Governing AI-Assisted Security Operations: A Design Science Framework for Operational Decision Support
This academic study addresses the critical challenge engineering managers face when integrating generative AI and coding agents into high-risk operational functions, specifically within Security Operations Centers (SOCs). The authors argue that AI-assisted decision support must be managed as a governed engineering capability before being scaled into full automation to preserve accountability, privacy, and auditability. Using Kusto Query Language (KQL) and Microsoft Azure security capabilities as a technical case study, the research highlights that even read-only queries pose risks such as privacy breaches, cost overruns, and misleading interpretations. The study employs design science research to develop a governed AI query-broker artifact. This framework separates AI planning from operational execution through mechanisms like schema-grounded retrieval, policy validation, and auditable agent traces. Rather than introducing new detection algorithms, the primary contribution is a comprehensive management framework. It specifies design propositions, role accountability, maturity stages, and quality gates to govern AI-assisted operations in high-risk digital infrastructure, ensuring safe and disciplined adoption of advanced AI technologies in security contexts.
Wire timeline
Governing AI-Assisted Security Operations: A Design Science Framework for Operational Decision Support
This academic study addresses the critical challenge engineering managers face when integrating generative AI and coding agents into high-risk operational functions, specifically within Security Operations Centers (SOCs). The authors argue that AI-assisted decision support must be managed as a governed engineering capability before being scaled into full automation to preserve accountability, privacy, and auditability. Using Kusto Query Language (KQL) and Microsoft Azure security capabilities as a technical case study, the research highlights that even read-only queries pose risks such as privacy breaches, cost overruns, and misleading interpretations. The study employs design science research to develop a governed AI query-broker artifact. This framework separates AI planning from operational execution through mechanisms like schema-grounded retrieval, policy validation, and auditable agent traces. Rather than introducing new detection algorithms, the primary contribution is a comprehensive management framework. It specifies design propositions, role accountability, maturity stages, and quality gates to govern AI-assisted operations in high-risk digital infrastructure, ensuring safe and disciplined adoption of advanced AI technologies in security contexts.
cs.AI updates on arXiv.org