SOC / Defensive Operations
Responsible for 15 controls, consulted on 30, accountable for none. The SOC acts entirely inside authority granted elsewhere — which is the design, and also the risk.
What It Is.
Owns. Maneuver. Executes fires and emplaces obstacles inside the standing rules of engagement.
Doctrinal origin. The G3. Executes the scheme — emplaces obstacles, repositions sensors, delivers fires — inside standing engagement authority.
The SOC executes. It is Responsible for maneuver assignment and implementation state (SM-2, SM-3), for the decisive-point protection floor and barrier sufficiency alongside platform owners (KT-2, KT-5), for decision-loop measurement (TA-1), for pre-authorized response (TA-4), for the tempo degradation trigger (TA-5), for the remediation backlog (CE-5), for drafting the rules of engagement it will then operate under (CG-3), and for recovery integrity verification and the reconstitution exercise (RC-4, RC-5).
That the SOC is Accountable for nothing is not an oversight. Every action it takes is either pre-authorized by the rules of engagement or escalated to the Authorizing Official; a SOC that holds its own accountability is a SOC that can authorize its own fires, and the first time a containment action takes a statutory service offline, the question of who agreed to that has no answer. Engagement authority is exactly what this structure is protecting.
One honest tension sits inside TA-1: the SOC measures its own decision loop. Detect, decide, contain — three timestamps, all recorded by the party being measured. The control’s own assessment procedure exists because of this and says to test the derivation against a sample of raw incident records rather than accept the computed figure. An assessor who skips that step is measuring the SOC’s reporting, not its tempo.
Every Control It Touches.
Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.
Accountable0 controls
Answers for the outcome. Exactly one role per control, and it is not delegable.
None. This role holds no accountable assignment anywhere in the framework.
Responsible8 controls
Does the work, or shares it. More than one role may be Responsible for the same control.
Consulted50 controls
Asked before the control is settled, because it holds knowledge the accountable role does not.
What It Puts into the Chain.
The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 23 products across 8 controls.
SM — Scheme of Maneuver
- Interaction alerts carrying no false-positive budget
- Detection events contributing to the detect segment
- Emplacement coverage feeding the posture computation
TA — Tempo and Temporal Advantage
- Defender loop time, the denominator of the temporal advantage ratio
- Loop time recorded for trend across cycles
- Baseline against which degradation is detected
- Degradation scenarios requiring a pre-planned branch
- Degradation status reported with the posture result
RC — Reconstitution and Recovery
- Objectives missed in exercise, entering the backlog
- Exercise results recorded across cycles
- Undemonstrated objectives requiring disposition
EN — Engagement and Pursuit
- Declared incidents requiring reconstruction
- Prioritized incidents requiring an authority decision
- Measured decide segment of the decision loop
- The material reconstruction is performed from
- Integrity record restore points are verified against
- Retention requirement sensor coverage must satisfy
- Authority response time within the decide segment
- Evidence for revising the pre-authorized set
- The decision authorizing transition to recovery
DV — Devices Terrain
- Detection telemetry that declaration and triage run on
- The record reconstruction is performed from
- Coverage as the detect segment of the decision loop
What It Depends On.
The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.
SM — Scheme of Maneuver
- Avenues of approach that determine where deception is worth placing
- Decisive points whose approaches are seeded first
- Terrain classification, so decoys are plausible for their layer
- Decide-segment measurement the response target is set against
TA — Tempo and Temporal Advantage
- Incident and alert timestamps from case management and response tooling
- Cycle cadence establishing the reporting period
- Baseline loop measurement to detect degradation against
- Barrier failure as a degradation trigger
- Role readiness gaps that would slow the loop
RC — Reconstitution and Recovery
- Objectives to be demonstrated
- Rebuild paths to be walked
- Verification step to be exercised
EN — Engagement and Pursuit
- Endpoint detection telemetry
- Deception interaction alerts, which carry no false-positive budget
- Asset weighting used to rank what was declared
- Decide-segment target the triage period is set against
- Declared incidents that trigger preservation
- Dwell estimate that sets the retention floor
- Terrain classification determining what must be preserved
- Legal and privacy determinations bounding what may be held
- Declared and prioritized incidents
- Pre-authorized response set, which bounds what needs escalating
- Rules of engagement defining the limits of authority
- Declared phase, which can widen standing authority
DV — Devices Terrain
- Device inventory coverage is reconciled against
- Dwell estimate that sets how long telemetry must survive
- Evidence retention requirement the sensors must satisfy
What the Role Has to Be Good At.
A pre-authorized fire (TA-4) has to be reversible and bounded, because it will execute without a human at machine speed. The design question is not whether it works but what it does when the detection was wrong.
The decision loop is only as real as the moment recorded as “decide”. Recording it when the ticket was updated rather than when the judgment was made produces a scoreboard that is precise and false.
Acting outside the ROE once, successfully, is how a program loses its engagement authority — because the next review will narrow it.
SM-2 sites moves on specific ground. A detection that is not attached to an element on the overlay cannot be counted toward coverage and will not survive the next tooling change.
Knowing which decisions genuinely need the Authorizing Official is what keeps the escalation path fast when it is actually used.
How It Goes Wrong.
Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.
Alerts triaged, tickets closed, hours worked. All measures of performance, none of effectiveness — the exact failure MOP and MOE exist to separate.
The ROE is written once and never revisited, so the pre-authorized proportion silently falls as the estate grows. Tempo degrades without any single decision to degrade it.
SM-3 tracks whether a maneuver is operational, not whether a product is licensed. A control marked implemented on the strength of a procurement is the most common way coverage numbers become fiction.
The exception becomes the practice, undocumented, and the rules of engagement stop describing what the SOC actually does.
KT-5 exists because an unmonitored barrier fails silently. When it does, the reachability answer changes and nothing raises its hand.
Against the Other Five.
The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.
The source of the SOC’s authority. The width of the pre-authorized list is the Authorizing Official’s single largest lever on defensive tempo.
Supplies the routes and the priorities the SOC sites moves against. The SOC is Consulted on almost all of the cell’s controls — that consultation is where “this route is not actually reachable in production” gets said.
Adjacent but deliberately separate. Hunt validates maneuver effectiveness (SM-6) on ground the SOC operates, and that check is worthless if the two are the same people under a different name.
The SOC proposes obstacles; platform owners site them and live with them. Co-responsibility on KT-2, KT-5, SM-2 and SM-3 makes that a negotiation rather than an instruction.
Co-responsible for the rules of engagement (CG-3) — the SOC drafts what it needs to execute, the ISSO makes it defensible, the Authorizing Official approves it.