Having gone through the process of enumerating your threat profile, defining the SOC scope and evaluating what services would be proportionate for your SOC you should be in a position to put it all together.
It's common for SOC operating models to be represented on a single page:
Very basic operating model
The diagram above is very basic, and your design will likely differ. However it is important to keep it simple at the start and revisit the model as the design process continues. Once you’re in a position to start digging down into each of the pillars or functions it is important to capture how each component should be interacting with others and most importantly what the key outputs are.
There are many ways to map this but if you’re stuck, the SIPOC model is very useful.
Once the dependencies, inputs, processes and outputs are enumerated and understood, you can start establishing technology requirements and find the most appropriate tools for your SOC.
When you’re in a position to proceed:
The next section covers the principles of Onboarding, an area that is often underestimated and therefore, under resourced.