Skip to main content

Pro audit program · v1.0

SOC Maturity Quick Check

Whether you run a SOC in-house or use an MSSP — a quick check on coverage, tooling, response time and reporting.

  • General target area
  • NIST CSF framework
  • 7 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Whether you run a SOC in-house or use an MSSP — a quick check on coverage, tooling, response time and reporting.

Risks addressed

  • High No coverage outside business hours
  • Critical Alert fatigue u2014 real incidents missed
  • High No documented runbooks for top incident types

Controls (7)

  1. 24x7 coverage (in-house or MSSP)

    Critical

    24x7 coverage (in-house or MSSP)

    How to test + evidence

    Testing procedure: Documented rota / MSSP SLA covering nights + weekends + holidays.

    Evidence to collect: Rota / contract.

  2. Mean-Time-To-Detect tracked + trending

    High

    Mean-Time-To-Detect tracked + trending

    How to test + evidence

    Testing procedure: MTTD metric reported monthly with trend.

    Evidence to collect: SOC dashboard.

  3. Mean-Time-To-Respond tracked

    High

    Mean-Time-To-Respond tracked

    How to test + evidence

    Testing procedure: MTTR per severity reported.

    Evidence to collect: SOC dashboard.

  4. Runbooks for top 10 alert types

    High

    Runbooks for top 10 alert types

    How to test + evidence

    Testing procedure: Documented playbooks; analysts can step through without senior help.

    Evidence to collect: Runbook library.

  5. Use-case engineering / detection coverage

    Medium

    Use-case engineering / detection coverage

    How to test + evidence

    Testing procedure: Detections mapped to MITRE ATT&CK + reviewed quarterly.

    Evidence to collect: Detection inventory.

  6. Quarterly purple-team exercises

    Medium

    Quarterly purple-team exercises

    How to test + evidence

    Testing procedure: Detection effectiveness tested with red-team / purple-team scenarios.

    Evidence to collect: Test reports.

  7. False-positive rate tracked + trending down

    Medium

    False-positive rate tracked + trending down

    How to test + evidence

    Testing procedure: FP rate < 30% on top alert types; tuning meeting cadence in place.

    Evidence to collect: Tuning minutes.