Skip to content
Open access

INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK

Aug 2026 · Denetişim · 0 citations · 9 references

TL;DR

A model that integrates real-time Security Operations Center log analytics with continuous auditing processes and aims to bridge the technical gap between operational threat monitoring activities and the internal audit function indicates that log-level visibility reduces blind spots in internal audit, strengthens control design, and supports a proactive governance approach.

Abstract

This article develops a model that integrates real-time Security Operations Center (SOC) log analytics with continuous auditing processes and aims to bridge the technical gap between operational threat monitoring activities and the internal audit function. Although SOC units generate high volumes of data, including authentication records, network traffic, and endpoint activities, these data sources are not systematically used in internal audit activities. The developed structure treats real-time log streams as audit evidence for assessing control effectiveness, identifying risk indicators, and analyzing deviations. Within this scope, SOC rules, audit tests, and risk scenarios are linked within an integrated structure. Methodologically, the study is based on the Design Science Research (DSR) approach. To evaluate the feasibility of the model, a virtualized three-host SOC environment was designed and implemented. The model was tested through a proof-of-concept scenario based on privileged access activities occurring outside business hours. The findings indicate that log-level visibility reduces blind spots in internal audit, strengthens control design, and supports a proactive governance approach, particularly in sectors with high security requirements such as the defense industry.

Read PDF

Similar papers

Review Open access Sep 2026

The Compliance Gap: Why Audit-Based Cybersecurity Models Fail Critical Infrastructure and the Case for Continuous Control

A conceptual review argues that this model is structurally incapable of guaranteeing security in modern CI environments and develops the case for a transition to continuous monitoring and continuous control and traces the intellectual and regulatory lineage of the alternative.

Chukwunenye Amadi · 0 citations
Open access Aug 2026

Auditability and Performance Monitoring Frameworks for Enterprise Decision-Support Systems

This study proposes an integrated Auditability and Performance Monitoring Framework for enterprise DSS environments that unifies structured reporting workflows, transaction traceability, KPI-based performance evaluation, and validation procedures within a single architecture.

Ramsha Siddiqui, Ahmed Erfan Nahian, Nirban Bhowmick et al. · 1 citation
Review Aug 2026

Transition from Periodic Security Assessments to Continuous Vulnerability Management Frameworks

The article examines the transition from scheduled security assessments to continuous vulnerability management frameworks in enterprise environments with unstable external exposure and explains why periodic assessment loses completeness when asset states change between review cycles.

Kolchin Rustam · 0 citations
Aug 2026

Taming tool sprawl: Streamlining cyber security programme performance

The paper concludes that a disciplined focus on validation enables financial institutions to reduce exposure, improve returns on existing investments, and provide more meaningful, evidence-based reporting to senior stakeholders.

Tim Dickinson · 0 citations
Review Open access Aug 2026

From It Audit Findings to Cybersecurity Governance: A Risk-Based Remediation Framework for Critical Digital Infrastructure

This article proposes an eleven- stage risk-based remediation framework running from finding validation through continuous monitoring, together with eight measures spanning timeliness, ownership, verification quality, and business linkage, which is proposed rather than empirically validated.

Josephat Deogratius Katundabwile, David Mbui Kamau · 0 citations
Sep 2026

Implementing a Security Operations Baseline Through Process Tree Modeling for Network Security Situational Awareness

A novel NSSA framework based on process tree modeling and dynamic service-chain orchestration that significantly outperforms PCA and Basic Evolution in terms of true positive and false positive rates, while the dynamic service-chain mechanism ensures efficient resource utilization and rapid threat containment.

Si-Wei Li, Xiao-Dong Wei · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.