Security Program Pillars Templates
The CISO Marketplace AI Security Department pillars, rebuilt as open-source DIY guides — the real architecture we run, written so you can build it on your own estate, with the managed version available if you would rather not
The Operator's Manual — C2 Command Layer
The capstone above all six pillars: one seat that conducts the whole department. Intake from four employee doorways, visible approval gates, one living risk register, and observability into every AI channel — with the agent layer and MCP wiring that runs it.
Pillar 05 — The Incident Response Operating System
An operating system for the worst day — the right people in one room, on one clock, with 90% of the hardest choices already made. Built on NIST 800-61 Rev. 3, with the offline runbook, the notification clocks and a ready-to-run tabletop.
Pillar 04 — The AI-SOC Operating System
Read every alert, resolve the routine, escalate only what needs a human. A reducer that overlays your existing SIEM, EDR, identity and cloud — human-gated, auditable, and capped at an autonomy level you can defend.
Pillar 01 — The Compliance Operating System
Map controls once, satisfy every framework. A continuous, registry-driven compliance program across SOC 2, ISO 27001, HIPAA, PCI, CMMC, DORA and NIS2 — plus the ISO 42001 and EU AI Act layer most guides still omit.
Pillar 06 — The Fractional CISO Operating System
The capstone hub: a human-owned register that aggregates every security stream into board-legible, quantified risk. The 2026 pricing ladder, the first 90 days, the five-page board deck, and the layer the AI vCISO platforms structurally cannot replace.
Pillar 02 — AI-Augmented DevSecOps Risk Register
Run a continuous, AI-triaged security program across 100+ apps as a solo engineer. Platform-first discovery, SAST/SCA/secrets/DAST, a self-healing risk register, and tiered Claude triage — on free and near-free parts.
Pillar 03 — AI-Augmented PTaaS Lane
An authorized, sandboxed autonomous offense lane that proves bugs — a crashing proof-of-vulnerability or live exploit chain, paired with a candidate patch, under the same register and human gate as Pillar 02. Design-stage guide, published before the build.
Bug-Hunter Automation
The continuous discovery layer between Pillars 02 and 03 — shift-left source analysis, autonomous runtime testing, and a validation gate in the middle that files findings instead of noise. Ten sections, eight working appendices.
Pillar 04 Companion — The Open SOC Reference Architecture
The open-source SOC diagram everyone shares has two commercial products on it. This is the corrected version — six planes, 24 components with verified licenses and named replacements, an AI analyst plane with a defensible autonomy ceiling, and three sized builds with honest hour counts.
Pillar 04 Companion — SOC in a Box
The Open SOC reference architecture landed on one machine you can hold — a coreboot NUC with the Management Engine disabled, Nitrokey as the root of trust, three disks mapped to three storage tiers, and a 14-test acceptance suite you run before pointing a single agent at it.