🎉 Launch offer — 20% off every workbook & bundle. Applied automatically at checkout.
ciso.diy
Open SOC Architecture + Complete Build Series preview
Bundles build seriesbundleopen sourcesecurity programme

Open SOC Architecture + Complete Build Series

The reference architecture and all ten build volumes — the whole system-level design plus every plane built end to end, in the recommended build order. 30% off buying separately.

The complete set: the architecture that sits above the series, and all ten volumes that construct it.

Pillar 04 — The Open SOC Reference Architecture is the system-level document. Six planes ordered by ownership, a 24-component licence truth table with named replacements for the entries that fail, an AI analyst plane with an autonomy ceiling you can defend, three sized builds with honest hour counts, and five buy lines.

All ten Build Series volumes, each constructing part of what the architecture designs.

The volumes are numbered by subject and read in a different order — 02 → 01 → 06 → 05 → 03 → 10 → 04 → 07 → 09 → 08.

Inventory first, because every other volume scopes from it. Detection second, because its agents and network sensor pay dividends into volumes 02, 03, 07 and 09 at no marginal cost. Identity third, because in a remote-first estate that is where incidents actually begin. Backup next, because half of ransomware outcomes are decided by whether the restore works. Vulnerability management once you have inventory and detection to prioritise against. Email here, earlier than its number — locking down non-sending domains is an afternoon of work that closes a real spoofing gap and is the volume most likely to produce a visible early win, which matters when a programme needs internal support to keep going. Then response capability, hardening, cloud posture, and segmentation last, because it depends on both the inventory and the identity work being real.

Twelve months of updates across all eleven. Ships without support.

What's in this bundle

Security Program Pillars 10 pages

Pillar 04 Companion — The Open SOC Reference Architecture

The open-source SOC diagram everyone shares has two commercial products on it. This is the corrected version — six planes, 24 components with verified licenses and named replacements, an AI analyst plane with a defensible autonomy ceiling, and three sized builds with honest hour counts.

Architecture & Build 9 pages

Build Series Vol. 02 — Asset Inventory & Discovery

Discovery tells you what is out there. The source of truth holds what you have decided about it. The control lives in the reconciliation between them, not in either list.

Architecture & Build 9 pages

Build Series Vol. 01 — Detection & Monitoring

Wazuh, Suricata and Zeek assembled into a stack one person can operate, with the tuning and detection validation that almost every deployment skips.

Architecture & Build 9 pages

Build Series Vol. 06 — Identity & Access

One front door, authenticators that survive phishing, privileged identities separated from daily work, and access that genuinely ends when people do.

Architecture & Build 9 pages

Build Series Vol. 05 — Backup & Recovery

Copies an attacker holding domain admin cannot reach, and restores you have actually performed and timed — including the full-estate rebuild nobody plans for.

Architecture & Build 9 pages

Build Series Vol. 03 — Vulnerability Management

Finding what is exploitable, fixing what matters, and proving both — with a prioritisation model that still works when the severity score is missing.

Architecture & Build 7 pages

Build Series Vol. 10 — Email & Domain Defense

Domain authentication all the way to enforcement, transport security, portfolio hygiene, and the monitoring that tells you when someone is impersonating you.

Architecture & Build 9 pages

Build Series Vol. 04 — Incident Response Lab

The capability to investigate, contain and report — built before you need it, including the reporting clocks measured in hours rather than days.

Architecture & Build 8 pages

Build Series Vol. 07 — Endpoint Hardening & Configuration

Baselines per system class, enforced continuously and measured for drift, across a fleet that includes machines you do not manage and cannot reach on a network.

Architecture & Build 9 pages

Build Series Vol. 09 — Cloud & SaaS Security Posture

The control plane where the estate actually lives — misconfiguration, privilege graphs, public exposure, and the SaaS tenants nobody has ever baselined.

Architecture & Build 9 pages

Build Series Vol. 08 — Network Segmentation & Zero Trust

The containment substrate the rest of the series assumes: isolating a host, keeping a compromised endpoint away from the backups, restricting an unmanaged device to a narrow slice.

What's included

  • PDF — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
One-time purchase
$799.00 $639.20 20% off
  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-08-31