Certifying a SOC's Managed Security Services doesn't necessarily mean reaching the same level. CCN-STIC 896 allows for the accreditation of different services, and depending on which ones are certified, the CCN establishes three maturity levels: Basic SOC, Advanced SOC, and Full SOC.
The difference between them isn't related to the size of the center, the number of analysts, or the volume of alerts it manages. The key lies in the capabilities it can demonstrate through its certified services.
Understanding this structure allows for a broader approach to certification. Before deciding which services to certify, it's helpful to know which level reflects the SOC's current capabilities and what would need to be added to advance to the next level.
Three Levels and Five Services
The starting point is the Basic SOC, which requires certified Cybersecurity Management and Detection services.
The combination makes sense from an operational perspective. Management provides the layer from which the SOC's strategy, objectives, governance, and monitoring and improvement mechanisms are established. Detection constitutes the core activity focused on identifying, analyzing, and reporting security threats and events.
The next level is the Advanced SOC. Prevention and Response services are added to Management and Detection.
This is a significant leap. The SOC no longer only demonstrates the ability to govern its operations and detect threats, but also the ability to anticipate them and act upon their identification.
Finally, the Full SOC incorporates the Protection service into the four previous ones. This covers all five categories: Cybersecurity Management, Prevention, Protection, Detection, and Response.
This classification allows maturity levels to be used as more than just recognition. It also provides a benchmark for analyzing how the SOC's capabilities are distributed.
The leap between levels begins with identifying what capability is missing
For a SOC that already has certified Management and Detection, moving to an Advanced level has a very specific meaning: it must also accredit its Prevention and Response services.
This allows for a much more useful analysis than simply aiming to 'move up a level'.
The exercise consists of reviewing the missing services separately.
If the objective is to incorporate Prevention, it will be necessary to verify what capabilities in this area already exist, how they are being provided, and how far they fall from the requirements established in CCN-STIC 896.
The same applies to Response. The SOC may already perform activities related to this service, but it will be necessary to verify whether its scope, procedures, resources, and evidence allow it to be accredited according to the guide.
Moving from Advanced to Full focuses the analysis on Protection. In this case, the organization will have already certified the other four services and can focus its efforts on determining what it needs to incorporate the fifth.
Viewed in this way, the maturity model offers a fairly clear roadmap: identify the services that can already be accredited, locate the missing capabilities, and work specifically on them.
Practical Review of Maturity Level
To determine where a SOC truly stands, an initial review can be conducted using the five services of CCN-STIC 896 as a reference.
Cybersecurity Management
Is there a defined structure for governing, monitoring, and improving the SOC's activity?
Detection
Are there consolidated capabilities and procedures in place to identify, analyze, and report security threats and events?
If both answers can be supported by the capabilities and evidence required by the guide, then the foundation for a Basic SOC is established.
From there:
Prevention
Which preventive capabilities are actually implemented, and which could be accredited?
Response
Are there operational capacity and procedures in place to respond to detected incidents?
The incorporation and certification of both services allows us to move towards the Advanced level.
Finally:
Protection
Does the SOC have the capabilities associated with this service, and are they sufficiently consolidated to pursue certification?
This last service completes the set of requirements to qualify for recognition as a Full SOC.
The objective of this review is not to internally assign a category. Recognition of the maturity level is the responsibility of the CCN and is requested once the necessary services have been certified. Its usefulness lies in identifying which capabilities separate the SOC from that next level and allowing it to focus its efforts there.
A SOC that wants to evolve from Basic to Full does not, therefore, have to address all of CCN-STIC 896 at once. It can use the service structure to establish a progressive roadmap, prioritizing those services that allow it to expand its capabilities coherently.