Agentic AI-Driven SOC-as-a-Service for Optimizing Incident Response in Cloud Environments: A Conceptual Framework
Abdulaziz Y. Alhumaidi, Faisal A. Al-Qadda, Albandari Alsumayt, Majid AlshammariCloud security operations must process high-volume, rapidly changing telemetry within short response windows while maintaining governance and accountability. However, the literature on cloud defense, SOC modernization, retrieval-augmented generation (RAG), and Agentic AI remains fragmented. This paper combines a legacy corpus of 23 studies with a reproducible Scopus update of 10 quality-appraised studies and proposes a secure Agentic AI-driven SOC-as-a-Service (SOCaaS) framework. The review identifies long-standing problems of alert fatigue, limited operational context, fragmented tooling, and weak validation, together with unresolved concerns regarding trust, explainability, bounded autonomy, forensic preparedness, and prompt injection. The principal technical contribution is a six-layer architecture supported by a cross-cutting security and trust-enforcement plane that separates untrusted telemetry from agent instructions, constrains retrieval and tool use, applies deterministic governance checks, requires human approval for high-impact actions, and enables auditable execution. Four simulation experiments evaluate component-level behavior for automated triage, retrieval grounding, governance-gated orchestration, and audit completeness. Under the stated synthetic assumptions, the governed agentic configuration yields a 6.8-fold reduction in mean response time relative to the modeled manual baseline. These results indicate internal feasibility rather than production efficacy.