Jul 2026· Computer Science & IT Research Journal· Vol 7, pp. 405-419· 0 citations
TL;DR
The methodology addresses log correlation, alert triage, incident classification and cross-functional escalation protocols and produces measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR) while reducing alert fatigue and redundant infrastructure costs.
Abstract
Enterprise IT infrastructure has grown increasingly complex, which places simultaneous demands on operations teams to maintain high availability and to defend against a growing array of cyber threats. Historically, uptime assurance and security monitoring have operated as discrete organizational functions with separate toolsets, personnel and objectives. This siloed approach creates operational blind spots that threat actors and system failures exploit with equal consequence. This article presents a structured methodology for integrating security monitoring into uptime assurance workflows within enterprise data center environments. Drawing on frameworks established by the National Institute of Standards and Technology (NIST), the Information Technology Infrastructure Library (ITIL) and peer-reviewed scholarship published between 2015 and 2025, the study identifies key convergence points between availability management and threat detection, proposes an integrated operational model and examines the organizational and technological prerequisites for sustainable implementation. The methodology addresses log correlation, alert triage, incident classification and cross-functional escalation protocols. The findings indicated that integration produces measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR) while reducing alert fatigue and redundant infrastructure costs. This article concludes with recommendations for enterprise IT leaders seeking to unify security and availability operations under a coherent governance structure.
Keywords: Uptime Assurance, Security Monitoring, Enterprise IT Infrastructure, IT Operations, Availability Management, Threat Detection, ITIL, NIST, Integrated Operations, Incident Response.
The proposed maturity model comprising Fragmented, Instrumented, Correlated, Automated, Automated, and Adaptive stages provides organizations with a practical roadmap for assessing current capabilities and systematically advancing toward intelligent, self-optimizing security operations.
Lakshmi Kiran Meesala· International Journal of Art...· 0 citations
This article develops a model that integrates real-time Security Operations Center (SOC) log analytics with continuous auditing processes and aims to bridge the technical gap between operational threat monitoring activities and the internal audit function. Although SOC units generate high volumes of data, including authentication records, network traffic, and endpoint activities, these data sources are not systematically used in internal audit activities. The developed structure treats real-time log streams as audit evidence for assessing control effectiveness, identifying risk indicators, and analyzing deviations. Within this scope, SOC rules, audit tests, and risk scenarios are linked within an integrated structure. Methodologically, the study is based on the Design Science Research (DSR) approach. To evaluate the feasibility of the model, a virtualized three-host SOC environment was designed and implemented. The model was tested through a proof-of-concept scenario based on privileged access activities occurring outside business hours. The findings indicate that log-level visibility reduces blind spots in internal audit, strengthens control design, and supports a proactive governance approach, particularly in sectors with high security requirements such as the defense industry.
Kübra Aslan, A. Özel, Onur Ceran· Denetişim· 0 citations
The rapid expansion of the life cycle for software deployment has required a move from traditional, manual security analysis to automated and integrated assurance frameworks. This study examines the effectiveness of integrating assurance, real-time threat detection, and automated certification gates right into the Continuous Integration and Continuous Deployment pipeline. The analysis is based on a synthetic dataset comprising values from 429 different builds, which is used to study the agreement between automated gating mechanisms and lower vulnerability escape rates. We used a standard tool chain consisting of Jenkins for orchestration, SonarQube for static analysis, and Splunk for log aggregation to emulate a high-velocity enterprise environment. The system seeks to reduce technical debt and potential security risks without impeding deployment velocity by enforcing stringent quality gates that prevent non-compliant artifacts from being promoted. The study highlights the quantitative effects of these controls on success build rates and on the exposure of hidden threats during staging. The results reveal that, despite an initial slowdown in delivery velocity, the incorporation of automated certification gates considerably reduces critical severity incident rates. Implications: The results indicate how to make system changes in response to data for those attempting to put DevSecOps into practice while maintaining the speed and integrity of their systems.
Sauhard Bhatt, Satyanarayana Gadiraju· 2026 6th International Confe...· 0 citations
The rapid digitisation of critical infrastructure has made traditional fragmented risk assessment practices increasingly challenging to scale. For global industrial leaders managing hundreds of diverse projects, there is a real need for a unified methodology that ensures technical rigour, cross-project reproducibility, and scalability. This paper introduces the Advanced Risk Assessment Methodology for Industrial Systems (ARAMIS), an innovative framework developed through a strategic partnership between Airbus Protect and Alstom. ARAMIS merges the structured, requirement-driven security levels of ISA/IEC 62443 with the scenario-based approach of Expression des Besoins et Identification des Objectifs de Sécurité Risk Manager (EBIOS RM). The paper details the five-module structure of ARAMIS, its unique multilayered modelling of operational scenarios and its algorithmic approach to calculating security levels target (SL-T). Finally, it discusses the implementation of the methodology within the Fence risk management tool to ensure seamless reproducibility and knowledge capitalisation across global project portfolios. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Serge Benoliel, Florence Foudrain· International Conference on...· 0 citations
Public administration software systems are increasingly adopting microservices architectures to achieve scalability, flexibility, and resilience. However, the complexity of distributed systems poses challenges to access authorization management. This study presents the SIARE-Artefactos solution, which is designed to automate the registration and authorization of resources within Paraguay’s Integrated State Resource Management System (SIARE). SIARE-Artefactos leverages OAuth 2.0 and Spring Boot Starter to ensure secure and efficient authorization processes. SIARE-Artefactos leverages OAuth 2.0 and Spring Boot Starter to ensure secure and efficient authorization processes. SIARE-Artefactos has been implemented and used by public employees in Paraguay, enabling validation with real users. For the validation we adopted a mixed-methods, combining quantitative with qualitative sources, and a longitudinal observational design. The convergence of evidence allowed us to correlate the objective reduction in deployment times (from minutes to seconds) with the subjective perception of 'system predictability' reported by the DevOps team. Validation of the proposal demonstrates the solution's replicability to other cases with similar challenges and resources, as well as its ability to significantly improve system reliability and reduce configuration time by 74%. This highlights its potential to transform large-scale public administration systems using modern DevOps practices and agile methodologies.
Security Information and Event Management (SIEM) systems are a key part of modern cybersecurity operations, especially in government settings where they are responsible for protecting sensitive data and making sure that important national services keep running. Even though traditional SIEM platforms are used a lot, they mostly use rule-based detection methods and manual incident response workflows. This makes it take longer to contain threats and keeps the false positive rate high. This paper systematically analyzes the operational difficulties encountered during SIEM implementations at the General Administration of Government Computer (GAGC) and the Palestinian Computer Emergency Response Team (PALCERT), both functioning under the Ministry of Telecommunications and Information Technology in Palestine. A mixed-methods research methodology—incorporating semi-structured expert interviews, focus group discussions, structured surveys, and quantitative log analysis—is utilized to assess current operational constraints and system limitations. Based on these results, we suggest a better AI-driven SIEM framework that combines machine learning-based threat detection with an automated incident response layer that follows security playbooks that have already been set up. Experimental assessment utilizing simulated cyberattack scenarios indicates statistically significant enhancements: detection accuracy rose from 79.1% to 91.5%, the false positive rate diminished from 32.4% to 20.2%, and the average incident response time decreased from 18.7 to 11.0 minutes, reflecting a 41% reduction. These results show that adding AI and automation to SIEM operations can make national cybersecurity much stronger, make analysts less tired, and make government digital infrastructure more resilient overall.
Mohammed AbuTaha· Journal of Intelligent Decis...· 0 citations