About this program
Whether you run a SOC in-house or use an MSSP — a quick check on coverage, tooling, response time and reporting.
Risks addressed
- High No coverage outside business hours
- Critical Alert fatigue u2014 real incidents missed
- High No documented runbooks for top incident types
Controls (7)
-
24x7 coverage (in-house or MSSP)
CriticalThis control establishes continuous monitoring and incident response capabilities through dedicated personnel or a Managed Security Service Provider (MSSP) available around the clock, every day of the year. Coverage includes real-time security event triage, alert investigation, escalation of confirmed incidents,…
How to test + evidence
Testing procedure: Documented rota / MSSP SLA covering nights + weekends + holidays.
Evidence to collect: Rota / contract.
-
Mean-Time-To-Detect tracked + trending
HighMean-Time-To-Detect (MTTD) is a key performance indicator measuring the average elapsed time between the onset of a security incident or anomalous activity and its detection by security monitoring systems or personnel. Organizations systematically track MTTD across incidents, categorize by attack…
How to test + evidence
Testing procedure: MTTD metric reported monthly with trend.
Evidence to collect: SOC dashboard.
-
Mean-Time-To-Respond tracked
HighMean-Time-To-Respond (MTTR) is a key performance indicator that measures the elapsed time from when a security incident is detected to when containment, eradication, or recovery actions are completed. Organizations establish baseline MTTR targets for different incident severity levels, continuously track…
How to test + evidence
Testing procedure: MTTR per severity reported.
Evidence to collect: SOC dashboard.
-
Runbooks for top 10 alert types
HighThis control requires the Security Operations Center (SOC) to maintain documented runbooks for the ten most frequently triggered alert types in the organization's security monitoring infrastructure. Each runbook must include triage procedures, investigation steps, escalation criteria, containment actions, and resolution…
How to test + evidence
Testing procedure: Documented playbooks; analysts can step through without senior help.
Evidence to collect: Runbook library.
-
Use-case engineering / detection coverage
MediumUse-case engineering and detection coverage is the systematic process of translating threat intelligence, adversary behaviors, and business-critical attack scenarios into specific detection logic within security monitoring tools (SIEM, EDR, NDR). Each use case defines what to detect, how to detect…
How to test + evidence
Testing procedure: Detections mapped to MITRE ATT&CK + reviewed quarterly.
Evidence to collect: Detection inventory.
-
Quarterly purple-team exercises
MediumQuarterly purple-team exercises involve coordinated engagements where offensive security professionals (red team) execute realistic attack scenarios while defensive teams (blue team) detect and respond, with both sides collaborating in real-time to identify gaps. Unlike standalone penetration tests, purple teaming emphasizes…
How to test + evidence
Testing procedure: Detection effectiveness tested with red-team / purple-team scenarios.
Evidence to collect: Test reports.
-
False-positive rate tracked + trending down
MediumThis control requires the organization to systematically measure the false-positive rate of security detection systems (SIEM, IDS/IPS, EDR, DLP, WAF, etc.) over time and demonstrate that rates are declining or remain within acceptable thresholds. False positives are alerts that incorrectly…
How to test + evidence
Testing procedure: FP rate < 30% on top alert types; tuning meeting cadence in place.
Evidence to collect: Tuning minutes.