Paper Type
Short
Paper Number
PACIS2026-1583
Description
This study examines how organizations adjust cybersecurity governance as they integrate SOAR into SIEM-centered security operations. Increasing alert volumes and regulatory pressures are prompting a shift from analyst-driven, manual workflows toward more standardized, auditable, and automation-supported incident handling. Using a qualitative case study based on interviews, field observations, and archival materials, the research analyzes how practitioners interpret operational rules, coordinate response decisions, and maintain accountability in the pre-automation stage. A ludological lens conceptualizes security operations as evolving interaction systems composed of rules, tools, actors, and feedback mechanisms. Guided by the Gioia methodology, the study identifies which operational practices require reassessment when SOAR capabilities are incorporated into SIEM environments and examines how governance structures adapt as automation becomes operational.
Recommended Citation
Chou, Chih-Yuan and Chen, Kuan-Hsiang, "A Ludology Perspective on Preparations Required to Support SOAR Adoption in Security Operations" (2026). PACIS 2026 Proceedings. 7.
https://aisel.aisnet.org/pacis2026/dig_sec/dig_sec/7
A Ludology Perspective on Preparations Required to Support SOAR Adoption in Security Operations
This study examines how organizations adjust cybersecurity governance as they integrate SOAR into SIEM-centered security operations. Increasing alert volumes and regulatory pressures are prompting a shift from analyst-driven, manual workflows toward more standardized, auditable, and automation-supported incident handling. Using a qualitative case study based on interviews, field observations, and archival materials, the research analyzes how practitioners interpret operational rules, coordinate response decisions, and maintain accountability in the pre-automation stage. A ludological lens conceptualizes security operations as evolving interaction systems composed of rules, tools, actors, and feedback mechanisms. Guided by the Gioia methodology, the study identifies which operational practices require reassessment when SOAR capabilities are incorporated into SIEM environments and examines how governance structures adapt as automation becomes operational.
Comments
08-Security