Abstract

The growing use of artificial intelligence and generative AI in security operations centres  have the ability to improve alert triage, investigation, threat-intelligence enrichment,  and incident response. It also introduces governance risks including explainability, data  leakage, prompt injection, model lifecycle management, human oversight, and the  traceability of AI-assisted decisions. This study has developed a best-practice and risk assessment framework for the auditable integration of AI in UAE’s governmental SOCs.  The research follows a qualitative and practitioner-informed documentary analysis.  Publicly available UAE cybersecurity policies, internationally recognised NIST and  ISO/IEC standards, academic literature, industry guidance and compliance  publications were reviewed. Moreover, they were accompanied by nine professional  meetings, consultations and semi-structured interviews with SOC practitioners. The  evidence was analysed through control-evidence mapping, a five-level indicative  maturity assessment, structured risk assessment, and two theoretical SOC scenarios  representing normal operations and an AI-related incident.  The findings show a potential gap between national cybersecurity policy expectations  and publicly observable evidence of entity-level operationalisation. Audit and  accountability and incident response were assessed at Level 2, which shows that it is  developing but inconsistently documented practices. The three AI-related domains  (which are AI governance, AI incident response, and GenAI data governance) were  assessed at Level 1, showing limited publicly available evidence of formalised and  repeatable controls. The risk assessment was able to identify ten material risks, with  the most significant involving weak audit trails, the absence of formal AI governance  and the lack of an AI-specific incident-response playbook.  The study proposes a standards-aligned framework based on auditability, explainability,  policy alignment, and risk-based human oversight. The framework includes an analyst action logging schema, standardised incident-response procedures, an AI use-case  catalogue, defined accountability roles, AI-specific incident playbooks, a phased  implementation roadmap, and a compliance crosswalk. The framework gives a  structured approach for translating UAE, NIST and ISO/IEC requirements into practical  SOC governance controls. As the evaluation is documentary and scenario-based,  future research should validate the framework through implementation and control  testing within operational governmental SOC environments.

Publication Date

8-2026

Document Type

Thesis

Student Type

Graduate

Degree Name

Computer Science (MS)

Department, Program, or Center

Electrical Engineering

Advisor

Huda Saadeh

Campus

RIT Dubai

Share

COinS