OCDF on one page
OCDFA summary of this framework's terms.
The framework uses a handful of ideas many times over. Learn these and every other page reads faster.
How the pieces fit
- Pick a tier (Essential, Standard or Advanced). It decides which capabilities apply to an organisation of your size and exposure.
- Build the capabilities in the six functions, in the order the first 90 days sets out, people and process before tools.
- Measure how well you run them on four maturity levels, criterion by criterion, with evidence.
- Give every gap an owner and a date, and reassess once a year.
Around all of it sit two lenses: the CIA triad, which says what each capability protects, and the regulatory layer, which says which laws require it.
The terms
| Term | What it means | Where it lives |
|---|---|---|
| CDC | Cyber Defence Center: the organisational capability that governs, prevents, detects, responds and recovers. Used interchangeably with SOC here. | Introduction |
| Six functions | Govern, Identify, Protect, Detect, Respond, Recover, taken from NIST CSF 2.0. Govern sits above the other five. | Documents 01–06 |
| Capability | Something the CDC must be able to do, with an ID such as DE-2 (detection engineering). 43 in total. |
Capability index |
| Tier E · S · A | Essential, Standard, Advanced. Which capabilities apply at your size. Higher tiers include the lower ones. | Implementation tiers |
| Level 1–4 | Initial, Managed, Established, Optimising. How well you run the capabilities you have. Staged: a level counts only when every criterion at it and below is met. | Maturity model |
| Criterion status | Each maturity criterion is scored on five states, from not considered to implemented & evidenced. Only the top two count, or only the top one with evidence-based scoring. | Scoring method |
| Evidence | The document, export or test result that proves a criterion. Without it, a self-assessment is an opinion. | Self-assessment tool |
| Operating model | Who runs the watch: a provider (A), an in-house tiered SOC (B), an in-house capability-based team (C), a hybrid, or a shared CDC (D). | Operating models |
| [GATE] [HARD] [SOFT] | How much a capability depends on another department: a decision it must take, work it must do, or input that improves the result. | Introduction |
| CIA mapping | Whether a capability mainly protects confidentiality, integrity or availability. | CIA triad |
| Regulatory hooks | The NIS2, GDPR, DORA and related articles each function helps you meet. | Each function document; EU landscape |
| National annex | NIS2 status, authorities and reporting channels for one member state. | Annexes |
| ECSF roles | The European Cybersecurity Skills Framework profiles the CDC's roles are built on. | Roles & competences |
| Source labels | Law · Standard · Guidance · OCDF · Practitioner: where a statement's authority comes from. | Why trust this framework |
What you get
- Guidance: the six function documents, the build order, operating models, roles, and deep dives on running the CDC, detection-as-code and threat intelligence.
- Templates: charter, incident response plan, detection use case, metrics, job description, MSSP checklist, containment actions, controls register and annual calendar. All templates
- Playbooks: three by attack and four by platform. Playbooks
- Browser tools: regulatory profile selector, team skill matrix and maturity self-assessment. Tools
- A worked example of a fictional organisation using all of the above. Worked example
Three rules the whole framework follows
- Mandate before machinery. Authority, scope and budget come before tools.
- Evidence over assertion. A capability that cannot be shown to work does not count.
- Balanced beats spiky. Level 2 in every function is worth more than Level 4 detection on top of Level 1 governance, because attackers use the weakest function.
Open CDC Framework, licensed CC BY 4.0.