← Back to Marketplace
1. Purpose & Scope
This guide establishes the overarching governance architecture, risk taxonomy, and operational lifecycle required to maintain an enterprise information security management system (ISMS). It is designed as the master reference document that defines what must be controlled and why, while delegating the granular how to dedicated Standard Operating Procedures (SOPs).
In Scope:
- All personnel, contractors, third-party vendors, and service accounts with logical or physical access to corporate assets.
- All endpoints, servers, network infrastructure, cloud tenants, SaaS subscriptions, and data processing activities.
- Governance workflows including risk classification, RACI assignment, compliance mapping, and control lifecycle management.
Out of Scope:
- Physical facility security (covered under separate FAC-SOP series).
- Product-specific software development lifecycle security (covered under SDLC-SOP series).
2. Governance & RACI Matrix
Clear accountability prevents overlap and omission. The following matrix defines responsibility for core framework activities:
| Activity |
CISO |
SOC Lead |
IT Manager |
HR / Legal |
| Policy Development |
Accountable |
Consulted |
Consulted |
Informed |
| Risk Assessment |
Accountable |
Responsible |
Consulted |
Informed |
| Incident Declaration |
Accountable |
Responsible |
Informed |
Informed |
| Access Revocation |
Approved |
Informed |
Responsible |
Accountable |
| Vendor Risk Acceptance |
Accountable |
Consulted |
Responsible |
Approved |
| Control Validation (Audit) |
Accountable |
Responsible |
Consulted |
Approved |
3. Information Risk Classification Model
All corporate data and systems must be classified according to the impact of unauthorized disclosure, alteration, or destruction.
| Level |
Criteria |
Handling Requirements |
| Level 1 — Public |
Approved marketing material; published press releases. |
Standard integrity controls; no encryption required at rest. |
| Level 2 — Internal |
Operational handbooks, org charts, internal memos. |
Access control required; encryption in transit (TLS 1.2+). |
| Level 3 — Confidential |
Customer PII, financial forecasts, audit findings. |
Role-based access; AES-256 at rest; logging mandatory. |
| Level 4 — Restricted |
Security architecture; incident forensics; cryptographic keys. |
Need-to-know only; MFA mandatory; air-gapped backups. |
4. Standard SOP Template Architecture
Every operational playbook in the ISCSECURITY catalog follows a uniform control structure to ensure audit readiness and immediate deployability. When you purchase any SOP from the 14-pillar collection, it contains the following standardized sections:
Section 1 — Document Control & Metadata
Unique Document ID, version, effective date, classification, owner, and review cycle. Printed on every page footer for audit traceability.
Section 2 — Purpose & Scope
Explicit in-scope and out-of-scope statements. Defines personnel, systems, networks, and data subject to the procedure. Includes jurisdiction-specific applicability notes (GDPR, CCPA, labor law).
Section 3 — Definitions & Taxonomy
Controlled vocabulary with ISO 27001, NIST, and MITRE ATT&CK alignment where relevant. Eliminates ambiguity during audits or incident testimony.
Section 4 — Roles & Responsibilities (RACI)
Granular responsibility assignment per role: CISO, SOC, HR, Legal, People Manager, End User, IT Service Desk. Includes authority boundaries (e.g., "Can revoke access; cannot terminate").
Section 5 — Standards & Policy Requirements
The mandatory rules and configuration baselines. Written in prescriptive "shall / must / may not" language suitable for direct legal and regulatory citation.
Section 6 — Technical Controls & Detection Rules
Technology-agnostic control objectives with vendor-specific implementation examples (Microsoft Purview, CrowdStrike, Splunk, etc.). Includes SIEM correlation rules, DLP policy logic, and UEBA thresholds.
Section 7 — Response Procedures by Severity
Tiered playbooks (Minor / Moderate / Severe / Critical) with step-by-step decision trees. Includes automated response actions, escalation timelines, and evidence preservation triggers.
Section 8 — Investigation & Evidence Handling
Forensic preservation protocols, chain-of-custody templates, interview standards, and analysis integrity requirements (hash verification, bit-copy analysis).
Section 9 — Metrics & KPIs
Measurable performance indicators with target values, measurement methods, and review frequencies. Designed for quarterly management review and continuous improvement.
Section 10 — Compliance Mapping
Direct mappings to ISO 27001:2022 Annex A, NIST CSF 2.0, PCI DSS v4.0, GDPR, CCPA/CPRA, SOX ITGC, and HIPAA where applicable.
Section 11 — Appendices
Editable templates: Acknowledgment forms, coaching scripts, investigation report forms, configuration exports, evidence manifests, and approval sign-off sheets.
✓ What makes this different from generic policy templates?
These are operational playbooks, not static policies. They contain executable detection logic, forensic procedures, and HR-legal escalation triggers that map to your SIEM, EDR, and IAM platforms today.
5. The 14-Control Operational Pillar Map
This framework is executed through fourteen discrete operational playbooks. The matrix below maps each SOP to its parent NIST Cybersecurity Framework function and relevant ISO 27001:2022 Annex A controls.
⬇ Each row links to the full marketplace catalog for immediate purchase and download.
| Pillar / SOP |
NIST CSF 2.0 |
ISO 27001:2022 |
Availability |
| SOP-001: Incident Response & Containment |
Respond (RS) |
A.5.24, A.5.25 |
Paid Template |
| SOP-002: Phishing Investigation & Triage |
Detect (DE) |
A.5.7, A.5.23 |
Paid Template |
| SOP-003: Ransomware Mitigation |
Respond (RS) |
A.5.29, A.8.1 |
Paid Template |
| SOP-004: User Provisioning / De-provisioning |
Protect (PR) |
A.5.15, A.5.16, A.5.18 |
Paid Template |
| SOP-005: Privileged Access Review |
Protect (PR) |
A.5.18 |
Paid Template |
| SOP-006: MFA Enforcement |
Protect (PR) |
A.5.17 |
Paid Template |
| SOP-007: Patch Management |
Protect (PR) |
A.8.8, A.8.9 |
Paid Template |
| SOP-008: Vulnerability Assessment |
Identify (ID) |
A.5.7, A.8.8 |
Paid Template |
| SOP-009: Asset Lifecycle & Disposal |
Protect (PR) |
A.5.09, A.8.1 |
Paid Template |
| SOP-010: Data Backup & Recovery |
Recover (RC) |
A.5.29, A.8.1 |
Paid Template |
| SOP-011: Vendor / Third-Party Risk |
Govern (GV) |
A.5.19, A.5.20 |
Paid Template |
| SOP-012: Change Management Control |
Protect (PR) |
A.5.29, A.8.8 |
Paid Template |
| SOP-013: Security Awareness & Phishing Simulation |
Protect (PR) |
A.6.3, A.6.4 |
Paid Template |
| SOP-014: Acceptable Use Enforcement |
Govern (GV) |
A.5.11, A.6.3 |
Paid Template |
6. Operational Lifecycle Workflow
Security controls are not static artifacts. They follow a continuous cycle aligned with ISO 27001 Clause 10 and NIST CSF Improve (IM):
- Identify & Classify: Map assets, classify data (per Section 3), and determine risk appetite. Output: Asset inventory, data flow maps, risk register.
- Implement Controls: Deploy the technical and procedural controls defined in the relevant SOPs above. Output: Baseline configurations, enforced policies, training completions.
- Monitor & Detect: Aggregate telemetry, audit logs, and anomaly thresholds to identify deviations. Output: SIEM alerts, vulnerability scan results, access reviews.
- Respond & Recover: Execute incident response phase gates; restore services via backup protocols. Output: Containment evidence, eradication reports, RCA documentation.
- Review & Improve: Annual management review, access re-certification, and policy gap analysis. Output: Updated SOP versions, control effectiveness metrics, CAPA log.
7. Sample Extract: Incident Response Phase Gates
To demonstrate the depth of our operational playbooks, the following high-level phase gates are excerpted from the full SOP-001: Incident Response & Containment. This preview illustrates strategic decision trees; the complete template contains workstation isolation commands, forensic chain-of-custody templates, and stakeholder communication scripts.
Phase 1 — Preparation
Objective: Ensure tools, contacts, and legal retainers are active.
Decision Gate: Is the IR war room activated and lead assigned within 15 minutes of declaration?
Phase 2 — Detection & Analysis
Objective: Validate alert legitimacy and determine scope.
Decision Gate: Is the event a false positive, minor incident, or material breach requiring regulatory notification?
Phase 3 — Containment
Objective: Limit blast radius without destroying evidence.
Decision Gate: Short-term (network isolation) vs. long-term (AD segmentation) strategy selected?
Phase 4 — Eradication
Objective: Remove threat actor presence and restore integrity.
Decision Gate: Has the root cause (IOC / vulnerability) been neutralized and verified across all affected assets?
Phase 5 — Recovery
Objective: Return systems to production with enhanced monitoring.
Decision Gate: Have restored systems passed integrity baselines and threat-hunting validation?
Phase 6 — Post-Incident
Objective: Document lessons learned and update controls.
Decision Gate: Have all SOP gaps been logged for the quarterly management review and CAPA tracking?
📎 Full Technical Runbooks in Paid SOPs:
The complete SOP-001 includes Active Directory isolation PowerShell scripts, memory acquisition SOPs, regulatory breach notification timelines (GDPR 72-hour, state privacy laws), and executive briefing templates.
8. Compliance Mapping Summary
This governance framework and the 14 operational SOPs directly satisfy control objectives from the following audit architectures:
- SOC 2 Type II: Trust Services Criteria CC1.0 (Control Environment), CC6.1 (Access Control), CC7.2 (System Monitoring), and CC8.1 (Change Management).
- ISO/IEC 27001:2022: Clauses 4–10 (Context, Leadership, Planning, Support, Operation, Evaluation, Improvement) and Annex A.5 (Organizational Controls).
- NIST CSF 2.0: Govern (GV) and Identify (ID) functions, providing the foundational context for Protect, Detect, Respond, and Recover.
- PCI DSS v4.0: Requirements 1 (Firewall), 7 (Access Restrictions), 8 (Identity), 10 (Logging), and 12 (Security Policy).
9. Document Control & Revision History
| Version |
Date |
Author |
Description of Changes |
| 1.0 |
2025-03-15 |
ISCSECURITY Arch |
Initial draft for internal stakeholder review. |
| 2.0 |
2026-08-30 |
ISCSECURITY Arch |
Public evaluation release; mapped to 14 operational SOP pillars; added template architecture preview. |
Need the Editable Source Files?
Use this framework as your internal policy spine. Then operationalize it with the 14 detailed SOP templates above.
Unlock the Complete Operational Playbooks
This sample is strategic. The 14 fully editable, audit-tested .DOCX templates map straight to your enterprise deployment configurations and contain the technical runbooks referenced above.
Browse Full Catalog
Disclaimer: This document is a public evaluation copy intended for reference and educational purposes. It does not constitute legal advice or a complete audit-ready control set. Organizations should adapt this framework to their specific regulatory environment and risk appetite.
© ISCSECURITY SOP Framework. Classification: Public Domain / Reference. Unauthorized resale of templates prohibited.