Skip to content

OCDF on one page

OCDFA summary of this framework's terms.

The framework uses a handful of ideas many times over. Learn these and every other page reads faster.

How the pieces fit

  1. Pick a tier (Essential, Standard or Advanced). It decides which capabilities apply to an organisation of your size and exposure.
  2. Build the capabilities in the six functions, in the order the first 90 days sets out, people and process before tools.
  3. Measure how well you run them on four maturity levels, criterion by criterion, with evidence.
  4. Give every gap an owner and a date, and reassess once a year.

Around all of it sit two lenses: the CIA triad, which says what each capability protects, and the regulatory layer, which says which laws require it.

The terms

Term What it means Where it lives
CDC Cyber Defence Center: the organisational capability that governs, prevents, detects, responds and recovers. Used interchangeably with SOC here. Introduction
Six functions Govern, Identify, Protect, Detect, Respond, Recover, taken from NIST CSF 2.0. Govern sits above the other five. Documents 01–06
Capability Something the CDC must be able to do, with an ID such as DE-2 (detection engineering). 43 in total. Capability index
Tier E · S · A Essential, Standard, Advanced. Which capabilities apply at your size. Higher tiers include the lower ones. Implementation tiers
Level 1–4 Initial, Managed, Established, Optimising. How well you run the capabilities you have. Staged: a level counts only when every criterion at it and below is met. Maturity model
Criterion status Each maturity criterion is scored on five states, from not considered to implemented & evidenced. Only the top two count, or only the top one with evidence-based scoring. Scoring method
Evidence The document, export or test result that proves a criterion. Without it, a self-assessment is an opinion. Self-assessment tool
Operating model Who runs the watch: a provider (A), an in-house tiered SOC (B), an in-house capability-based team (C), a hybrid, or a shared CDC (D). Operating models
[GATE] [HARD] [SOFT] How much a capability depends on another department: a decision it must take, work it must do, or input that improves the result. Introduction
CIA mapping Whether a capability mainly protects confidentiality, integrity or availability. CIA triad
Regulatory hooks The NIS2, GDPR, DORA and related articles each function helps you meet. Each function document; EU landscape
National annex NIS2 status, authorities and reporting channels for one member state. Annexes
ECSF roles The European Cybersecurity Skills Framework profiles the CDC's roles are built on. Roles & competences
Source labels Law · Standard · Guidance · OCDF · Practitioner: where a statement's authority comes from. Why trust this framework

What you get

  • Guidance: the six function documents, the build order, operating models, roles, and deep dives on running the CDC, detection-as-code and threat intelligence.
  • Templates: charter, incident response plan, detection use case, metrics, job description, MSSP checklist, containment actions, controls register and annual calendar. All templates
  • Playbooks: three by attack and four by platform. Playbooks
  • Browser tools: regulatory profile selector, team skill matrix and maturity self-assessment. Tools
  • A worked example of a fictional organisation using all of the above. Worked example

Three rules the whole framework follows

  1. Mandate before machinery. Authority, scope and budget come before tools.
  2. Evidence over assertion. A capability that cannot be shown to work does not count.
  3. Balanced beats spiky. Level 2 in every function is worth more than Level 4 detection on top of Level 1 governance, because attackers use the weakest function.

Open CDC Framework, licensed CC BY 4.0.