Araştırma Makalesi

INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK

Sayı: 35 23 Ağustos 2026
PDF İndir
TR EN

INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK

Öz

This article develops a model that integrates real-time Security Operations Center (SOC) log analytics with continuous auditing processes and aims to bridge the technical gap between operational threat monitoring activities and the internal audit function. Although SOC units generate high volumes of data, including authentication records, network traffic, and endpoint activities, these data sources are not systematically used in internal audit activities. The developed structure treats real-time log streams as audit evidence for assessing control effectiveness, identifying risk indicators, and analyzing deviations. Within this scope, SOC rules, audit tests, and risk scenarios are linked within an integrated structure. Methodologically, the study is based on the Design Science Research (DSR) approach. To evaluate the feasibility of the model, a virtualized three-host SOC environment was designed and implemented. The model was tested through a proof-of-concept scenario based on privileged access activities occurring outside business hours. The findings indicate that log-level visibility reduces blind spots in internal audit, strengthens control design, and supports a proactive governance approach, particularly in sectors with high security requirements such as the defense industry.

Anahtar Kelimeler

Teşekkür

Doç. Dr. Onur CERAN

Kaynakça

  1. Alles, M. G., Kogan, A., & Vasarhelyi, M. A. (2008). Putting continuous auditing theory into practice: Lessons from two pilot implementations. Journal of Information Systems, 22(2), 195–214. https://doi.org/10.2308/jis.2008.22.2.195
  2. Alles, M., & Vasarhelyi, M. A. (2004). Continuous assurance and auditing: A prototype implementation. International Journal of Accounting Information Systems, 5(2), 143–168.
  3. Antunes, M. G., Maximiano, M., & Gomes, D. (2022). A client-centered information security and cybersecurity auditing framework. Applied Sciences, 12(9), 4102.
  4. Behl, A., & Behl, K. (2017). Cyberwar: The next threat to national security and what to do about it. Oxford University Press.
  5. Behloul, A., Ait Chellouche, M., & Lakhoua, N. (2015). Audit policy compliance and log analysis for information systems security. In Proceedings of the 2015 IEEE Security and Privacy Workshops (SPW) (pp. 183–188). IEEE. https://ieeexplore.ieee.org/document/7166125
  6. Briliyant, A. S., Ramadhani, N., & Nugraha, A. A. (2025). Beyond automation gap: A survey on continuous compliance audit for IoT security. SSRN. https://doi.org/10.2139/ssrn.xxxxx
  7. Chamkar, A., Maleh, Y., & Gherabi, N. (2024). Security operations centers: Use case best practices, coverage, and gap analysis based on MITRE ATT&CK. Journal of Cybersecurity and Privacy, 4(4), 36–52.
  8. Chandola, V., Banerjee, A., & Kumar, V. (2009). Anomaly detection: A survey. ACM Computing Surveys, 41(3).

Ayrıntılar

Birincil Dil

İngilizce

Konular

Bilgi Güvenliği Yönetimi

Bölüm

Araştırma Makalesi

Yayımlanma Tarihi

23 Ağustos 2026

Gönderilme Tarihi

25 Mayıs 2026

Kabul Tarihi

24 Haziran 2026

Yayımlandığı Sayı

Yıl 2026 Sayı: 35

Kaynak Göster

APA
Aslan, K., Özel, A., & Ceran, O. (2026). INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK. Denetişim, 35, 246-314. https://doi.org/10.58348/denetisim.1958605
AMA
1.Aslan K, Özel A, Ceran O. INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK. DENETİŞİM. 2026;(35):246-314. doi:10.58348/denetisim.1958605
Chicago
Aslan, Kübra, Azze Özel, ve Onur Ceran. 2026. “INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK”. Denetişim, sy 35: 246-314. https://doi.org/10.58348/denetisim.1958605.
EndNote
Aslan K, Özel A, Ceran O (01 Ağustos 2026) INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK. Denetişim 35 246–314.
IEEE
[1]K. Aslan, A. Özel, ve O. Ceran, “INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK”, DENETİŞİM, sy 35, ss. 246–314, Ağu. 2026, doi: 10.58348/denetisim.1958605.
ISNAD
Aslan, Kübra - Özel, Azze - Ceran, Onur. “INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK”. Denetişim. 35 (01 Ağustos 2026): 246-314. https://doi.org/10.58348/denetisim.1958605.
JAMA
1.Aslan K, Özel A, Ceran O. INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK. DENETİŞİM. 2026;:246–314.
MLA
Aslan, Kübra, vd. “INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK”. Denetişim, sy 35, Ağustos 2026, ss. 246-14, doi:10.58348/denetisim.1958605.
Vancouver
1.Kübra Aslan, Azze Özel, Onur Ceran. INTEGRATING CONTINUOUS AUDITING INTO SOC OPERATIONS: AN AUDIT-DRIVEN THREAT MONITORING FRAMEWORK. DENETİŞİM. 01 Ağustos 2026;(35):246-314. doi:10.58348/denetisim.1958605

Denetişim dergisi yayımladığı çalışmalarla; alanındaki profesyoneller, akademisyenler ve düzenleyiciler arasında etkili bir iletişim ağı kurarak, Dünyada etkin bir denetim ve yönetim sistemine ulaşma yolculuğunda önemli mesafelerin kat edilmesine katkı sağlamaktadır.