SOC-CMM INTRODUCTION

Model

The SOC-CMM certification model is based on the SOC-CMM model used for assessments. The model is not exactly the same but has significant overlap. This allows organizations to smoothly transition from SOC-CMM capability maturity assessments to SOC-CMM certification.
The certification model has 5 domains and 20 elements and is depicted below.

Model soc

The blue part of the model represents the part where maturity is evaluated, the purple domains represent the part where both maturity and capabilities are evaluated.

The main difference between the maturity model and the assessment model are in the technology and services domains. For technology, instead of evaluating individual technologies, security monitoring is approached from a platform perspective. Any relevant tools used to deliver security monitoring can be part of the technology stack and will be evaluated as a single platform. For services, the core of SOC services (reactive & proactive monitoring and response) is evaluated. Threat intelligence is added as a mandatory component to ensure SOCs understand what they are protecting the organization against.