ASEF: the AI SOC Evaluation Framework
ASEF, the AI SOC Evaluation Framework, is a vendor-neutral way to evaluate any SOC tool across the SecOps Shift Map, from the data pipeline through detection, investigation, response, and remediation. It measures what each tool does, and how much of that work the AI does on its own.
Evaluate any tool on the map, not only a whole platform.
ASEF lays out the full security operations lifecycle as one Shift Map: data ingestion and processing, detection engineering, investigation and triage, then response, remediation, and the feedback loop, with a Platform and Trust layer running across all of it. Every product you might buy sits somewhere on that map.
You do not have to evaluate a whole AI SOC platform to use it. Score a data pipeline, a detection engineering tool, an investigation copilot, or a standalone response engine on its own. Put the zones you care about in scope, and the framework grades only those, in depth, down to their subdomains, and leaves the rest out of the verdict.
Buy the whole stack, or decouple it.
You can now buy this whole stack from one vendor, or assemble it from separate parts. Both are real strategies, and the choice keeps getting harder as more of the stack decouples. The question shifts from which platform to which tool for which job.
That is why ASEF grades tools, not suites. It gives you one consistent ruler to hold against a single-vendor platform and against a specialized tool for one stage, so both get measured against your gap, not against a vendor's framing. You evaluate each product for the exact job you need it to do, and compare them on the same sheet.
What it measures is the AI inside each tool.
What ASEF measures inside each tool is the AI. Every capability is scored on an autonomy scale: no capability, the AI assisting while you act, the AI proposing while you approve, the AI acting under your veto, or the AI running end to end with no human in the loop. That makes it strongest exactly where product claims are hardest to check, AI SOC and Agentic SOC, where "the AI handles it" can mean anything from a chatbot to a fully autonomous workflow. ASEF turns that claim into a score you can hold up.
Two modes off one map.
ASEF is built by practitioners, for practitioners, and it runs in two modes off the same map. Practitioners read it forward, from Frame to Decide, to compare products, prove the finalists on their own data, and make the call against thresholds they set themselves. Product teams read it backward, as the evaluation their own product will face, to score each capability for trust, complexity, and impact, find the zones where they are hollow, and run gap analysis against the same map their buyers use.
The SecOps Shift Map
- Data ingestion and processing
- Detection engineering and SecOps resilience
- Investigation and Triage
- Response, Remediation, and Feedback loop
- Platform and Trust (cross-cutting)
The autonomy scale
- 0, None: no capability here
- 1C, Collaborator: the AI assists, the human acts
- 1G, Guide: the AI proposes, the human approves
- 1A, Approver: the AI acts, the human can veto
- 2, Automated: runs end to end, no human in the loop
The six-stage journey
- Frame the gap: define the SOC gap and the org path (no SOC, MDR, mature).
- Map the shift: place capabilities on the Shift Map across the lifecycle zones.
- Score capabilities: apply the autonomy scale (0, 1C, 1G, 1A, 2) per capability.
- Run a proof: validate scores against the vendor in a structured proof of value.
- Compare profiles: compare candidate tools side by side on the same scoring sheet.
- Decide and measure: make the call and track PICERL metrics after rollout.
Frequently asked questions
- What is ASEF?
- ASEF, the AI SOC Evaluation Framework, is a vendor-neutral way to evaluate any SOC tool across the SecOps Shift Map, from the data pipeline through detection, investigation, response, and remediation, plus a cross-cutting Platform and Trust layer. It scores what each tool does and how much of that work the AI does on its own, so it is strongest for AI SOC and Agentic SOC.
- Can I use ASEF to evaluate a single tool, not a whole platform?
- Yes. Put only the zones you care about in scope, for example detection engineering or investigation, and ASEF grades those in depth and leaves the rest out of the verdict. You can score a data pipeline, a detection engineering tool, an investigation copilot, or a standalone response engine on its own.
- Who uses ASEF, and what are the two modes?
- Two audiences read the same map. Practitioners read it forward to evaluate and choose tools. Product teams read it backward to run gap analysis on their own product. The scores an evaluator assigns are the verdict; the editorial reference is only marked context.
- How does ASEF evaluate AI capabilities?
- Every capability is scored on an autonomy scale: no capability, the AI assisting while you act, the AI proposing while you approve, the AI acting under your veto, or the AI running end to end with no human in the loop.
- Is ASEF open to use?
- Yes. The framework reference and the guide are public at secops-unpacked.ai/asef/guide.