{"id":{"repo_id":"cape-town","oai_identifier":"oai:open.uct.ac.za:11427/42557"},"canonical_url":"https://search.dev.ndltd.org/etd/cape-town/oai:open.uct.ac.za:11427/42557","repository":{"repo_id":"cape-town","name":"University of Cape Town","base_url":"https://open.uct.ac.za/oai/request"},"display":{"title":"A conceptual model for digital forensic readiness in security operation centres: a South African study","abstract":"The increase in the adoption of technology has resulted in the number of cyber-attacks and security breaches also rising. These cyber-attacks and breaches have become advanced and can go undetected for months. With the rise in cyber-attacks, the need for organizations to tighten cybersecurity measures and be ready to investigate the breaches speedily has become crucial. These measures include the adoption of Security Operations Centres (SOC) that integrate digital forensic capabilities with various cybersecurity tools. The reviewed literature shows that having a well-defined digital forensic readiness (DFR) strategy in place is important to ensure quick and efficient investigations that do not have a huge impact on the organization. In addition, conducting internal investigations helps an organization reduce costs. While there are proposed frameworks that aim to help an organization become forensically ready, none have a specific focus on a SOC. SOCs are complex, making conducting a digital forensic investigation challenging. The objective of this study was to develop a conceptual model for DFR that focused on SOCs in South Africa. To achieve this, the study first analysed existing DFR frameworks and drew key factors that were common in all frameworks. Management support, policies, processes and procedures, forensic technologies, legal frameworks, technical skills, and training were identified as the key factors that have a potential influence on the forensic readiness of a SOC. The study was conducted using a quantitative research approach and a survey questionnaire. Data were collected from professionals who work in organizations running a SOC in South Africa through a survey. The data were analysed using statistical methods and the results of the study indicate that the digital forensic readiness of a SOC is dependent on management support, organizational policies, processes and procedures, the integration of forensic and cybersecurity technologies, understanding various legal requirements, technical skills, and continuous training. All participants had at least one form of formal qualification and one industry-related certificate. The proposed DFR conceptual model examined various factors that SOCs can use to assess their forensic readiness. The findings also highlight the importance of having a holistic approach to forensic readiness which also include continuous investment in both technology and technical skills to keep up with evolving technology. Furthermore, the findings can be used by SOCs to identify areas in their DFR plan they need to focus on to enhance their cyber-resilience.","abstract_html":"The increase in the adoption of technology has resulted in the number of cyber-attacks and security breaches also rising. These cyber-attacks and breaches have become advanced and can go undetected for months. With the rise in cyber-attacks, the need for organizations to tighten cybersecurity measures and be ready to investigate the breaches speedily has become crucial. These measures include the adoption of Security Operations Centres (SOC) that integrate digital forensic capabilities with various cybersecurity tools. The reviewed literature shows that having a well-defined digital forensic readiness (DFR) strategy in place is important to ensure quick and efficient investigations that do not have a huge impact on the organization. In addition, conducting internal investigations helps an organization reduce costs. While there are proposed frameworks that aim to help an organization become forensically ready, none have a specific focus on a SOC. SOCs are complex, making conducting a digital forensic investigation challenging. The objective of this study was to develop a conceptual model for DFR that focused on SOCs in South Africa. To achieve this, the study first analysed existing DFR frameworks and drew key factors that were common in all frameworks. Management support, policies, processes and procedures, forensic technologies, legal frameworks, technical skills, and training were identified as the key factors that have a potential influence on the forensic readiness of a SOC. The study was conducted using a quantitative research approach and a survey questionnaire. Data were collected from professionals who work in organizations running a SOC in South Africa through a survey. The data were analysed using statistical methods and the results of the study indicate that the digital forensic readiness of a SOC is dependent on management support, organizational policies, processes and procedures, the integration of forensic and cybersecurity technologies, understanding various legal requirements, technical skills, and continuous training. All participants had at least one form of formal qualification and one industry-related certificate. The proposed DFR conceptual model examined various factors that SOCs can use to assess their forensic readiness. The findings also highlight the importance of having a holistic approach to forensic readiness which also include continuous investment in both technology and technical skills to keep up with evolving technology. Furthermore, the findings can be used by SOCs to identify areas in their DFR plan they need to focus on to enhance their cyber-resilience.","abstract_has_math":false,"creators":["Nkwe, Boitumelo"],"institution":"Department of Information Systems","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":null,"school":null,"contributors":[],"advisors":["Kyobe, Michael"],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025","date_published":"2025","updated_at":"2026-07-22T22:23:06Z","subjects":["Security operations centre","digital forensic readiness","conceptual models"],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/11427/42557","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Kyobe, Michael"]},{"key":"dc:creator","label":"Author","values":["Nkwe, Boitumelo"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2026-01-13T09:15:34Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2026-01-13T09:15:34Z"]},{"key":"dc:date.issued","label":"Date","values":["2025"]},{"key":"dc:publisher.department","label":"Dc Publisher Department","values":["Department of Information Systems"]},{"key":"dc:publisher.institution","label":"Dc Publisher Institution","values":["University of Cape Town"]},{"key":"dc:type","label":"Dc Type","values":["Thesis / Dissertation"]},{"key":"dc:type.qualificationlevel","label":"Dc Type Qualificationlevel","values":["Masters","MCom"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Security operations centre","digital forensic readiness","conceptual models"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/11427/42557"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["The increase in the adoption of technology has resulted in the number of cyber-attacks and security breaches also rising. These cyber-attacks and breaches have become advanced and can go undetected for months. With the rise in cyber-attacks, the need for organizations to tighten cybersecurity measures and be ready to investigate the breaches speedily has become crucial. These measures include the adoption of Security Operations Centres (SOC) that integrate digital forensic capabilities with various cybersecurity tools. The reviewed literature shows that having a well-defined digital forensic readiness (DFR) strategy in place is important to ensure quick and efficient investigations that do not have a huge impact on the organization. In addition, conducting internal investigations helps an organization reduce costs. While there are proposed frameworks that aim to help an organization become forensically ready, none have a specific focus on a SOC. SOCs are complex, making conducting a digital forensic investigation challenging. The objective of this study was to develop a conceptual model for DFR that focused on SOCs in South Africa. To achieve this, the study first analysed existing DFR frameworks and drew key factors that were common in all frameworks. Management support, policies, processes and procedures, forensic technologies, legal frameworks, technical skills, and training were identified as the key factors that have a potential influence on the forensic readiness of a SOC. The study was conducted using a quantitative research approach and a survey questionnaire. Data were collected from professionals who work in organizations running a SOC in South Africa through a survey. The data were analysed using statistical methods and the results of the study indicate that the digital forensic readiness of a SOC is dependent on management support, organizational policies, processes and procedures, the integration of forensic and cybersecurity technologies, understanding various legal requirements, technical skills, and continuous training. All participants had at least one form of formal qualification and one industry-related certificate. The proposed DFR conceptual model examined various factors that SOCs can use to assess their forensic readiness. The findings also highlight the importance of having a holistic approach to forensic readiness which also include continuous investment in both technology and technical skills to keep up with evolving technology. Furthermore, the findings can be used by SOCs to identify areas in their DFR plan they need to focus on to enhance their cyber-resilience."]},{"key":"dc:title","label":"Title","values":["A conceptual model for digital forensic readiness in security operation centres: a South African study"]}]}],"canonical_facts":{"dc:contributor.advisor":["Kyobe, Michael"],"dc:creator":["Nkwe, Boitumelo"],"dc:date.accessioned":["2026-01-13T09:15:34Z"],"dc:date.available":["2026-01-13T09:15:34Z"],"dc:date.issued":["2025"],"dc:description.abstract":["The increase in the adoption of technology has resulted in the number of cyber-attacks and security breaches also rising. These cyber-attacks and breaches have become advanced and can go undetected for months. With the rise in cyber-attacks, the need for organizations to tighten cybersecurity measures and be ready to investigate the breaches speedily has become crucial. These measures include the adoption of Security Operations Centres (SOC) that integrate digital forensic capabilities with various cybersecurity tools. The reviewed literature shows that having a well-defined digital forensic readiness (DFR) strategy in place is important to ensure quick and efficient investigations that do not have a huge impact on the organization. In addition, conducting internal investigations helps an organization reduce costs. While there are proposed frameworks that aim to help an organization become forensically ready, none have a specific focus on a SOC. SOCs are complex, making conducting a digital forensic investigation challenging. The objective of this study was to develop a conceptual model for DFR that focused on SOCs in South Africa. To achieve this, the study first analysed existing DFR frameworks and drew key factors that were common in all frameworks. Management support, policies, processes and procedures, forensic technologies, legal frameworks, technical skills, and training were identified as the key factors that have a potential influence on the forensic readiness of a SOC. The study was conducted using a quantitative research approach and a survey questionnaire. Data were collected from professionals who work in organizations running a SOC in South Africa through a survey. The data were analysed using statistical methods and the results of the study indicate that the digital forensic readiness of a SOC is dependent on management support, organizational policies, processes and procedures, the integration of forensic and cybersecurity technologies, understanding various legal requirements, technical skills, and continuous training. All participants had at least one form of formal qualification and one industry-related certificate. The proposed DFR conceptual model examined various factors that SOCs can use to assess their forensic readiness. The findings also highlight the importance of having a holistic approach to forensic readiness which also include continuous investment in both technology and technical skills to keep up with evolving technology. Furthermore, the findings can be used by SOCs to identify areas in their DFR plan they need to focus on to enhance their cyber-resilience."],"dc:identifier.uri":["http://hdl.handle.net/11427/42557"],"dc:language.iso":["en"],"dc:publisher.department":["Department of Information Systems"],"dc:publisher.institution":["University of Cape Town"],"dc:subject":["Security operations centre","digital forensic readiness","conceptual models"],"dc:title":["A conceptual model for digital forensic readiness in security operation centres: a South African study"],"dc:type":["Thesis / Dissertation"],"dc:type.qualificationlevel":["Masters","MCom"]},"updated_at":"2026-07-22T22:23:06Z"}