ASOC deployment architecture
ASOC Reference Architecture · Slide 1 of 2
Defense in Depth: where Secure, Assure, and SOAR install, what crosses, how action returns
Customer-controlled environment — controls, data and owners stay here
Firewall / WAFPerimeter policy
IDS / NDRNetwork detection
EDR / MDMEndpoint control
Vuln mgmtScan + patch
AD / PAMPrivileged access
KMS / PKIKey + cert authority
DNS securityResolution policy
MicrosegmentationEast-west control
Secure live sensorSPAN / TAP · packet metadata · signed findings · rolling local buffer
Branch / remote / OT
SD-WANSite routing
Branch firewallLocal enforcement
OT passive tapProtocol-aware sensor
AllowlistingApplication control
Local EDROffline-capable
Segment isolationAuto-quarantine
Local recoverySite-safe rollback
Physical accessBadge / camera log
ASOC connector runtimeVM or container in-zone · polls native APIs · receives webhooks
Cloud / SaaS / delivery
IAMCloud identity
CSPM / KSPMPosture mgmt
VPC flow / WAFTraffic + edge policy
KMS / DLPData protection
Backup / DRRecovery state
CASB / SaaS auditSaaS control plane
CI / CDBuild + release
SAST / SBOMCode + supply chain
ASOC cloud + build hooksLeast-privilege API identity per account · read-only posture and audit
Local evidence vaultRaw PCAP · payloads, encrypted — upload disabled without named approval
SOAR execution relaySOAR’s own execution engine — config change, patch, replay under approved scope
BNetwork boundaryF
ASOC platform — SaaS or customer-hosted clusterAPI gateway + ingestionauthn · schema · rate limit · tenant isolation BSecureObserveAssets, exposure graph, reachability, attack paths, PQC discovery CAssureValidateClaim replay, provenance, coverage, code and control evidence DSOARDetect · Decide · ExecuteFive air-gapped cyber LLMs — anomaly detection, config change, patching, network replay EPolicy + authority gateRBAC / ABAC scope · named-owner approval · timeout and blast radiusGoverns what SOAR is already able to execute — signs scope, expiry, rollback
Asset inventoryLive and continuous
Exposure graphReachability paths
Attack path analysisCross-layer chains
Claim replayAgainst the source
Provenance chainSigned, versioned
Coverage scoringPlus human review
Anomaly detection5 air-gapped LLMs
Config change + patchDirect execution
Network replayLive sensor tasking
Asset + relationship graphTenant-isolated, encrypted graph persistence
Evidence + audit storeImmutable, signed, retained records
Operations planeHealth · backup / DR · PAM-only key rotation
ASOC · DEPLOYMENT ARCHITECTURE · 01 / 11



