Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
In-house SOC or SOCaaS in the Swedish Public Sector: Investigation of the factors influencing the choice of Security Operations Center in the Swedish public sector
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
2025 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

In recent years there has been a significant increase in cyberthreats for a multitude of reasons. Many organizations have therefore decided to employ a Security Operations Center (SOC) to strengthen their security work. Employing a SOC allows for monitoring, detection, and responses to different cyberthreats aimed at them. The public sector is one of the most important sectors in society due to its impact on the public, which has led to it being the target of many malicious attacks. The need for SOC in this sector is therefore crucial, but because of the many unique laws it abides by, it may be difficult to make an informed decision that will not be regretted. 

This study aims to analyze and compare the different implementations of SOC that being in-house, hybrid, and SOCaaS and highlight the main benefits and challenges of each approach. It also aims to present the primary factors that have an influence on which implementations may be preferred for different organizations in the public sector. Understanding these allowed a framework to be developed that aimed to assist organizations within Sweden’s public sector in their decision-making process. 

The data needed to understand these factors was collected using semi-structured interviews with ten participants from six organizations within Sweden's public sector. The participants were either security experts directly working in a security team or in a management position overseeing it. The interviews examined what current implementation they used, along with the different factors that influenced their choice. To analyze the data collected, a thematic analysis was used featuring an abductive approach to reasoning. This allowed for comparisons to past research, along with discoveries of new theories based on insights provided by the participants. 

The results provided by our chosen research method showcased a variety of factors that were shown to have an influence on what implementation may be preferred given different circumstances. The factors that were the most impactful were the need for continuous monitoring, strong competence, and abiding by legal and regulatory requirements. Reasons for this include the difficulty of achieving 24/7 monitoring internally because most organizations operate during regular office hours. Finding the necessary competence to uphold a SOC is also difficult because of the resources and time required. In the public sector, abiding to laws and regulations also play a key role, due to them ensuring that sufficient security is in place to protect critical services and sensitive information. 

Place, publisher, year, edition, pages
2025. , p. 80
Keywords [en]
Cybersecurity, In-house SOC, Outsourcing, Public Sector, Security Operations Center (SOC), SOC-as-a-Service (SOCaaS), SOC decision-making.
National Category
Information Systems
Identifiers
URN: urn:nbn:se:hj:diva-68760OAI: oai:DiVA.org:hj-68760DiVA, id: diva2:1972983
Subject / course
JTH, Informatics
Supervisors
Examiners
Available from: 2025-06-19 Created: 2025-06-19 Last updated: 2025-10-13Bibliographically approved

Open Access in DiVA

fulltext(1471 kB)278 downloads
File information
File name FULLTEXT01.pdfFile size 1471 kBChecksum SHA-512
62e73f4d5e9495755908e9909d6f3099864d38e75073a5986dcc75b20af3579e8d30a759147a5e30cd26c3da8b68045dd46d9f7994f143619300036665e3a56f
Type fulltextMimetype application/pdf

By organisation
JTH, Department of Computer Science and Informatics
Information Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 280 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 736 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf