AI & Computingarticle2026-08-23

INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK

0 citations

Abstract

This article develops a model that integrates real-time Security Operations Center (SOC) log analytics with continuous auditing processes and aims to bridge the technical gap between operational threat monitoring activities and the internal audit function. Although SOC units generate high volumes of data, including authentication records, network traffic, and endpoint activities, these data sources are not systematically used in internal audit activities. The developed structure treats real-time log streams as audit evidence for assessing control effectiveness, identifying risk indicators, and analyzing deviations. Within this scope, SOC rules, audit tests, and risk scenarios are linked within an integrated structure. Methodologically, the study is based on the Design Science Research (DSR) approach. To evaluate the feasibility of the model, a virtualized three-host SOC environment was designed and implemented. The model was tested through a proof-of-concept scenario based on privileged access activities occurring outside business hours. The findings indicate that log-level visibility reduces blind spots in internal audit, strengthens control design, and supports a proactive governance approach, particularly in sectors with high security requirements such as the defense industry.

// Source

View paper (DOI)OpenAlexDenetişimPublished 2026-08-23

Authors: Kübra Aslan, Azze Özel, Onur Ceran

Institutions: Gazi Hastanesi, Aselsan (Turkey), Teknoloji Arastirma ve Gelistirme Endustriyel Urunler Bilisim Teknolojileri San Tic