Indonesian Journal of Electrical Engineering and Computer Science
Vol 42, No 2: May 2026

A structured process model to optimize detection capabilities in security operations centers (SOCs)

Adi Nugroho (Swiss German University)
Charles Lim (Swiss German University)
Heru Purnomo Ipung (Swiss German University)



Article Info

Publish Date
10 May 2026

Abstract

The security operations center (SOC) is essential for protecting organizational assets and maintaining operational continuity against rapidly changing cyber threats. Despite its significance, numerous SOCs establish detection capabilities lacking of a systematic framework, frequently culminating in inefficiencies and constrained efficacy. This paper presents a process model aimed at improving SOC detection capabilities by aligning them with business objectives, pertinent risks, and the evolving character of contemporary threats. The study includes an evaluation of current detection methodologies, utilizing the MITRE ATT&CK architecture and threat intelligence data to pinpoint relevant risks and detection deficiencies. A case study was performed at the XYZ Organization to evaluate current detection capabilities and implement the recommended process model. The model was validated through interviews with experts in the SOC field, verifying the findings' credibility. The findings demonstrate that the model efficiently helps SOC in synchronizing detection methods with organizational objectives, prioritizing pertinent threats, and promoting the enhancement of more targeted and adaptable detection capabilities. This research provides theoretical insights into SOC detection modeling and practical assistance for enterprises aiming to enhance their cybersecurity operations.

Copyrights © 2026