Making Security Work: Vulnerability Disclosure Programs (VDPs) and the Organizational Foundations of Cybersecurity

让安全发挥作用:漏洞披露计划 (VDP) 和网络安全的组织基础

基本信息

  • 批准号:
    2203175
  • 负责人:
  • 金额:
    $ 34.13万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2022
  • 资助国家:
    美国
  • 起止时间:
    2022-06-01 至 2025-05-31
  • 项目状态:
    未结题

项目摘要

Cybersecurity is now an organizational imperative. High-profile data breaches, ransomware attacks, and other costly exploits and attacks have made cybersecurity a priority for all manner of public and private organizations. Organizations are increasingly adopting vulnerability disclosure programs (VDPs) as a key strategy for managing and mitigating cybersecurity risk. These programs crowdsource security work—they invite independent security researchers to report newly identified software bugs. Yet, the adoption and management of these programs is rarely simple or straightforward. They can create new points of stress and complication within organization. This project examines how these programs work and, importantly, how they can be improved. Protecting digital networks, devices, and software is a key national priority. Ultimately, the research project’s insights will help organizations improve their security.While organizations have long relied on a blend of in-house information technology expertise and contracted computer services, VDPs are a different approach to harnessing expertise. This project uncovers the ongoing intra-organizational work required to integrate these new intuitional models of software review within organizations; and it assesses the ultimate effectiveness of VDPs to improve organizational cybersecurity. Specifically, the project addresses two related research questions: (i) What forms of institutional work are needed to create and sustain VDPs?; (ii) How effective are VDPs at improving security? To answer these questions, the project creates and analyzes a novel set of qualitative and quantitative data drawn from select ongoing VDPs. Collected data includes anonymized program data, administrative data, and interviews with staff associated with managing VDPs. This project provides a window into: (i) how new cybersecurity practices are adopted, maintained, and transformed by and within organizations; and (ii) the efficacy of VDPs to improve organizational cybersecurity. Answering these questions will provide insight into larger organizational dimensions of cybersecurity and the efficacy of VDPs to improve security outcomes. More broadly, in addressing these research questions, the project advances insights into the often-overlooked institutional work associated with adopting and sustaining new organizational innovations.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
网络安全现在是组织的当务之急。备受瞩目的数据泄露、勒索软件攻击以及其他代价高昂的漏洞和攻击使得网络安全成为各种公共和私人组织的首要任务。组织越来越多地采用漏洞披露计划(vdp)作为管理和减轻网络安全风险的关键策略。这些程序将安全工作众包——它们邀请独立的安全研究人员报告新发现的软件漏洞。然而,这些程序的采用和管理很少是简单或直接的。它们可以在组织内部制造新的压力点和复杂性。这个项目研究了这些程序是如何工作的,更重要的是,如何改进它们。保护数字网络、设备和软件是国家的首要任务。最终,该研究项目的见解将帮助组织提高其安全性。虽然组织长期依赖于内部信息技术专业知识和合同计算机服务的混合,但vdp是利用专业知识的一种不同方法。这个项目揭示了正在进行的组织内部工作,需要在组织内集成这些新的软件评审的直观模型;它评估了vdp在提高组织网络安全方面的最终有效性。具体而言,该项目涉及两个相关的研究问题:(i)需要何种形式的体制工作来建立和维持虚拟发展方案?(ii) vdp在改善保安方面的成效如何?为了回答这些问题,该项目创建并分析了从选择的正在进行的vdp中提取的一组新的定性和定量数据。收集的数据包括匿名程序数据、管理数据以及与管理vdp相关的工作人员的访谈。本项目为以下方面提供了一个窗口:(i)组织内部如何采用、维护和转变新的网络安全实践;以及(ii) vdp在改善组织网络安全方面的有效性。回答这些问题将有助于深入了解网络安全的更大组织维度,以及vdp在改善安全结果方面的有效性。更广泛地说,在解决这些研究问题时,该项目推进了对与采用和维持新的组织创新相关的经常被忽视的机构工作的见解。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Ryan Ellis其他文献

Regulating Cybersecurity: Institutional Learning or a Lesson in Futility?
监管网络安全:制度学习还是徒劳的教训?
TEVAR in Connective Tissue Disease Patients is not a Definitive Option
  • DOI:
    10.1016/j.jvs.2024.06.106
  • 发表时间:
    2024-09-01
  • 期刊:
  • 影响因子:
  • 作者:
    Bryan D. Cass;Courtney Hanak;Ryan Ellis;Ahmed Sorour;Jon Quatromoni;Sean Lyden;Francis Caputo
  • 通讯作者:
    Francis Caputo
Fossil fuel interests in Puerto Rico: Perceptions of incumbent power and discourses of delay
波多黎各的化石燃料利益:对现有权力的看法和延迟的讨论
  • DOI:
    10.1016/j.erss.2024.103467
  • 发表时间:
    2024
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Laura Kuhl;Jennie C. Stephens;Carlos Arriaga Serrano;M. Pérez;C. Ortiz;Ryan Ellis
  • 通讯作者:
    Ryan Ellis
Centralizing cytoreductive surgery for ovarian cancer to high-volume centers: What is the impact of travel on patients? (2207)
将卵巢癌细胞减灭术集中到高容量中心:旅行对患者有什么影响?(2207)
  • DOI:
    10.1016/j.ygyno.2023.06.327
  • 发表时间:
    2023-09-01
  • 期刊:
  • 影响因子:
    4.100
  • 作者:
    Ryan Kahn;Xiaoyue Ma;Sushmita Gordhandas;Ryan Ellis;Xiuling Zhang;Emeline Aviki;Nadeem Abu-Rustum;Ginger Gardner;Yukio Sonoda;Oliver Zivanovic;Kara Long Roche;Elizabeth Jewell;Thomas Boerner;Dennis Chi
  • 通讯作者:
    Dennis Chi
Effect of tongue scraper and rinses on bad breath, a double-blind, randomized, parallel group clinical trial.
刮舌和漱口对口臭的影响,一项双盲、随机、平行组临床试验。

Ryan Ellis的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Ryan Ellis', 18)}}的其他基金

RAPID International Type I: Collaborative Research: COVID Data Infrastructure Builders: Creating Resilient and Sustainable Research Collaborations
RAPID 国际 I 类:协作研究:新冠病毒数据基础设施建设者:创建有弹性和可持续的研究合作
  • 批准号:
    2109966
  • 财政年份:
    2021
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Standard Grant
EAGER: SaTC: Early-Stage Interdisciplinary Collaboration: Improving the Bug Bounty System
EAGER:SaTC:早期跨学科合作:改进错误赏金系统
  • 批准号:
    1915815
  • 财政年份:
    2019
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Standard Grant

相似海外基金

Research on Legislation of Work and Income Security for the Realization of Self-Desciplined Old Age
实现自律养老的工作和收入保障立法研究
  • 批准号:
    22H00790
  • 财政年份:
    2022
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
The effect of gig economy work on workers' financial (in)security and the mediating role of social security systems
零工经济工作对劳动者财务(安全​​)保障的影响及社会保障制度的中介作用
  • 批准号:
    ES/S016414/1
  • 财政年份:
    2020
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Research Grant
Cyber Security for Employees Required to Work from Home
需要在家工作的员工的网络安全
  • 批准号:
    54952
  • 财政年份:
    2020
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Feasibility Studies
Work life security in the structuralization of unemployment and underemployment
失业和就业不足结构化中的工作生活保障
  • 批准号:
    15H03295
  • 财政年份:
    2015
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
Right and duty to work in the coordination of labour law and social security law
劳动法和社会保障法相协调的工作权利和义务
  • 批准号:
    26780034
  • 财政年份:
    2014
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Grant-in-Aid for Young Scientists (B)
Examination of the Normative Relationship Between Meaning of Work and Income Security Policy
工作意义与收入保障政策之间规范关系的审视
  • 批准号:
    26370033
  • 财政年份:
    2014
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Which burglary security devices work for whom and in what context?
哪些防盗安全设备适用于谁以及在什么情况下使用?
  • 批准号:
    ES/K003771/1
  • 财政年份:
    2013
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Research Grant
Which burglary security devices work for whom and in what context?
哪些防盗安全设备适用于谁以及在什么情况下使用?
  • 批准号:
    ES/K003771/2
  • 财政年份:
    2013
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Research Grant
FINANCIAL (IN)SECURITY IN LATER LIFE: WOMEN, WORK , SUPERANNUATION AND AUSTRALIA'S RETIREMENT INCOME SYSTEM
晚年的财务(安全​​)保障:女性、工作、退休金和澳大利亚的退休收入体系
  • 批准号:
    LP0347060
  • 财政年份:
    2003
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Linkage Projects
ITR: Behavioral Information Security: The Politics, Motivation, and Ethics of Information Security in Work Organizations
ITR:行为信息安全:工作组织中信息安全的政治、动机和伦理
  • 批准号:
    0312078
  • 财政年份:
    2003
  • 资助金额:
    $ 34.13万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了