| 研究生: |
陳貫翔 Chen, Kuan-Hsiang |
|---|---|
| 論文名稱: |
從遊戲學視角探討支援資安作業導入 SOAR 所需的前置準備 A Ludology Perspective on Preparations Required to Support SOAR Adoption in Security Operations |
| 指導教授: |
周致遠
Chou, Chih-Yuan |
| 口試委員: |
歐素華
Ou, Su-Hua 曾筱珽 Tseng, Hsiao-Ting |
| 學位類別: |
碩士
Master |
| 系所名稱: |
商學院 - 資訊管理學系 Department of Management Information System |
| 論文出版年: | 2026 |
| 畢業學年度: | 114 |
| 語文別: | 英文 |
| 論文頁數: | 69 |
| 中文關鍵詞: | SOAR 、SIEM 、遊戲研究 、安全協調 、自動化 |
| 外文關鍵詞: | SOAR, SIEM, Ludology, Security Orchestration, Automation |
| 相關次數: | 點閱:13 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
隨著資安事件數量與複雜度持續增加,組織逐漸導入安全、協調、自動化和回應(security orchestration, automation, and response, SOAR)以提升資安營運效率。然而,現有 SOAR 研究多聚焦於技術能力與系統架構,較少探討組織在導入前所需進行的準備工作。因此,本研究以臺灣某金融機構為個案,探討組織在以安全資訊與事件管理(security information and event management, SIEM)為核心的資安作業環境中,如何為未來導入 SOAR 進行準備。本研究採用質性個案研究方法,透過半結構式訪談、參與式觀察及文件分析蒐集資料,並以 Gioia 分析法進行分析。理論上,本研究引入遊戲學作為分析視角,將組織中的資安作業理解為由規則、行動者與能動性、工具與可供性,以及回饋四個構面所組成之互動系統。研究結果顯示,SOAR 導入不僅涉及技術能力建置,更涉及決策邏輯明確化、權責配置、工具能力發展與組織學習等議題。本研究進一步提出一個以遊戲學為基礎之概念模型,說明組織如何透過規則建立、能動性重新分配、工具能力發展及回饋循環,逐步完成 SOAR 導入準備。本研究除補充現有 SOAR 文獻較少討論之組織面向外,亦提供實務界規劃資安自動化導入之參考。
As cybersecurity threats continue to grow in scale and complexity, organizations are increasingly adopting security orchestration, automation, and response (SOAR) to improve the efficiency of security operations. Existing SOAR studies primarily focus on technical capabilities and system architectures, while relatively little attention has been paid to the organizational preparations required before implementation. This study examines how organizations prepare for SOAR adoption within SIEM-centered security operations. A qualitative case study was conducted in a Taiwanese financial institution. Data were collected through semi-structured interviews, participant observation, and document analysis, and were analyzed using the Gioia methodology. The study adopts a ludology perspective, conceptualizing cybersecurity operations as an interactive system consisting of rules, actors and agency, tools and affordances, and feedback loops. The findings show that SOAR adoption involves not only technological deployment but also the development of decision rules, authority allocation, tool capabilities, and organizational learning mechanisms. Based on these findings, a ludology-based conceptual model was developed to explain how organizations prepare for SOAR adoption through rule formation, agency redistribution, capability development, and feedback-driven learning. The study contributes to the SOAR literature by extending attention beyond technical implementation toward organizational preparation and offers insights into how organizations approach cybersecurity automation initiatives.
CHAPTER 1 INTRODUCTION 1
CHAPTER 2 CONCEPTUAL BACKGROUND 6
2.1 Documentation and Institutionalization 6
2.2 Socio-Relational Perspectives 8
2.3 Ludology 10
2.3.1 Rules 12
2.3.2 Actors and agency 13
2.3.3 Tools and affordances 13
2.3.4 Feedback loops 14
CHAPTER 3 RESEARCH METHODOLOGY 17
3.1 Research Approach 17
3.2 Data Collection 19
3.3 Data Analysis 23
CHAPTER 4 CASE BACKGROUND 29
CHAPTER 5 ANALYSIS AND FINDINGS 33
5.1 Rules 33
5.1.1 Making Decision Logic Explicit 33
5.1.2 Managing Exceptions and Human Discretion 34
5.1.3 Accountability Concerns in Decision-Making 35
5.2 Actors and agency 37
5.2.1 Professional Experience and Contextual Knowledge in Incident Judgement 37
5.2.2 Decision Authority under Hierarchical Permission Structures 38
5.2.3 Organizational Adoption and Continued Use Intention 39
5.3 Tools and Affordance 41
5.3.1 AI as a Supportive Analytical Tool 41
5.3.2 Constraints on Automation Capability 41
5.3.3 Cross-System Support for Incident Analysis 43
5.3.4 Expectations for Expanded Automation Capability 43
5.4 Feedback Loops 45
5.4.1 Documentation and Accumulation of Operational Knowledge 45
5.4.2 Continuous Process Optimization and Adjustment 46
5.4.3 Building Shared Risk Awareness 47
5.4.4 Transfer of Tacit Knowledge and Experience 48
CHAPTER 6 DISCUSSION 50
6.1 Ludology Lens to Finding 51
6.2 Theoretical Contribution 54
6.3 Practical Contribution 56
CHAPTER 7 CONCLUSION 58
7.1 Concluding Remarks 58
7.2 Limitation and Future Research Direction 59
REFERENCES 61
Afroogh, S., Akbari, A., Malone, E., Kargar, M., & Alambeigi, H. (2024). Trust in AI: Progress, challenges, and future directions. Humanities and Social Sciences Communications, 11, Article 1568. https://doi.org/10.1057/s41599-024-04044-8
Ahimbisibwe, B. K., & Nabende, P. (2023). The institutionalisation of information security management practices in selected organisations in Uganda. International Journal of Advanced Research, 6(1), 48–63. https://doi.org/10.37284/ijar.6.1.1155
Alavi, R., Islam, S., & Mouratidis, H. (2014). A conceptual framework to analyze human factors of information security management system (ISMS) in organizations. Human aspects of information security, privacy, and trust, 297–305. https://doi.org/10.1007/978-3-319-07620-1_26
AlGhamdi, S., Win, K. T., & Vlahu-Gjorgievska, E. (2020). Information security governance challenges and critical success factors: Systematic review. Computers & Security, 99, Article 102030. https://doi.org/10.1016/j.cose.2020.102030
Ali, O., Murray, P. A., Muhammed, S., Dwivedi, Y. K., & Rashiti, S. (2022). Evaluating organizational level IT innovation adoption factors among global firms. Journal of Innovation & Knowledge, 7(3), Article 100213. https://doi.org/10.1016/j.jik.2022.100213
Arghire, I. (2025). CISA releases guidance on SIEM and SOAR implementation. SecurityWeek. https://www.securityweek.com/cisa-releases-guidance-on-siem-and-soar-implementation/
Australian Cyber Security Centre. (2025). Implementing SIEM and SOAR platforms: Practitioner guidance, Australian Signals Directorate. https://www.cyber.gov.au/business-government/detecting-responding-to-threats/event-logging/implementing-siem-soar-platforms/practitioner-guidance
Awa, H. O., Etim, W., & Ogbonda, E. (2024). Stakeholders, stakeholder theory and corporate social responsibility (CSR). International Journal of Corporate Social Responsibility, 9, Article 11. https://doi.org/10.1186/s40991-024-00094-y
Bada, M., & Nurse, J. R. (2019). Developing cybersecurity education and awareness programmes for small-and medium-sized enterprises (SMEs). Information & Computer Security, 27(3), 393–410. https://doi.org/10.1108/ICS-07-2018-0080
Batewela, S., Ranaweera, P., Liyanage, M., Zeydan, E., & Ylianttila, M. (2025). Addressing security orchestration challenges in next-generation networks: A comprehensive overview. IEEE Open Journal of the Computer Society, 6, 669–687.
https://doi.org/10.1109/OJCS.2025.3564788
Benzar, A., Kovalenko, Y. O., Taranenko, A., Balynska, O., & Balynskyi, I. (2025). Organizational context of security management: Implications for information systems. Management (Montevideo), 3, 250. https://doi.org/10.62486/agma2025250
Böhm, F., Vielberth, M., & Pernul, G. (2022). Formalizing and integrating user knowledge into security analytics. SN Computer Science, 3(5), Article 347.
https://doi.org/10.1007/s42979-022-01209-7
Bridges, R. A., Rice, A. E., Oesch, S., Nichols, J. A., Watson, C., Spakes, K., Norem, S., Huettel, M., Jewell, B., Weber, B., Gannon, C., Bizovi, O., Hollifield, S. C., & Erwin, S. (2023). Testing SOAR tools in use. Computers & Security, 129, Article 103201. https://doi.org/10.1016/j.cose.2023.103201
Caillois, R. (2001). Man, play, and games (M. Barash, Trans.). University of Illinois Press.
Chng, S., Lu, H. Y., Kumar, A., & Yau, D. (2022). Hacker types, motivations and strategies: A comprehensive framework. Computers in Human Behavior Reports, 5, Article 100167. https://doi.org/10.1016/j.chbr.2022.100167
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide (NIST Special Publication 800-61 Rev. 2). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r2
De Smet, D., & Mayer, N. (2016). Integration of IT governance and security risk management: A systematic literature review. 2016 International Conference on Information Society (i-Society), 143–148. https://doi.org/10.1109/i-Society.2016.7854200
Di Giulio, M., & Vecchi, G. (2023). How “institutionalization” can work. Structuring governance for digital transformation in Italy. Review of Policy Research, 40(3), 406–432. https://doi.org/10.1111/ropr.12488
Dubé, L., & Paré, G. (2003). Rigor in information systems positivist case research: Current practices, trends, and recommendations. MIS Quarterly, 27(4), 597–636. https://doi.org/10.2307/30036550
Dupont, B. (2019). The cyber-resilience of financial institutions: Significance and applicability. Journal of Cybersecurity, 5(1), Article tyz013. https://doi.org/10.1093/cybsec/tyz013
Emerson, R. M., Fretz, R. I., & Shaw, L. L. (2011). Writing ethnographic fieldnotes. University of Chicago Press.
https://press.uchicago.edu/ucp/books/book/chicago/W/bo12182616.html
Financial Supervisory Commission R.O.C. (2024). Reference guidelines for the implementation of zero trust architecture in the financial industry. Financial Supervisory Commission R.O.C..
https://www.fsc.gov.tw/ch/home.jsp?id=96&parentpath=0,2&mcustomize=news_view.jsp&dataserno=202407180002&dtable=News
Frasca, G. (2003). Ludologists love stories, too: Notes from a debate that never took place. Proceedings of DiGRA 2003 Conference: Level Up, 93–99. DiGRA.
https://doi.org/10.26503/dl.v2003i1.64
Garris, R., Ahlers, R., & Driskell, J. E. (2002). Games, motivation, and learning: A research and practice model. Simulation & Gaming, 33(4), 441–467.
https://doi.org/10.4324/9781315243092-25
Gioia, D. A., Corley, K. G., & Hamilton, A. L. (2013). Seeking qualitative rigor in inductive research: Notes on the Gioia methodology. Organizational Research Methods, 16(1), 15–31. https://doi.org/10.1177/1094428112452151
Global Taiwan Institute. (2024, March). The nexus of cybersecurity and national security: Taiwan’s imperatives amidst escalating cyber threats. Global Taiwan Institute. https://globaltaiwan.org/2024/03/the-nexus-of-cybersecurity-and-national-security-taiwans-imperatives-amidst-escalating-cyber-threats/
Global Taiwan Institute. (2025, July). Advancing cyber resilience: Taiwan’s strategic shift in the seventh phase of its national cybersecurity program. Global Taiwan Institute. https://globaltaiwan.org/2025/07/advancing-cyber-resilience-taiwans-strategic-shift/
Hoff, K. A., & Bashir, M. (2015). Trust in automation: Integrating empirical evidence on factors that influence trust. Human Factors, 57(3), 407–434.
https://doi.org/10.1177/0018720814547570
Hohan, A. I., Olaru, M., & Pirnea, I. C. (2015). Assessment and continuous improvement of information security based on TQM and business excellence principles. Procedia Economics and Finance, 32, 352–359. https://doi.org/10.1016/S2212-5671(15)01404-5
Hong, M. J. (2024). Research on management mechanisms of cross-departmental collaboration in solving complex public problems. Open Journal of Social Sciences, 12(12), 483–493. https://doi.org/10.4236/jss.2024.1212032
Hunicke, R., LeBlanc, M., & Zubek, R. (2004, July). MDA: A formal approach to game design and game research. Proceedings of the AAAI Workshop on Challenges in Game AI, 4(1), Article 1722.
https://cdn.aaai.org/Workshops/2004/WS-04-04/WS04-04-001.pdf
Itani, D., Itani, R., Eltweri, A. A., Faccia, A., & Wanganoo, L. (2024, February). Enhancing cybersecurity through compliance and auditing: a strategic approach to resilience. 2024 2nd International Conference on Cyber Resilience (ICCR), 1–10. https://doi.org/10.1109/ICCR61006.2024.10532959
Järvinen, A. (2007, January). Introducing applied ludology: Hands-on methods for game studies. Proceedings of DiGRA 2007 Conference: Situated Play, 134–144. https://doi.org/10.26503/dl.v2007i1.280
Kent, K., & Souppaya, M. (2006). Guide to computer security log management (NIST SP 800–92). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-92
Kramer, F. D., Yu, P. W., Webster, J., & Sizeland, E. (2024). Strengthening Taiwan’s resiliency. Atlantic Council. https://www.atlanticcouncil.org/in-depth-research-reports/report/strengthening-taiwans-resiliency/
Kremer, R., Wudali, P. N., Momiyama, S., Araki, T., Furukawa, J., Elovici, Y., & Shabtai, A. (2023). IC-SECURE: Intelligent system for assisting security experts in generating playbooks for automated incident response. arXiv. https://doi.org/10.48550/arXiv.2311.03825
Lahusen, C., Maggetti, M., & Slavkovik, M. (2024). Trust, trustworthiness and AI governance. Scientific Reports, 14(1), Article 20752. https://doi.org/10.1038/s41598-024-71761-0
Linderoth, J. (2013). Beyond the digital divide: An ecological approach to gameplay. Transactions of the Digital Games Research Association, 1(1), 1–17. https://doi.org/10.26503/todigra.v1i1.9
Lokuge, S., Sedera, D., Grover, V., & Dongming, X. (2019). Organizational readiness for digital innovation: Development and empirical calibration of a construct. Information & Management, 56(3), 445–461. https://doi.org/10.1016/j.im.2018.09.001
Luo, Z.-H. (2024, November 7). Financial Fast-ID Verification Hub to Launch Next June, 20 Pilot Institutions Expected. IThome. https://www.ithome.com.tw/news/165876
Magnusson, L., Iqbal, S., Elm, P., & Dalipi, F. (2025). Information security governance in the public sector: investigations, approaches, measures, and trends. International Journal of Information Security, 24(4), Article 177. https://doi.org/10.1007/s10207-025-01097-x
Masilela, L., & Nel, D. (2021). The role of data and information security governance in protecting public sector data and information assets in national government in South Africa. Africa’s Public Service Delivery and Performance Review, 9(1), 385. https://doi.org/10.4102/apsdpr.v9i1.385
Nacke, L. E., & Lindley, C. A. (2010). Affective ludology, flow and immersion in a first-person shooter: Measurement of player experience. The Journal of the Canadian Game Studies Association, 3(5), 1–21. https://doi.org/10.48550/arXiv.1004.0248
Nicolini, D. (2012). Practice theory, work, and organization: An introduction. OUP Oxford.
Parasuraman, R., Sheridan, T. B., & Wickens, C. D. (2000). A model for types and levels of human interaction with automation. IEEE Transactions on systems, man, and cybernetics-Part A: Systems and Humans, 30(3), 286–297. https://doi.org/10.1109/3468.844354
Pawar, S., & Palivela, H. (2022). LCCI: A framework for least cybersecurity controls to be implemented for small and medium enterprises (SMEs). International Journal of Information Management Data Insights, 2(1), Article 100080.
https://doi.org/10.1016/j.jjimei.2022.100080
Police Broadcasting Service, National Police Agency, Ministry of the Interior, Republic of China (Taiwan) (2023). "Eagle Eye Anti-Fraud Alliance" Officially Established: CIB Partners with Financial Industry to Combat Fraud, Using AI to Identify High-Risk Accounts for Proactive Prevention, Police Broadcasting Service, National Police Agency, Ministry of the Interior, Republic of China (Taiwan).
https://www.pbs.npa.gov.tw/ch/app/data/view?module=wg183&id=18740&serno=1bc4ca26-31f8-4343-8482-53e22201978f
Pratt, M. G. (2009). From the editors: For the lack of a boilerplate: Tips on writing up (and reviewing) qualitative research. Academy of Management Journal, 52(5), 856–862. https://doi.org/10.5465/amj.2009.44632557
Qu, S. Q., & Dumay, J. (2011). The qualitative research interview. Qualitative Research in Accounting & Management, 8(3), 238–264. https://doi.org/10.1108/11766091111162070
Rahman, T., Rohan, R., Pal, D., & Kanthamanon, P. (2021). Human factors in cybersecurity: A scoping review. The 12th International Conference on Advances in Information Technology, 1–11.
https://doi.org/10.1145/3468784.3468789
Riggins, P., & McPherson, D. (2019). Tools for mathematical ludology. arXiv:1912.03295. https://doi.org/10.48550/arXiv.1912.03295
Romanosky, S. (2016). Examining the costs and causes of cyber incidents. Journal of Cybersecurity, 2(2), 121–135. https://doi.org/10.1093/cybsec/tyw001
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). NIST SP 800-207 Zero Trust Architecture. 1–50. https://doi.org/10.6028/NIST.SP.800-207
Savaş, S., & Karataş, S. (2022). Cyber governance studies in ensuring cybersecurity: an overview of cybersecurity governance. International Cybersecurity Law Review, 3(1), 7–34. https://doi.org/10.1365/s43439-021-00045-4
Scarfone, K., Souppaya, M., Cody, A., & Orebaugh, A. (2008). Technical guide to information security testing and assessment. NIST Special Publication, 800(115). https://doi.org/10.6028/NIST.SP.800-115
Schinagl, S., & Shahim, A. (2020). What do we know about information security governance? “From the basement to the boardroom”: towards digital security governance. Information & Computer Security, 28(2), 261–292. https://doi.org/10.1108/ICS-02-2019-0033
Sicart, M. (2008). Defining game mechanics. Game Studies, 8(2). https://gamestudies.org/0802/articles/sicart
Stroeh, K., Mauro Madeira, E. R., & Goldenstein, S. K. (2013). An approach to the correlation of security events based on machine learning techniques. Journal of Internet Services and Applications, 4(1), Article 7. https://doi.org/10.1186/1869-0238-4-7
Surdyk, A. (2008). Ludology as game research in language pedagogy studies/ Ludologie als spielforschung– angewandt in der fremdsprachendidaktik. Kalbotyra, 59, 261–270. https://doi.org/10.15388/Klbt.2008.7614
Vykopal, J., Vizvary, M., Oslejsek, R., Celeda, P., & Tovarnak, D. (2017). Lessons learned from complex hands-on defence exercises in a cyber range. 2017 IEEE Frontiers in Education Conference (FIE), 1–8. https://doi.org/10.1109/FIE.2017.8190713
Wardrip-Fruin, N., Mateas, M., Dow, S., & Sali, S. (2009). Agency reconsidered. DiGRA Digital Library. https://doi.org/10.26503/dl.v2009i1.369
Widder, D. G., Dabbish, L., Herbsleb, J. D., Holloway, A., & Davidoff, S. (2021). Trust in collaborative automation in high stakes software engineering work: A case study at NASA. Proceedings of the 2021 CHI Conference on Human Factors in Computing Systems, 1–13. https://doi.org/10.1145/3411764.3445650
Winecoff, A., & Bogen, M. (2025, April). Improving governance outcomes through AI documentation: Bridging theory and practice. Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, 1–18. https://doi.org/10.1145/3706598.3713814
Yin, R. K. (2018). Case study research and applications (6th ed.). Sage.
Yu, Z.-H. (2017, December 22). Taiwan's Financial Information Sharing and Analysis Center (F-ISAC) has been launched, specializing in 9 major cybersecurity intelligence services, with 23 domestic securities firms being the first to join. IThome. https://www.ithome.com.tw/news/119886
Zieba, M., & Bongiovanni, I. (2022). Knowledge management and knowledge security—Building an integrated framework in the light of COVID‐19. Knowledge and Process Management, 29(2), 121–131. https://doi.org/10.1002/kpm.1707
此全文未授權公開