跳到主要內容

簡易檢索 / 詳目顯示

研究生: 陳貫翔
Chen, Kuan-Hsiang
論文名稱: 從遊戲學視角探討支援資安作業導入 SOAR 所需的前置準備
A Ludology Perspective on Preparations Required to Support SOAR Adoption in Security Operations
指導教授: 周致遠
Chou, Chih-Yuan
口試委員: 歐素華
Ou, Su-Hua
曾筱珽
Tseng, Hsiao-Ting
學位類別: 碩士
Master
系所名稱: 商學院 - 資訊管理學系
Department of Management Information System
論文出版年: 2026
畢業學年度: 114
語文別: 英文
論文頁數: 69
中文關鍵詞: SOARSIEM遊戲研究安全協調自動化
外文關鍵詞: SOAR, SIEM, Ludology, Security Orchestration, Automation
相關次數: 點閱:13下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 隨著資安事件數量與複雜度持續增加,組織逐漸導入安全、協調、自動化和回應(security orchestration, automation, and response, SOAR)以提升資安營運效率。然而,現有 SOAR 研究多聚焦於技術能力與系統架構,較少探討組織在導入前所需進行的準備工作。因此,本研究以臺灣某金融機構為個案,探討組織在以安全資訊與事件管理(security information and event management, SIEM)為核心的資安作業環境中,如何為未來導入 SOAR 進行準備。本研究採用質性個案研究方法,透過半結構式訪談、參與式觀察及文件分析蒐集資料,並以 Gioia 分析法進行分析。理論上,本研究引入遊戲學作為分析視角,將組織中的資安作業理解為由規則、行動者與能動性、工具與可供性,以及回饋四個構面所組成之互動系統。研究結果顯示,SOAR 導入不僅涉及技術能力建置,更涉及決策邏輯明確化、權責配置、工具能力發展與組織學習等議題。本研究進一步提出一個以遊戲學為基礎之概念模型,說明組織如何透過規則建立、能動性重新分配、工具能力發展及回饋循環,逐步完成 SOAR 導入準備。本研究除補充現有 SOAR 文獻較少討論之組織面向外,亦提供實務界規劃資安自動化導入之參考。


    As cybersecurity threats continue to grow in scale and complexity, organizations are increasingly adopting security orchestration, automation, and response (SOAR) to improve the efficiency of security operations. Existing SOAR studies primarily focus on technical capabilities and system architectures, while relatively little attention has been paid to the organizational preparations required before implementation. This study examines how organizations prepare for SOAR adoption within SIEM-centered security operations. A qualitative case study was conducted in a Taiwanese financial institution. Data were collected through semi-structured interviews, participant observation, and document analysis, and were analyzed using the Gioia methodology. The study adopts a ludology perspective, conceptualizing cybersecurity operations as an interactive system consisting of rules, actors and agency, tools and affordances, and feedback loops. The findings show that SOAR adoption involves not only technological deployment but also the development of decision rules, authority allocation, tool capabilities, and organizational learning mechanisms. Based on these findings, a ludology-based conceptual model was developed to explain how organizations prepare for SOAR adoption through rule formation, agency redistribution, capability development, and feedback-driven learning. The study contributes to the SOAR literature by extending attention beyond technical implementation toward organizational preparation and offers insights into how organizations approach cybersecurity automation initiatives.

    CHAPTER 1 INTRODUCTION 1
    CHAPTER 2 CONCEPTUAL BACKGROUND 6
    2.1 Documentation and Institutionalization 6
    2.2 Socio-Relational Perspectives 8
    2.3 Ludology 10
    2.3.1 Rules 12
    2.3.2 Actors and agency 13
    2.3.3 Tools and affordances 13
    2.3.4 Feedback loops 14
    CHAPTER 3 RESEARCH METHODOLOGY 17
    3.1 Research Approach 17
    3.2 Data Collection 19
    3.3 Data Analysis 23
    CHAPTER 4 CASE BACKGROUND 29
    CHAPTER 5 ANALYSIS AND FINDINGS 33
    5.1 Rules 33
    5.1.1 Making Decision Logic Explicit 33
    5.1.2 Managing Exceptions and Human Discretion 34
    5.1.3 Accountability Concerns in Decision-Making 35
    5.2 Actors and agency 37
    5.2.1 Professional Experience and Contextual Knowledge in Incident Judgement 37
    5.2.2 Decision Authority under Hierarchical Permission Structures 38
    5.2.3 Organizational Adoption and Continued Use Intention 39
    5.3 Tools and Affordance 41
    5.3.1 AI as a Supportive Analytical Tool 41
    5.3.2 Constraints on Automation Capability 41
    5.3.3 Cross-System Support for Incident Analysis 43
    5.3.4 Expectations for Expanded Automation Capability 43
    5.4 Feedback Loops 45
    5.4.1 Documentation and Accumulation of Operational Knowledge 45
    5.4.2 Continuous Process Optimization and Adjustment 46
    5.4.3 Building Shared Risk Awareness 47
    5.4.4 Transfer of Tacit Knowledge and Experience 48
    CHAPTER 6 DISCUSSION 50
    6.1 Ludology Lens to Finding 51
    6.2 Theoretical Contribution 54
    6.3 Practical Contribution 56
    CHAPTER 7 CONCLUSION 58
    7.1 Concluding Remarks 58
    7.2 Limitation and Future Research Direction 59
    REFERENCES 61

    Afroogh, S., Akbari, A., Malone, E., Kargar, M., & Alambeigi, H. (2024). Trust in AI: Progress, challenges, and future directions. Humanities and Social Sciences Communications, 11, Article 1568. https://doi.org/10.1057/s41599-024-04044-8
    Ahimbisibwe, B. K., & Nabende, P. (2023). The institutionalisation of information security management practices in selected organisations in Uganda. International Journal of Advanced Research, 6(1), 48–63. https://doi.org/10.37284/ijar.6.1.1155
    Alavi, R., Islam, S., & Mouratidis, H. (2014). A conceptual framework to analyze human factors of information security management system (ISMS) in organizations. Human aspects of information security, privacy, and trust, 297–305. https://doi.org/10.1007/978-3-319-07620-1_26
    AlGhamdi, S., Win, K. T., & Vlahu-Gjorgievska, E. (2020). Information security governance challenges and critical success factors: Systematic review. Computers & Security, 99, Article 102030. https://doi.org/10.1016/j.cose.2020.102030
    Ali, O., Murray, P. A., Muhammed, S., Dwivedi, Y. K., & Rashiti, S. (2022). Evaluating organizational level IT innovation adoption factors among global firms. Journal of Innovation & Knowledge, 7(3), Article 100213. https://doi.org/10.1016/j.jik.2022.100213
    Arghire, I. (2025). CISA releases guidance on SIEM and SOAR implementation. SecurityWeek. https://www.securityweek.com/cisa-releases-guidance-on-siem-and-soar-implementation/
    Australian Cyber Security Centre. (2025). Implementing SIEM and SOAR platforms: Practitioner guidance, Australian Signals Directorate. https://www.cyber.gov.au/business-government/detecting-responding-to-threats/event-logging/implementing-siem-soar-platforms/practitioner-guidance
    Awa, H. O., Etim, W., & Ogbonda, E. (2024). Stakeholders, stakeholder theory and corporate social responsibility (CSR). International Journal of Corporate Social Responsibility, 9, Article 11. https://doi.org/10.1186/s40991-024-00094-y
    Bada, M., & Nurse, J. R. (2019). Developing cybersecurity education and awareness programmes for small-and medium-sized enterprises (SMEs). Information & Computer Security, 27(3), 393–410. https://doi.org/10.1108/ICS-07-2018-0080
    Batewela, S., Ranaweera, P., Liyanage, M., Zeydan, E., & Ylianttila, M. (2025). Addressing security orchestration challenges in next-generation networks: A comprehensive overview. IEEE Open Journal of the Computer Society, 6, 669–687.
    https://doi.org/10.1109/OJCS.2025.3564788
    Benzar, A., Kovalenko, Y. O., Taranenko, A., Balynska, O., & Balynskyi, I. (2025). Organizational context of security management: Implications for information systems. Management (Montevideo), 3, 250. https://doi.org/10.62486/agma2025250
    Böhm, F., Vielberth, M., & Pernul, G. (2022). Formalizing and integrating user knowledge into security analytics. SN Computer Science, 3(5), Article 347.
    https://doi.org/10.1007/s42979-022-01209-7
    Bridges, R. A., Rice, A. E., Oesch, S., Nichols, J. A., Watson, C., Spakes, K., Norem, S., Huettel, M., Jewell, B., Weber, B., Gannon, C., Bizovi, O., Hollifield, S. C., & Erwin, S. (2023). Testing SOAR tools in use. Computers & Security, 129, Article 103201. https://doi.org/10.1016/j.cose.2023.103201
    Caillois, R. (2001). Man, play, and games (M. Barash, Trans.). University of Illinois Press.
    Chng, S., Lu, H. Y., Kumar, A., & Yau, D. (2022). Hacker types, motivations and strategies: A comprehensive framework. Computers in Human Behavior Reports, 5, Article 100167. https://doi.org/10.1016/j.chbr.2022.100167
    Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide (NIST Special Publication 800-61 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r2
    De Smet, D., & Mayer, N. (2016). Integration of IT governance and security risk management: A systematic literature review. 2016 International Conference on Information Society (i-Society), 143–148. https://doi.org/10.1109/i-Society.2016.7854200
    Di Giulio, M., & Vecchi, G. (2023). How “institutionalization” can work. Structuring governance for digital transformation in Italy. Review of Policy Research, 40(3), 406–432. https://doi.org/10.1111/ropr.12488
    Dubé, L., & Paré, G. (2003). Rigor in information systems positivist case research: Current practices, trends, and recommendations. MIS Quarterly, 27(4), 597–636. https://doi.org/10.2307/30036550
    Dupont, B. (2019). The cyber-resilience of financial institutions: Significance and applicability. Journal of Cybersecurity, 5(1), Article tyz013. https://doi.org/10.1093/cybsec/tyz013
    Emerson, R. M., Fretz, R. I., & Shaw, L. L. (2011). Writing ethnographic fieldnotes. University of Chicago Press.
    https://press.uchicago.edu/ucp/books/book/chicago/W/bo12182616.html
    Financial Supervisory Commission R.O.C. (2024). Reference guidelines for the implementation of zero trust architecture in the financial industry. Financial Supervisory Commission R.O.C..
    https://www.fsc.gov.tw/ch/home.jsp?id=96&parentpath=0,2&mcustomize=news_view.jsp&dataserno=202407180002&dtable=News
    Frasca, G. (2003). Ludologists love stories, too: Notes from a debate that never took place. Proceedings of DiGRA 2003 Conference: Level Up, 93–99. DiGRA.
    https://doi.org/10.26503/dl.v2003i1.64
    Garris, R., Ahlers, R., & Driskell, J. E. (2002). Games, motivation, and learning: A research and practice model. Simulation & Gaming, 33(4), 441–467.
    https://doi.org/10.4324/9781315243092-25
    Gioia, D. A., Corley, K. G., & Hamilton, A. L. (2013). Seeking qualitative rigor in inductive research: Notes on the Gioia methodology. Organizational Research Methods, 16(1), 15–31. https://doi.org/10.1177/1094428112452151
    Global Taiwan Institute. (2024, March). The nexus of cybersecurity and national security: Taiwan’s imperatives amidst escalating cyber threats. Global Taiwan Institute. https://globaltaiwan.org/2024/03/the-nexus-of-cybersecurity-and-national-security-taiwans-imperatives-amidst-escalating-cyber-threats/
    Global Taiwan Institute. (2025, July). Advancing cyber resilience: Taiwan’s strategic shift in the seventh phase of its national cybersecurity program. Global Taiwan Institute. https://globaltaiwan.org/2025/07/advancing-cyber-resilience-taiwans-strategic-shift/
    Hoff, K. A., & Bashir, M. (2015). Trust in automation: Integrating empirical evidence on factors that influence trust. Human Factors, 57(3), 407–434.
    https://doi.org/10.1177/0018720814547570
    Hohan, A. I., Olaru, M., & Pirnea, I. C. (2015). Assessment and continuous improvement of information security based on TQM and business excellence principles. Procedia Economics and Finance, 32, 352–359. https://doi.org/10.1016/S2212-5671(15)01404-5
    Hong, M. J. (2024). Research on management mechanisms of cross-departmental collaboration in solving complex public problems. Open Journal of Social Sciences, 12(12), 483–493. https://doi.org/10.4236/jss.2024.1212032
    Hunicke, R., LeBlanc, M., & Zubek, R. (2004, July). MDA: A formal approach to game design and game research. Proceedings of the AAAI Workshop on Challenges in Game AI, 4(1), Article 1722.
    https://cdn.aaai.org/Workshops/2004/WS-04-04/WS04-04-001.pdf
    Itani, D., Itani, R., Eltweri, A. A., Faccia, A., & Wanganoo, L. (2024, February). Enhancing cybersecurity through compliance and auditing: a strategic approach to resilience. 2024 2nd International Conference on Cyber Resilience (ICCR), 1–10. https://doi.org/10.1109/ICCR61006.2024.10532959
    Järvinen, A. (2007, January). Introducing applied ludology: Hands-on methods for game studies. Proceedings of DiGRA 2007 Conference: Situated Play, 134–144. https://doi.org/10.26503/dl.v2007i1.280
    Kent, K., & Souppaya, M. (2006). Guide to computer security log management (NIST SP 800–92). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-92
    Kramer, F. D., Yu, P. W., Webster, J., & Sizeland, E. (2024). Strengthening Taiwan’s resiliency. Atlantic Council. https://www.atlanticcouncil.org/in-depth-research-reports/report/strengthening-taiwans-resiliency/
    Kremer, R., Wudali, P. N., Momiyama, S., Araki, T., Furukawa, J., Elovici, Y., & Shabtai, A. (2023). IC-SECURE: Intelligent system for assisting security experts in generating playbooks for automated incident response. arXiv. https://doi.org/10.48550/arXiv.2311.03825
    Lahusen, C., Maggetti, M., & Slavkovik, M. (2024). Trust, trustworthiness and AI governance. Scientific Reports, 14(1), Article 20752. https://doi.org/10.1038/s41598-024-71761-0
    Linderoth, J. (2013). Beyond the digital divide: An ecological approach to gameplay. Transactions of the Digital Games Research Association, 1(1), 1–17. https://doi.org/10.26503/todigra.v1i1.9
    Lokuge, S., Sedera, D., Grover, V., & Dongming, X. (2019). Organizational readiness for digital innovation: Development and empirical calibration of a construct. Information & Management, 56(3), 445–461. https://doi.org/10.1016/j.im.2018.09.001
    Luo, Z.-H. (2024, November 7). Financial Fast-ID Verification Hub to Launch Next June, 20 Pilot Institutions Expected. IThome. https://www.ithome.com.tw/news/165876
    Magnusson, L., Iqbal, S., Elm, P., & Dalipi, F. (2025). Information security governance in the public sector: investigations, approaches, measures, and trends. International Journal of Information Security, 24(4), Article 177. https://doi.org/10.1007/s10207-025-01097-x
    Masilela, L., & Nel, D. (2021). The role of data and information security governance in protecting public sector data and information assets in national government in South Africa. Africa’s Public Service Delivery and Performance Review, 9(1), 385. https://doi.org/10.4102/apsdpr.v9i1.385
    Nacke, L. E., & Lindley, C. A. (2010). Affective ludology, flow and immersion in a first-person shooter: Measurement of player experience. The Journal of the Canadian Game Studies Association, 3(5), 1–21. https://doi.org/10.48550/arXiv.1004.0248
    Nicolini, D. (2012). Practice theory, work, and organization: An introduction. OUP Oxford.
    Parasuraman, R., Sheridan, T. B., & Wickens, C. D. (2000). A model for types and levels of human interaction with automation. IEEE Transactions on systems, man, and cybernetics-Part A: Systems and Humans, 30(3), 286–297. https://doi.org/10.1109/3468.844354
    Pawar, S., & Palivela, H. (2022). LCCI: A framework for least cybersecurity controls to be implemented for small and medium enterprises (SMEs). International Journal of Information Management Data Insights, 2(1), Article 100080.
    https://doi.org/10.1016/j.jjimei.2022.100080
    Police Broadcasting Service, National Police Agency, Ministry of the Interior, Republic of China (Taiwan) (2023). "Eagle Eye Anti-Fraud Alliance" Officially Established: CIB Partners with Financial Industry to Combat Fraud, Using AI to Identify High-Risk Accounts for Proactive Prevention, Police Broadcasting Service, National Police Agency, Ministry of the Interior, Republic of China (Taiwan).
    https://www.pbs.npa.gov.tw/ch/app/data/view?module=wg183&id=18740&serno=1bc4ca26-31f8-4343-8482-53e22201978f
    Pratt, M. G. (2009). From the editors: For the lack of a boilerplate: Tips on writing up (and reviewing) qualitative research. Academy of Management Journal, 52(5), 856–862. https://doi.org/10.5465/amj.2009.44632557
    Qu, S. Q., & Dumay, J. (2011). The qualitative research interview. Qualitative Research in Accounting & Management, 8(3), 238–264. https://doi.org/10.1108/11766091111162070
    Rahman, T., Rohan, R., Pal, D., & Kanthamanon, P. (2021). Human factors in cybersecurity: A scoping review. The 12th International Conference on Advances in Information Technology, 1–11.
    https://doi.org/10.1145/3468784.3468789
    Riggins, P., & McPherson, D. (2019). Tools for mathematical ludology. arXiv:1912.03295. https://doi.org/10.48550/arXiv.1912.03295
    Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121–135. https://doi.org/10.1093/cybsec/tyw001
    Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). NIST SP 800-207 Zero Trust Architecture. 1–50. https://doi.org/10.6028/NIST.SP.800-207
    Savaş, S., & Karataş, S. (2022). Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity governance. International Cybersecurity Law Review, 3(1), 7–34. https://doi.org/10.1365/s43439-021-00045-4
    Scarfone, K., Souppaya, M., Cody, A., & Orebaugh, A. (2008). Technical guide to information security testing and assessment. NIST Special Publication, 800(115). https://doi.org/10.6028/NIST.SP.800-115
    Schinagl, S., & Shahim, A. (2020). What do we know about information security governance? “From the basement to the boardroom”: towards digital security governance. Information & Computer Security, 28(2), 261–292. https://doi.org/10.1108/ICS-02-2019-0033
    Sicart, M. (2008). Defining game mechanics. Game Studies, 8(2). https://gamestudies.org/0802/articles/sicart
    Stroeh, K., Mauro Madeira, E. R., & Goldenstein, S. K. (2013). An approach to the correlation of security events based on machine learning techniques. Journal of Internet Services and Applications, 4(1), Article 7. https://doi.org/10.1186/1869-0238-4-7
    Surdyk, A. (2008). Ludology as game research in language pedagogy studies/ Ludologie als spielforschung– angewandt in der fremdsprachendidaktik. Kalbotyra, 59, 261–270. https://doi.org/10.15388/Klbt.2008.7614
    Vykopal, J., Vizvary, M., Oslejsek, R., Celeda, P., & Tovarnak, D. (2017). Lessons learned from complex hands-on defence exercises in a cyber range. 2017 IEEE Frontiers in Education Conference (FIE), 1–8. https://doi.org/10.1109/FIE.2017.8190713
    Wardrip-Fruin, N., Mateas, M., Dow, S., & Sali, S. (2009). Agency reconsidered. DiGRA Digital Library. https://doi.org/10.26503/dl.v2009i1.369
    Widder, D. G., Dabbish, L., Herbsleb, J. D., Holloway, A., & Davidoff, S. (2021). Trust in collaborative automation in high stakes software engineering work: A case study at NASA. Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems, 1–13. https://doi.org/10.1145/3411764.3445650
    Winecoff, A., & Bogen, M. (2025, April). Improving governance outcomes through AI documentation: Bridging theory and practice. Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, 1–18. https://doi.org/10.1145/3706598.3713814
    Yin, R. K. (2018). Case study research and applications (6th ed.). Sage.
    Yu, Z.-H. (2017, December 22). Taiwan's Financial Information Sharing and Analysis Center (F-ISAC) has been launched, specializing in 9 major cybersecurity intelligence services, with 23 domestic securities firms being the first to join. IThome. https://www.ithome.com.tw/news/119886
    Zieba, M., & Bongiovanni, I. (2022). Knowledge management and knowledge security—Building an integrated framework in the light of COVID‐19. Knowledge and Process Management, 29(2), 121–131. https://doi.org/10.1002/kpm.1707

    無法下載圖示 此全文未授權公開
    QR CODE
    :::