| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Vpeljava in uporaba SOAR orodja v organizaciji : diplomsko delo visokošolskega študijskega programa Informacijska varnost
Authors:ID Gerzina, Rok (Author)
ID Bernik, Igor (Mentor) More about this mentor... New window
Files:.pdf VS_Gerzina_Rok_2025.pdf (1,17 MB)
MD5: E035D0729CD323BDCA54C0224681D1AB
 
Language:Slovenian
Work type:Bachelor thesis/paper
Typology:2.11 - Undergraduate Thesis
Organization:FVV - Faculty of Criminal Justice and Security
Abstract:V diplomskem delu je predstavljena implementacija in uporaba SOAR orodja v organizaciji, ki se ukvarja z zagotavljanjem kibernetske varnosti. Namen raziskave je bil analizirati, kako vpeljava tovrstnega orodja vpliva na učinkovitost obravnave varnostnih dogodkov in kakšni so ključni izzivi pri integraciji v obstoječe okolje. V teoretičnem delu so obravnavani koncepti orkestracije, avtomatizacije in odzivanja na incidente ter pregled obstoječih raziskav in praks. V praktičnem delu je prikazana implementacija SOAR orodja, vključno z integracijo različnih varnostnih orodij, oblikovanjem delovnih tokov ter identifikacijo tehničnih in organizacijskih omejitev. Rezultati kažejo, da SOAR prinaša pomembne koristi, kot so skrajšani odzivni časi, razbremenitev zaposlenih pri rutinskih nalogah ter večja doslednost postopkov. Hkrati pa raziskava razkriva izzive, povezane z omejitvami API-jev, licenčnimi politikami ponudnikov ter potrebo po usposobljenem kadru. Ugotovitve potrjujejo, da SOAR lahko pomembno prispeva k večji učinkovitosti in zanesljivosti varnostnih procesov, vendar avtomatizacija ne more v celoti nadomestiti človeškega dejavnika. V zaključku so predlagane možnosti za nadaljnje raziskave, med drugim primerjava različnih komercialnih orodij ter vloga umetne inteligence pri nadgradnji obstoječih orodij. Raziskava temelji na pristopu študije primera, in sicer enojnem vgrajenem študijskem primeru, ki kombinira kvantitativne metrike (MTTD/MTTI/MTTR) in kvalitativne ugotovitve analitikov.
Keywords:kibernetska varnost, organizacije, delovni tokovi, orodja SOAR, diplomske naloge
Publication status:Published
Publication version:Version of Record
Place of publishing:Ljubljana
Place of performance:Ljubljana
Publisher:R. Gerzina
Year of publishing:2025
Year of performance:2025
Number of pages:X f., 72 str.
PID:20.500.12556/DKUM-95847 New window
UDC:004.056(043.2)
COBISS.SI-ID:262620419 New window
Publication date in DKUM:22.12.2025
Views:160
Downloads:17
Metadata:XML DC-XML DC-RDF
Categories:FVV
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:30.10.2025

Secondary language

Language:English
Title:Implementation and use of a soar tool in an organization
Abstract:This thesis presents the implementation and use of a SOAR tool in an organization responsible for cybersecurity. The aim of the research was to analyze how the adoption of such a tool affects the efficiency of handling security events and to identify key challenges when integrating it into an existing environment. The theoretical part discusses the concepts of orchestration, automation, and incident response, as well as an overview of existing research and practices. The practical part demonstrates the implementation of the SOAR tool, including the integration of various security tools, the design of workflows, and the identification of technical and organizational limitations. The results show that SOAR brings significant benefits such as reduced response times, reduces repetitive workload for analysts, and greater procedural consistency and auditability. At the same time, the study reveals challenges related to API limitations, vendor licensing policies, and the need for skilled staff. The findings confirm that SOAR can significantly improve the efficiency and reliability of security processes, although automation cannot fully replace the human factor. The conclusion outlines possibilities for further research, including the comparison of different commercial tools and the role of artificial intelligence in enhancing existing tools. The research is based on a case study approach, specifically a single embedded case design that combines quantitative metrics (MTTD/MTTI/MTTR) with qualitative analyst insights.
Keywords:SOAR, orchestration, automation, cybersecurity, playbooks


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica