Know the data is arriving
Track expected agents, collectors and log sources so silence, delayed telemetry and zero-data conditions are visible instead of being mistaken for a quiet environment.
Damocles Managed Security Operations combines source onboarding, source health, alert triage, investigation, escalation and reporting. The service records what data was available, what the analyst concluded, who owns the next action and which gaps remain open. Guardian gives the customer and provider one operational record of that work.
Customers need to know whether the expected sources are reporting, which alerts were reviewed, what the analyst concluded, who must act and whether the response was completed. A specialist console alone rarely answers all of those questions for the customer.
Damocles defines the operating responsibility behind the selected compatible security technology. Aegis provides the managed monitoring and analyst service, while Guardian presents customer-scoped source health, alerts, investigations, actions and reports.
Track expected agents, collectors and log sources so silence, delayed telemetry and zero-data conditions are visible instead of being mistaken for a quiet environment.
Use customer, asset, identity, vulnerability and source context to decide whether an alert is benign, suspicious, confirmed, unresolved or needs deeper investigation.
Escalate a clear required action with ownership, timing, evidence, expected outcome and a defined path into containment, remediation or incident response when required.
The service schedule defines the compatible connectors, customer scope, monitored sources, coverage window, investigation depth, escalation path and response responsibilities. Unsupported or missing data remains visible as a service condition.
Confirm approved collectors, agents, cloud, firewall, identity, endpoint, DNS, vulnerability and other security sources; map each source to the correct customer and expected operating state.
Identify configured, reporting, delayed, zero-data, degraded and unavailable source states and distinguish a telemetry problem from an absence of security activity.
Review alert context, affected assets and identities, known exposure, duplicate activity and customer-specific conditions before deciding whether an investigation is required.
Build a defensible record of the event using available telemetry, timeline, affected scope, related activity, evidence, analyst conclusion, disposition and remaining uncertainty.
Use agreed contacts, severity, service hours and response paths to move the issue to the customer, MSP, Damocles engineer or incident-response process that actually owns the next step.
Report monitored scope, source-health exceptions, material alerts, investigation outcomes, unresolved actions, recurring noise and service-improvement work.
Review source health, triage, investigation and escalation workflows to identify telemetry gaps, inconsistent decisions and actions that may not reach accountable owners.
Expected telemetry, ownership and usable context.
Missing, delayed or malformed security data.
How supported alerts enter triage and investigation.
Consistent priority, context and disposition decisions.
Timelines, artefacts and reasoning supporting conclusions.
Triggers, authority and accountable customer actions.
Status, closure, exceptions and linked remediation.
Source health, activity, outcomes and unresolved risk.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles checks an expected telemetry source through ownership, collection method, parsing, event receipt and onboarding acceptance.
Damocles reconciles the customer-approved source inventory with platform entries, owners, expected event types and current status.
Damocles compares expected cadence with last-event time, transport state, parsing status and source-side health for sampled sources.
Damocles identifies missing, delayed, filtered or unusable telemetry and records the affected detection and investigation use cases.
Damocles reviews selected detection logic, data dependencies, scope, suppression, tuning history and known blind spots.
Damocles samples representative alerts and records enrichment, severity, disposition, timing and analyst rationale.
Showing 6 representative areas. The full governed matrix contains 16 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.
Findings are reported against the governed service coverage and customer impact. Separate classification references are shown only where they are part of the approved profile.
Reviews sampled telemetry health, detection handling, alert triage, investigation evidence, escalation, action ownership, case closure and operational reporting within the managed-security-operations scope.
An operating-model review with source and workflow evidence, material gaps, prioritised actions and validation outcomes.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles reconciles expected sources with ingestion health, samples detections and traces representative alerts through triage, investigation, escalation, customer action and closure. Operational records support service review but monitoring cannot guarantee detection of every attack.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Confirms expected telemetry, collection method, ownership and source-side health during onboarding and gap review.
Reviews ingestion state, detection output and representative alerts in the monitoring platform.
Builds timelines, preserves evidence and applies severity and escalation procedures to representative cases.
Tracks customer-owned actions, closure evidence, reporting and service-improvement decisions.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Source onboarding | Damocles checks an expected telemetry source through ownership, collection method, parsing, event receipt and onboarding acceptance. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for source onboarding. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to source onboarding. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Source onboarding when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled source onboarding; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Source inventory | Damocles reconciles the customer-approved source inventory with platform entries, owners, expected event types and current status. | Customer action owner and service reviewer Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for source inventory. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to source inventory. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Source inventory when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled source inventory; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Ingestion health | Damocles compares expected cadence with last-event time, transport state, parsing status and source-side health for sampled sources. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for ingestion health. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to ingestion health. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Ingestion health when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled ingestion health; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Telemetry gaps | Damocles identifies missing, delayed, filtered or unusable telemetry and records the affected detection and investigation use cases. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for telemetry gaps. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to telemetry gaps. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Telemetry gaps when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled telemetry gaps; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Detection content | Damocles reviews selected detection logic, data dependencies, scope, suppression, tuning history and known blind spots. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for detection content. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to detection content. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Detection content when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled detection content; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Alert triage | Damocles samples representative alerts and records enrichment, severity, disposition, timing and analyst rationale. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for alert triage. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to alert triage. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Alert triage when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled alert triage; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Investigation workflow | Damocles reconstructs representative investigation timelines from alerts, queries, evidence, hypotheses and analyst decisions. | Monitoring or SOC analyst Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for investigation workflow. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to investigation workflow. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Investigation workflow when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled investigation workflow; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Escalation | Damocles compares sampled escalation decisions and timing with severity, responsibility, contact and handoff requirements. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for escalation. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to escalation. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Escalation when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled escalation; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Customer communications | Damocles reviews representative customer notifications for timing, content, channel, acknowledgement and follow-up. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for customer communications. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to customer communications. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Customer communications when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled customer communications; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Investigation evidence | Damocles verifies that sampled investigations retain queries, events, notes, timestamps and decision evidence needed for review. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for investigation evidence. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to investigation evidence. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Investigation evidence when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled investigation evidence; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Action ownership | Damocles traces remediation and containment actions to named customer or provider owners, due dates and acceptance evidence. | Customer action owner and service reviewer Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for action ownership. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to action ownership. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Action ownership when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled action ownership; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Closure criteria | Damocles checks sampled closures for disposition, evidence, customer acknowledgement, residual actions and reopen criteria. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for closure criteria. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to closure criteria. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Closure criteria when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled closure criteria; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Operational reporting | Damocles reviews operational reports for source health, alerts, investigations, timing, actions, trends and stated limitations. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for operational reporting. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to operational reporting. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Operational reporting when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled operational reporting; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Service review | Damocles walks through service-review inputs, attendees, decisions, actions and subsequent improvement tracking. | Customer action owner and service reviewer Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for service review. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to service review. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Service review when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled service review; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Service boundaries and exclusions | Damocles records monitored sources, hours, responsibilities, exclusions, response authority and customer dependencies. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for service boundaries and exclusions. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to service boundaries and exclusions. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Service boundaries and exclusions when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled service boundaries and exclusions; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Detection limitations | Damocles documents known telemetry, detection, timing and response limitations and states that monitoring cannot guarantee detection of every attack. | Source owner and onboarding contact Assessment requires source inventory, monitoring access, sampled detections, alerts, cases, escalation records, actions and service reports, selected specifically for detection limitations. | Evidence records the source state, event timestamp, parser status, detection, alert, query, investigation timeline, escalation or action record relevant to detection limitations. | Incident Response Recommendations and Considerations for Cybersecurity Risk Management Revision 3 Applicability: Applies to Detection limitations when the operational process and representative records fall within the managed service period. Limit: The conclusion is limited to the sampled detection limitations; sampling cannot prove every event or attack is detected; customer and provider responsibilities remain bounded. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 Framework-level context | Contextual | Reviews sampled telemetry health, detection handling, alert triage, investigation evidence, escalation, action ownership, case closure and operational reporting within the managed-security-operations scope. | Source-health records, event and alert timestamps, sampled investigation timelines, analyst decisions, escalation and action records, closure evidence and service-review outputs. | Applies: Framework-level context is relevant where a customer uses NIST SP 800-53 to organise security monitoring, incident handling and assurance activities and wants the managed-service evidence available to its broader control assessment. Limit: No individual NIST control is claimed as verified. Sampling cannot prove continuous detection of every attack, complete control implementation, enterprise-wide monitoring coverage or organisational compliance. |
Assurance boundary: Damocles maps assessed coverage and observations to agreed objectives as traceable technical evidence. The review is not a certification, does not establish complete compliance, and does not confirm controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Managed Security Operations work.
Records coverage matrix produced from the authorised Managed Security Operations work.
Records retest and residual-risk record produced from the authorised Managed Security Operations work.
Records source inventory and health record produced from the authorised Managed Security Operations work.
Records investigation timeline produced from the authorised Managed Security Operations work.
Records escalation and action record produced from the authorised Managed Security Operations work.
Records service review record produced from the authorised Managed Security Operations work.
An operating-model review with source and workflow evidence, material gaps, prioritised actions and validation outcomes.
Managed security fails when monitoring, investigation, containment and remediation are treated as one vague responsibility. The service schedule separates analyst work, customer or MSP ownership and separately contracted response activity.
Monitor the contracted scope, review source health, triage alerts, investigate material activity, retain evidence, record disposition, escalate required action and tune approved workflows within the agreed service model.
Maintain access, supported source configuration, asset and identity context, contact details, change authority and the internal ability to complete customer-owned remediation or business decisions.
Damocles identifies missing, delayed or degraded telemetry and provides the evidence. The party that owns the device, connector, licence, network path or third-party platform completes the corrective change unless managed engineering is included.
For material activity, the service records alert origin, priority, timeline, affected assets or users, evidence reviewed, analyst conclusion, disposition, linked actions and any data limitation that prevented a stronger conclusion.
Endpoint isolation, account disablement, firewall changes, forensic acquisition, malware analysis, emergency response and broader incident handling are performed only where the service schedule or a separate incident-response authority includes them.
Patching, firewall or identity changes, endpoint rebuilds, cloud remediation and other engineering work remain customer or provider actions unless Damocles implementation or managed remediation is expressly included.
Platform capacity, source health, analyst coverage, response authority and incident-response capacity remain separate commercial and operational decisions.
Maintain the approved platform, connectors, agents, collectors, source mappings, health monitoring and support without continuous analyst triage.
Add alert triage, investigation, escalation and reporting during the agreed business-hours coverage window.
Add continuous monitoring and agreed escalation where the service model, source availability and operational capacity are expressly contracted.
Use an approved licensed monitoring and vulnerability platform with Guardian customer views and Aegis service delivery.
Use an approved self-hosted or provider-controlled option with explicit infrastructure, storage, maintenance, retention and analyst responsibilities.
Combine approved endpoint, firewall, cloud, identity, DNS, vulnerability and other sources under one customer operating model while retaining source-specific support boundaries.
Contacts, service hours, severity, escalation, response authority and customer responsibilities are agreed before live monitoring begins.
Confirm products, sources, contacts, priorities, customer mappings, service hours, escalation paths and response authority.
Record expected source health, normal activity, key assets and identities, known exposure, business-critical systems and operational exceptions.
Track source health and incoming security activity during the contracted coverage window and surface data-quality conditions that reduce investigation confidence.
Prioritise alerts, gather available context, correlate relevant activity, document evidence and determine whether the event is benign, suspicious, confirmed or unresolved.
Contact the agreed party and create the required customer action, engineering task, containment pathway or incident-response process with the available evidence attached.
Track closure, report unresolved issues, tune approved logic, correct source gaps and improve the customer baseline and service coverage over time.
The customer should be able to understand service health and material security activity without interpreting raw platform output.
Approved sources, agents, collectors, customer mappings, expected state, current health, last-seen context and known support or data-quality exceptions.
Known assets, identities, critical systems, normal activity, exclusions, contacts, service hours, escalation assumptions and customer-specific context used during triage.
Priority, status, alert origin, evidence, timeline, affected scope, analyst conclusion, disposition, uncertainty and linked customer action.
Who was contacted, when, why, which evidence was provided, what action was required and which response path or authority applied.
Monitored scope, source health, material alerts, investigations, unresolved actions, service gaps, recurring issues and improvement activity for the reporting period.
Approved source, detection, triage, workflow and operational changes required to reduce noise, restore visibility or improve investigation quality.
The customer or MSP provides the approved source list, required access, customer and asset mappings, escalation contacts, change authority, incident contacts, expected service hours, critical-system context and known environment constraints.
The service cannot reliably investigate activity from missing, delayed or unsupported data. Source gaps remain visible and are not represented as evidence that no risk exists. Where a conclusion cannot be validated because the required source or context is unavailable, that limitation is retained in the investigation or service record.
The report or service record is the beginning of remediation, not the end of the engagement. These steps keep the outcome usable after formal delivery.
Damocles walks the customer through the findings, evidence, affected scope, dependencies and uncertainty so there is agreement on what requires action.
Each material recommendation is allocated to the team that can implement it, with a clear expected outcome and realistic dependency on other changes.
Quick risk reduction, structural change, compensating controls and longer-term engineering are separated so the customer can plan the work sensibly.
Configuration records, change references, screenshots, test results, source state or other agreed evidence are retained for later review.
Where included, Damocles reviews the changed state, performs a retest or reassessment, and records whether the original exposure is resolved, reduced or still present.
Issues that cannot be fully removed remain visible with the accepted limitation, compensating control, review date and decision owner.
The proposal identifies the authorised scope, delivery method, assumptions, customer inputs, working window, deliverables, briefing, remediation support and any included retest or follow-up. Fixed-scope engagements are priced against that agreed boundary; retainers and managed services use the recurring quantity and service model stated in the schedule.
When the environment, target count, repositories, locations, access, service coverage or required evidence changes materially, Damocles records the impact before continuing. The customer can approve a variation, reduce the scope, defer the additional work or create a separate engagement. Hidden scope expansion is avoided because it produces poor testing and unreliable delivery dates.
Third-party licences, specialist platforms, travel, after-hours work, emergency response, remediation engineering and work outside the agreed deliverables are included only when listed in the proposal. Existing customer technologies can be used where they are supported and suitable; Damocles does not require a particular vendor simply to deliver the service.
Guardian presents source health, customer-scoped alerts, investigations, vulnerability context, risks, All Actions and approved reports through one workspace. External MSPs can operate authorised customer contexts while retaining the agreed first-line relationship.
Compatible security technologies remain distinct connector and delivery options. Aegis is the Damocles managed operational service behind them, and the service record keeps platform health, analyst conclusions and customer-owned actions visible as separate responsibilities.
The final answer depends on the customer environment and scope, but these are the points that should be resolved before work begins.
Timing depends on scope, access, environment stability, customer availability and the review depth required. The proposal states the expected delivery window and the assumptions that can change it.
Yes, but the change is recorded. Damocles explains the coverage, timing and commercial impact before additional work is performed.
Yes. Internal teams, developers, cloud partners, infrastructure providers and MSPs can participate where responsibilities, access and communication paths are clear.
Priority considers practical exploitability or failure likelihood, exposure, affected business capability, data, privilege, dependency, available compensating controls and remediation effort.
Remediation guidance and handover are included as stated in the proposal. Implementation, managed change, emergency work and extensive engineering are separate unless expressly included.
Closure uses the method suitable for the issue: retesting, rescanning, code or configuration review, operational evidence, restored source health, tabletop follow-up or another agreed validation method.
Monitored sources, ingestion, retention, service hours, triage, investigation depth, escalation, response time, containment, incident response, forensic work and remediation engineering are included only where expressly contracted. A 24×7 monitoring window does not automatically grant authority to isolate endpoints, disable identities or make production changes.
No monitoring service can identify or prevent every malicious event. Unsupported sources, missing data, telemetry delay, unavailable customer context and customer response delays remain explicit service conditions and can limit the strength or speed of an investigation conclusion.
We will map the compatible technology, source-health model, analyst responsibilities, escalation, reporting, response authority and Guardian customer experience required.