Research

Watch · narrated whiteboard episodesL3

The Governance of Autonomous SOC Authority

The Autonomous SOC debate is fundamentally a debate about authority. When an AI agent quarantines a production server, revokes credentials, or blocks a network segment, those acts are consequential and sometimes irreversible. No published decision-theoretic framework exists for when an autonomous SOC should act versus escalate — and that absence is itself an exploitable gap. This series builds the governance architecture from the ground up: a taxonomy of autonomous actions by reversibility and blast radius, the principal hierarchy that governs which agent can do what, the chain-of-custody problem when the forensic investigator is an AI, the playbook-drift attack surface when SOAR updates itself, and a maturity model for assessing readiness to grant autonomous authority. Grounded in NIST SP 800-61, NIST AI RMF, NIST SP 800-207, ISO/IEC 27035, and the human-autonomy interaction literature.

Murali Chillakuru·5 episodes
  1. 8 min Episode 1The Irreversibility Spectrum: A Taxonomy of Autonomous SOC ActionsBefore granting autonomous authority, classify every response action by reversibility time and blast radius — the two dimensions that determine which actions are safe to automate and which require human confirmation.
  2. 8 min Episode 2Principal Hierarchies in AI-Automated Response: Who Governs the Responder?When a multi-agent SOC pipeline executes containment without human confirmation, the question of which agent can countermand which is a security control — not an implementation detail.
  3. 7 min Episode 3Chain-of-Custody in AI-Mediated ForensicsWhen the forensic analyst is an AI, the chain-of-custody obligation shifts to the infrastructure that fed the AI its evidence — three custody gaps, three technical controls, and the IRID that ties it together.
  4. 6 min Episode 4Playbook Drift as an Attack Surface: When SOAR Updates ItselfAn adaptive SOAR platform that learns from feedback creates a feedback loop — and feedback loops in systems controlling security logic are themselves an attack surface.
  5. 7 min Episode 5Measuring Autonomous SOC Readiness: An Assessment FrameworkStandard technical readiness criteria are necessary but not sufficient for autonomous SOC deployment — a five-dimension governance framework fills the gap.