SOC Management: The SOC-CMM Model — Part 2
How Do You Measure Your Company's Security Operations Center Readiness? The Maturity of Business, HR, and Process

In the previous part, we covered how the SOC-CMM model works, and why it has become one of the most important self-assessment tools for modern SOCs. The model’s strength, though, lies in the fact that it doesn’t just examine technology and services — it also covers three foundational operating areas that determine how much real value the SOC is able to create: business alignment, the human factor, and process maturity.
In this second part, we cover SOC-CMM’s three “non-technology” core domains: Business, People, and Process. These domains form the organizational, strategic, and operational foundation of SOC operations. If any one of them is weak, the SOC’s overall maturity suffers — even if the technology is modern and the service portfolio is broad.
1. Business - The Maturity of Business Alignment
The Business domain examines how closely the SOC is tied to the company’s strategic goals, risk profile, and governance structure. A SOC operates effectively when it clearly understands what it’s protecting and why — and when it doesn’t function as an isolated IT function, but is organically integrated into the business. Business domain maturity directly determines how well the SOC can support the company’s decision-making and risk management.
Aspects of the Business domain:
- Business Drivers: assesses whether the SOC has identified, documented, and applies the company’s key business drivers in its decision-making.
- Customers and Stakeholders: examines whether the SOC has identified its internal and external stakeholders, and whether it can communicate with them in a differentiated way.
- Charter: examines whether the SOC has a formalized founding document (mission, vision, goals, responsibilities, and so on).
- Governance: assesses the SOC’s governance structure, decision-making authority, executive reporting, and governance meetings.
- Privacy and Policy: examines whether the policies governing SOC operations are documented, up to date, and compliant with applicable data protection law.
2. People - The Maturity of the SOC’s Human Factor
The People domain is one of the most critical areas of SOC operations: it examines whether the organization has adequate staffing levels, competencies, roles, and training structures. The SOC’s technology stack can be as modern as you like — without a stable, skilled, motivated team behind it, operations won’t be mature. People domain maturity directly determines the SOC’s responsiveness, quality, and long-term sustainability.
Aspects of the People domain:
- Employees: assesses SOC headcount, competency profile, and the presence of the necessary KSAOs (Knowledge, Skills, Abilities, and Other Characteristics).
- Roles and Hierarchy: examines whether roles, responsibilities, and organizational structure are clear and documented.
- People Management: assesses the maturity of team goal-setting, performance evaluation, succession planning, and management support.
- Knowledge Management: examines whether the SOC has a skills-and-knowledge matrix, documented knowledge, and a knowledge-sharing process.
- Training and Education: assesses onboarding, regular training, certification support, and practical exercises.

3. Process — The SOC’s Operational Maturity
The Process domain is the backbone of SOC operations: it examines how well documented, consistent, measurable, and improvable the SOC’s processes are. Process maturity determines how predictably, auditably, and scalably the SOC operates. In SOC-CMM version 2.4, this domain expanded significantly, and it’s now the most complex area of SOC operations.
Aspects of the Process domain:
- SOC Management: assesses the maturity of the operating model, continuous improvement, quality assurance, and SOC architecture.
- Operations and Facilities: examines the physical and organizational conditions of operations, including OPSEC (Operations Security), the war room, physical security, and remote-work support.
- Reporting and Communication: assesses the quality of reports, metrics, executive communication, and awareness campaigns.
- Use Case Management: assesses the full lifecycle of detection use cases, from definition through fine-tuning to MITRE ATT&CK mapping.
- Detection Engineering and Validation: examines detection quality assurance, automated validation, and verification of log source coverage.
- Automation Engineering: assesses the maturity and quality assurance of workflow automation and AI-based processes.
- Log Management: assesses log source coverage, data quality, normalization, and the integrity of log collection.
Case Example:
When a Lack of Process Undermines SOC Performance
A large enterprise’s SOC had a modern SIEM and experienced analysts, yet incident response was consistently delayed. A SOC-CMM assessment of the Process domain revealed that:
- there was no formalized use-case lifecycle management,
- roughly 25% of log sources were not sending data,
- incident-handling playbooks were out of date,
- reports were not reaching leadership.
The technology was in place — but a lack of process meant the SOC still wasn’t operating effectively.
Summary: Why the Business–People–Process Triad Is Critical
One of the key messages of the SOC-CMM framework is that SOC maturity isn’t purely a technology question. Real operational maturity rests on three pillars:
- Business alignment - the SOC knows what it needs to protect.
- Human factor (People) - the SOC has the right competencies.
- Process maturity - the SOC operates consistently and measurably.
If any one of these is missing, the SOC’s operations become vulnerable — even if the technology is modern and the service portfolio is broad.
(In the next installment, Part 3, we’ll cover SOC-CMM’s Technology and Services domains, which assess the SOC’s technical capabilities and service portfolio.)


