Abstract
The growing use of artificial intelligence and generative AI in security operations centres have the ability to improve alert triage, investigation, threat-intelligence enrichment, and incident response. It also introduces governance risks including explainability, data leakage, prompt injection, model lifecycle management, human oversight, and the traceability of AI-assisted decisions. This study has developed a best-practice and risk assessment framework for the auditable integration of AI in UAE’s governmental SOCs. The research follows a qualitative and practitioner-informed documentary analysis. Publicly available UAE cybersecurity policies, internationally recognised NIST and ISO/IEC standards, academic literature, industry guidance and compliance publications were reviewed. Moreover, they were accompanied by nine professional meetings, consultations and semi-structured interviews with SOC practitioners. The evidence was analysed through control-evidence mapping, a five-level indicative maturity assessment, structured risk assessment, and two theoretical SOC scenarios representing normal operations and an AI-related incident. The findings show a potential gap between national cybersecurity policy expectations and publicly observable evidence of entity-level operationalisation. Audit and accountability and incident response were assessed at Level 2, which shows that it is developing but inconsistently documented practices. The three AI-related domains (which are AI governance, AI incident response, and GenAI data governance) were assessed at Level 1, showing limited publicly available evidence of formalised and repeatable controls. The risk assessment was able to identify ten material risks, with the most significant involving weak audit trails, the absence of formal AI governance and the lack of an AI-specific incident-response playbook. The study proposes a standards-aligned framework based on auditability, explainability, policy alignment, and risk-based human oversight. The framework includes an analyst action logging schema, standardised incident-response procedures, an AI use-case catalogue, defined accountability roles, AI-specific incident playbooks, a phased implementation roadmap, and a compliance crosswalk. The framework gives a structured approach for translating UAE, NIST and ISO/IEC requirements into practical SOC governance controls. As the evaluation is documentary and scenario-based, future research should validate the framework through implementation and control testing within operational governmental SOC environments.
Publication Date
8-2026
Document Type
Thesis
Student Type
Graduate
Degree Name
Computer Science (MS)
Department, Program, or Center
Electrical Engineering
Advisor
Huda Saadeh
Recommended Citation
Alrazooqi, Nasser Hassan Nasser Abdulrazaq, "A Best-Practice and Risk-Assessment Framework for Auditable AI Integration in UAE Government SOCs" (2026). Thesis. Rochester Institute of Technology. Accessed from
https://repository.rit.edu/theses/12783
Campus
RIT Dubai
