View Categories

Detection & Alerting Framework

11 Docs

The Structured Use Case Architecture

Last Updated: March 18, 2026

The Detection and Alerting Framework provides the governance structure through which the SOC’s detection capability is designed, developed, validated, and maintained as the systematic expression...

Understanding the Cyber Kill Chain

Last Updated: March 18, 2026

The Cyber Kill Chain, originally developed by Lockheed Martin to characterise the progression of Advanced Persistent Threat intrusions, provides the structured model through which security...

Understanding Mandiant Attack Lifecycle

Last Updated: March 18, 2026

The Mandiant Attack Lifecycle describes the systematic progression that sophisticated, targeted adversaries follow from their initial entry into the environment through to the achievement of...

Understanding Mitre ATT&CK Framework

Last Updated: March 18, 2026

MITRE ATT&CK: The Adversarial Knowledge Framework The MITRE ATT&CK framework is the most comprehensive and operationally influential adversarial knowledge base available to the security community,...

Understanding Information Security Risk: Threats, Vulnerabilities, and Incidents

Last Updated: March 18, 2026

Information security risk represents the potential for a security incident to occur that results in loss, damage, or harm to the organisation’s information assets encompassing...

The Integrated Threat-to-Response Framework

Last Updated: March 18, 2026

The Security Operations Centre’s operational effectiveness depends not only on the quality of its individual components but on the coherence of the architecture connecting them....

Incident Classification and Categorization Framework

Last Updated: March 18, 2026

Incident taxonomy is the process of classifying and categorizing security incidents based on their nature, impact, and characteristics. A well-defined taxonomy helps the CERT standardize...

Risk-Aligned Incident Priority and Severity Classification

Last Updated: March 18, 2026

In the fast-evolving cyber threat landscape, the ability to prioritise and categorise security incidents based on their potential risk is not a procedural nicety but...

Business-Focused Incident Severity Framework

Last Updated: March 18, 2026

The technical characterisation of a security incident, however precise, provides an incomplete picture of the governance decisions the incident demands. The SOC analyst who classifies...

Content Development Life Cycle (CDLC)

Last Updated: March 18, 2026

A SIEM platform’s operational effectiveness depends less on the sophistication of its correlation engine than on the quality of the detection content running within it....

Turning Alert Noise into Operational Intelligence

Last Updated: March 18, 2026

False positive alerts are routinely dismissed as an unavoidable cost of running a security monitoring programme. In high-volume alert environments, incident responders are conditioned to...