Cybersecurity GRC 14 items
Security Operations Center (SOC) Operations Runbook Audit
Audits the operational runbooks and processes of a security operations center, including alert triage, escalation, shift management, and continuous improvement.
NIST 800-61NIST 800-53ISO 27001
Free PDF · enter your email to download.
Coverage & Staffing
- Is SOC monitoring coverage defined (24x7, follow-the-sun, or business-hours)? *
- Are analyst roles and tiers (T1/T2/T3) documented with responsibilities? *
- Is there a defined escalation path to incident response and management? *
- Are on-call rotations and contact trees maintained and current? *
Triage & Runbooks
- Do documented runbooks exist for the most common alert types? *
- Do runbooks define triage steps, enrichment sources, and decision criteria? *
- Are alert severity and priority definitions standardized? *
- Are runbooks reviewed and updated after significant incidents or changes?
Shift Management
- Is a structured shift handover process used to transfer open items? *
- Are open and in-progress cases tracked in a case management system? *
- Is an operational log of shift activity maintained?
Metrics & Improvement
- Are SOC performance metrics (MTTD, MTTR, alert volume) tracked? *
- Are recurring false positives fed back to detection engineering for tuning? *
- Is analyst burnout and alert fatigue monitored and managed?
Download the full Security Operations Center (SOC) Operations Runbook Audit checklist
Get it as a clean, printable PDF — free.
