the organization's security monitoring infrastructure. Each runbook must include triage procedures, investigation steps, escalation criteria, containment actions, and resolution…

    How to test + evidence

    Testing procedure: Documented playbooks; analysts can step through without senior help.

    Evidence to collect: Runbook library.

  5. Use-case engineering / detection coverage

    Medium

    Use-case engineering and detection coverage is the systematic process of translating threat intelligence, adversary behaviors, and business-critical attack scenarios into specific detection logic within security monitoring tools (SIEM, EDR, NDR). Each use case defines what to detect, how to detect…

    How to test + evidence

    Testing procedure: Detections mapped to MITRE ATT&CK + reviewed quarterly.

    Evidence to collect: Detection inventory.

  6. Quarterly purple-team exercises

    Medium

    Quarterly purple-team exercises involve coordinated engagements where offensive security professionals (red team) execute realistic attack scenarios while defensive teams (blue team) detect and respond, with both sides collaborating in real-time to identify gaps. Unlike standalone penetration tests, purple teaming emphasizes…

    How to test + evidence

    Testing procedure: Detection effectiveness tested with red-team / purple-team scenarios.

    Evidence to collect: Test reports.

  7. False-positive rate tracked + trending down

    Medium

    This control requires the organization to systematically measure the false-positive rate of security detection systems (SIEM, IDS/IPS, EDR, DLP, WAF, etc.) over time and demonstrate that rates are declining or remain within acceptable thresholds. False positives are alerts that incorrectly…

    How to test + evidence

    Testing procedure: FP rate < 30% on top alert types; tuning meeting cadence in place.

    Evidence to collect: Tuning minutes.