SOPs · Security

Security: SOPs

Six procedures covering triage, the approval gate, containment, vulnerability handling, access review and the exception register.

Markdown. No sign-up, no email.

SOP 1: Triage#

Run: continuously, worked in score order.

  1. The analysis agent correlates raw signals into events. Analysts read events, never raw alerts.
  2. Every event carries its evidence and its baseline departure.
  3. Nothing is closed without a recorded reason. "Closed, no action" is a legitimate outcome and an illegitimate blank.
  4. Anything closed as a false positive feeds tuning within the week.

Closing without investigation is the metric that precedes every missed intrusion, which is why it is counted rather than discouraged.

SOP 2: The approval gate#

Run: on any response action.

StepRule
ScoreAutomated. Orders the queue, decides nothing
PresentEvent, evidence, proposed response, and the blast radius of that response
ApproveA named human. Under 15 minutes for high-risk, at any hour
ExecuteOnly pre-approved action types, only after approval
VerifyConfirm it took effect. An unverified response is an assumption
LogWho approved, what ran, what changed

The blast radius line is not optional. Disabling a service account stops an attacker and may also stop payroll. The approver must see both halves before deciding.

SOP 3: Containment#

Run: on confirmed compromise.

  1. Preserve evidence before changing anything. Snapshot, capture memory if feasible, export logs. Containment destroys the evidence needed to understand scope.
  2. Contain, then eradicate, then recover. In that order.
  3. Rotate credentials after the access path is closed. Rotating first tells the attacker they are seen while they still have a way back in.
  4. Assume lateral movement until disproven. The first host found is rarely the first host used.
  5. Freeze automated remediation on affected systems for the duration.

SOP 4: Vulnerability handling#

Run: continuously, reviewed weekly.

Prioritise by exploitability and exposure, not by CVSS alone. A critical on an internal system nobody can reach matters less than a medium on the login page, and a scanner cannot tell you that.

Severity, adjusted for exposureFix within
Critical, internet-facing48 hours
Critical, internal7 days
High30 days
Medium90 days, or accept with a dated exception

SOP 5: Access review#

Run: quarterly, with Data and Analytics.

  • Every account, every privilege, every service credential.
  • Anything unused for 90 days is removed, not queried. Restoring access takes minutes; standing unused privilege is permanent attack surface.
  • Every service account has a named human owner. An unowned service account is the one nobody notices being used.
  • Credentials older than 180 days are rotated on a schedule rather than after an incident.

SOP 6: Exception register#

Run: monthly.

Every accepted risk gets a row: what, why, who accepted it, and when it expires.

An exception without an expiry is not an exception, it is a decision nobody admitted making. The monthly review exists to find the ones whose date passed, and there are always some.

Escalation#

SituationGoes to
Confirmed compromiseIncident lead and CEO immediately. Legal within the hour if data is involved
Customer data possibly exposedLegal, for the notification clock. It starts before you are certain
Approval unreachable for a high-risk eventDeputy. If also unreachable, escalate rather than auto-approve
An agent proposing a response outside the allowlistRefuse, investigate why it was proposed
Coverage below 95%CTO. Unmonitored assets are the ones that get used

Back to Security

Get new material when it is published

Everything here is free and stays free. There is no form in front of any document. If you want to know when new guides and templates go up, leave an email.

Roughly monthly. Unsubscribe in one click. We do not share your address, and we will not call you.