Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation.

Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation.
复制标题

DOI:
10.1111/risa.13687
复制
发表时间:
2022-08
期刊:
影响因子:
3.8
通讯作者:
Henshel, Diane S.
Henshel, Diane S.
中科院分区:
医学3区
文献类型:
--
作者:
Cains, Mariana G.;Flora, Liberty;Taber, Danica;King, Zoe;Henshel, Diane S.

文献摘要

参考文献

被引文献

相似文献

鉴于网络安全的多学科性质和网络安全问题在整个社会的普遍存在,必须拥有和使用标准化术语,并对网络安全和网络安全风险的含义形成全面的共识。使用专家启发方法,来自多个学科和两个部门(学术界,政府-军事)的合作网络研究人员进行了单独采访,并要求定义网络安全和网络安全风险。使用数据驱动的主题分析来确定每个定义、部门和网络专家组中最突出的主题,并将结果与当前的标准定义进行比较。网络分析被用来直观地显示部门和学科内部和跨部门和学科的突出主题的相互联系。当作为一个整体进行检查时,“上下文驱动”,“弹性系统功能”和“CIA(机密性,完整性,可用性)的维护”是网络安全定义中最突出的主题和有影响力的网络节点,而“CIA漏洞的影响”,“结果的概率”和“上下文驱动”是网络安全风险最突出的主题。我们使用这种专家启发过程来制定网络安全(网络安全)和网络安全风险的全面定义,这些定义涵盖了合作中所代表的所有学科的背景框架,并明确将人为因素作为重要的网络安全风险因素。
It is important to have and use standardized terminology and develop a comprehensive common understanding of what is meant by cyber security and cyber security risk given the multidisciplinary nature of cyber security and the pervasiveness of cyber security concerns throughout society. Using expert elicitation methods, collaborating cyber researchers from multiple disciplines and two sectors (academia, government–military) were individually interviewed and asked to define cyber security and cyber security risk. Data‐driven thematic analysis was used to identify the most salient themes within each definition, sector, and cyber expert group as a whole with results compared to current standards definitions. Network analysis was employed to visualize the interconnection of salient themes within and across sectors and disciplines. When examined as a whole group, “context‐driven,” “resilient system functionality,” and “maintenance of CIA (confidentiality, integrity, availability)” were the most salient themes and influential network nodes for the definition of cyber security, while “impacts of CIA vulnerabilities,” “probabilities of outcomes,” and “context‐driven” were the most salient themes for cyber security risk. We used this expert elicitation process to develop comprehensive definitions of cyber security (cybersecurity) and cyber security risk that encompass the contextual frameworks of all the disciplines represented in the collaboration and explicitly incorporates human factors as significant cyber security risk factors.
DOI: 10.1088/1742-5468/2008/10/p10008
发表时间: 2008-10-01
影响因子: 2.4
作者:
Blondel, Vincent D.;Guillaume, Jean-Loup;Lefebvre, Etienne
通讯作者: Lefebvre, Etienne
DOI: 10.1080/10429247.2013.11431973
发表时间: 2013-06-01
影响因子: 2.5
作者:
Henrie, Morgan
通讯作者: Henrie, Morgan
DOI: 10.1016/j.zefq.2008.08.013
发表时间: 2008-01-01
影响因子: 1.1
作者:
Gaissmaier, Wolfgang;Gigerenzer, Gerd
通讯作者: Gigerenzer, Gerd
DOI: 10.1111/j.1539-6924.2012.01844.x
发表时间: 2013-01-01
期刊: RISK ANALYSIS
影响因子: 3.8
作者:
Kellens, Wim;Terpstra, Teun;De Maeyer, Philippe
通讯作者: De Maeyer, Philippe
DOI: 10.1111/j.1539-6924.2008.01142.x
发表时间: 2008-12-01
期刊: RISK ANALYSIS
影响因子: 3.8
作者:
Cox, Louis Anthony (Tony), Jr.
通讯作者: Cox, Louis Anthony (Tony), Jr.