# 👔 Role Profile: SOC Manager

![SOC Mgr Avatar](../assets/SOC%20Mgr%20Avatar.png)

## 📋 Role Overview
The **SOC Manager** holds overall operational authority during incidents, approves major containment actions, declares Major Incidents, engages the BCP/DR process if required, coordinates executive escalation, oversees execution and reporting, and ensures overdue action tracking escalation occurs.

---

## 🎯 Mandatory Responsibilities (SOP / Authority Matrix)
- 👑 **Overall Operational Authority**: Overall operational authority during security incidents.
- 🚨 **Declare Major Incidents**: Formally declare Major Incidents (SEV-1/SEV-2) based on technical triage.
- 🛡️ **Approve Major Containment**: Approve major containment actions (e.g. taking critical servers offline, network segment isolation).
- 🔄 **Engage BCP/DR Process**: Engage Business Continuity Plan (BCP) or Disaster Recovery (DR) process if impact exceeds operational tolerance.
- 📞 **Coordinate Executive Escalation**: Coordinate executive escalation with CISO, CIO, and Executive Management.
- 📊 **Oversee Execution & Reporting**: Oversee technical response execution, status reporting, and resolution.
- ⏱️ **Overdue Action Escalation**: Ensure escalation occurs for overdue post-incident recommendations and PIR action items.

---

## 🎮 TTX Scenario Responsibilities (Loan Ransomware Incident)
- Review L2/L3 triage summary and formally declare SEV-1 Major Ransomware Incident.
- Authorize isolation of Loan file share `\\FS01\LoanShares` and user account restrictions.
- Evaluate BCP threshold with Loan Business Owner and align with CISO/CIO.

---

## 📝 Action Checklist
- [ ] Receive escalation from L2/L3 and declare Major Incident.
- [ ] Approve major technical containment actions.
- [ ] Coordinate executive notifications with CISO and CIO.
- [ ] Evaluate BCP/DR activation thresholds.
- [ ] Oversee Incident Response execution and approve technical recovery plans.
- [ ] Track post-incident corrective actions and escalate overdue items.
