Uploaded August 2025 | Updated September 2026, 3 hours ago
The Ontology for SOC Creation Assistance and Replication (OSCAR): A Community-Derived Tool for Developing SOC Capabilities
Justin Novak (Software Engineering Institute, US)
Dr. Justin Novak is a Senior Security Operations Researcher at the CERT Division of the Software Engineering Institute, leading a team as part of the Security Operations Division supporting the US Department of State, Department of Defense, and United States Treasury. In this role, his main focus in on capacity building for incident responders - both at the individual and organizational level. At the SEI, he is also involved in research on the development and operation of CSIRTs, Sector CSIRTs, and Security Operations Centers, focusing on incident response and incident management. Prior to the SEI, Justin worked in a variety of government roles, including with the federal government at the Department of Defense, and in state government. Justin holds a bachelor's degree in Physics from the University of Pittsburgh, a master's degree in Security Studies from the University of Pittsburgh, and a PhD in Science and Technology Policy from George Mason University with a focus on the impacts of development of innovative open-source software. Justin also serves as an adjunct professor at George Mason University's College of Engineering and Computing.
--
More organizations are choosing to deploy a Security Operations Center (SOC) model to improve enterprise security and to monitor data and information assets. However, developing a SOC can be a difficult, time-consuming, and expensive task. This also applies to organizations which may stop short of deploying a full stand-alone SOC, but which may nevertheless choose to deploy some capabilities normally associated with a SOC. To help organizations develop SOCs and SOC capabilities, we developed the Ontology for SOC Creation Assistance and Replication (OSCAR), a freely available resource meant to guide an organization through the development process, providing important baselines and a useful knowledge base along the way. OSCAR was developed using community input, including from interviews with FIRST members teams and input from other public and private sector SOC experts. Using this input, we synthesized a purpose-built dataset containing real-world insights into the SOC knowledge domain. For OSCAR, we used this dataset to develop a knowledge hierarchy that focuses on the traditionally emphasized people, process, and technology knowledge classes, while also addressing planning and functional considerations. OSCAR fills a gap in existing cyber ontologies by describing the development of SOCs and SOC capabilities, which is not a well-defined knowledge domain within existing cybersecurity ontologies, such as the Unified Cyber Ontology. Additionally, because the domain-specific knowledge used to create OSCAR is derived directly from working experts in the field, the ontology itself is a unique dataset not replicated elsewhere. This session is co-authored by Chris Rodman, who is unable to attend this year's conference.
The Ontology for SOC Creation Assistance and Replication (OSCAR): A Community-Derived Tool for Developing SOC Capabilities
Justin Novak (Software Engineering Institute, US)
Dr. Justin Novak is a Senior Security Operations Researcher at the CERT Division of the Software Engineering Institute, leading a team as part of the Security Operations Division supporting the US Department of State, Department of Defense, and United States Treasury. In this role, his main focus in on capacity building for incident responders - both at the individual and organizational level. At the SEI, he is also involved in research on the development and operation of CSIRTs, Sector CSIRTs, and Security Operations Centers, focusing on incident response and incident management. Prior to the SEI, Justin worked in a variety of government roles, including with the federal government at the Department of Defense, and in state government. Justin holds a bachelor's degree in Physics from the University of Pittsburgh, a master's degree in Security Studies from the University of Pittsburgh, and a PhD in Science and Technology Policy from George Mason University with a focus on the impacts of development of innovative open-source software. Justin also serves as an adjunct professor at George Mason University's College of Engineering and Computing.
--
More organizations are choosing to deploy a Security Operations Center (SOC) model to improve enterprise security and to monitor data and information assets. However, developing a SOC can be a difficult, time-consuming, and expensive task. This also applies to organizations which may stop short of deploying a full stand-alone SOC, but which may nevertheless choose to deploy some capabilities normally associated with a SOC. To help organizations develop SOCs and SOC capabilities, we developed the Ontology for SOC Creation Assistance and Replication (OSCAR), a freely available resource meant to guide an organization through the development process, providing important baselines and a useful knowledge base along the way. OSCAR was developed using community input, including from interviews with FIRST members teams and input from other public and private sector SOC experts. Using this input, we synthesized a purpose-built dataset containing real-world insights into the SOC knowledge domain. For OSCAR, we used this dataset to develop a knowledge hierarchy that focuses on the traditionally emphasized people, process, and technology knowledge classes, while also addressing planning and functional considerations. OSCAR fills a gap in existing cyber ontologies by describing the development of SOCs and SOC capabilities, which is not a well-defined knowledge domain within existing cybersecurity ontologies, such as the Unified Cyber Ontology. Additionally, because the domain-specific knowledge used to create OSCAR is derived directly from working experts in the field, the ontology itself is a unique dataset not replicated elsewhere. This session is co-authored by Chris Rodman, who is unable to attend this year's conference.










