Evaluating Cyber Security Evidence for Policy Advice: The Other Human Dimension
Evaluating Cyber Security Evidence for Policy Advice: The Other Human Dimension
批准号:
EP/P011691/1
负责人:
Madeline Carr
金额:
$29.83万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The quality of a state's capacity to respond to the challenges of cyber security is rapidly coming to be recognised as an important element of global competitiveness. This project seeks to understand the challenges faced by the UK's policy making community in interpreting, evaluating and understanding evidence about cyber security. Policy makers, sometimes with little relevant expertise and often in time-critical scenarios, are asked to assess evidence from a mix of sources including official threat intelligence, academic sources, and industry threat reports. Such a diverse evidence base is then used to make judgments on threat, risk, mitigation and consequences, and offer advice shaping the national regulatory landscape, foreign and domestic security policy, and a range of public and private sector initiatives. This element of the human dimension has significant relevance for the cyber security of the UK and is the main focus of this proposal. Assessment of evidence is a particular problem for policy making in this context for three reasons: First, some of the evidence is contradictory and/or potentially carries within it particular agendas or goals that may impede upon its rigour and reliability. The 'politicisation' of cyber security evidence is increasingly problematic as states sometimes privilege threat intelligence from sources located within their sovereign borders rather than based on the quality of the research they produce; Secondly, it has proven to be extremely difficult to conclusively attribute cyber attacks and to quantify the cost of cyber insecurity. These challenges mean that evidence can only support policy makers' decisions and evaluation of cyber security risks, threats and consequences to an extent;Finally, the landscape of cyber security is developing rapidly and spans many issue areas including national security, human rights, commercial concerns, and related infrastructure vulnerabilities. Consequently, policy makers must work to balance a range of sometimes conflicting interests that compete for attention and they must do so in a field with little precedent to draw upon.When exploring the problems (and possible remedies) of the human dimension of cyber security, many focus on end users. While this is important, equally important is the human dimension of decision making and advice offered by civil servants who collectively influence policy level responses to cyber threats. This project focuses on policy makers in the UK, specifically those civil servants who provide short and long term policy advice, either in response to specific crisis incidents or in the context of longer term planning for capacity building. This cohort is of particular importance given:- the unique set of technological, behavioural and policy challenges they currently face. They are a relatively small and disparate group, possessing varying levels of technical and behavioural experience;- their responsibility and impact goes well beyond their own organisations to shape the national and international landscape; and finally, - the lack of research to support this particular community, either in identifying specific challenges they face or in developing more effective mechanisms for doing so.This leads to several questions: what evidence do UK policy makers rely upon in this context? What is the quality of that evidence? How effective are the judgements about threats, risks, mitigation and consequences based on that evidence? Understanding how UK policy makers select evidence, why they privilege one source over another, and how adept they are at recognising possible weaknesses or flaws in evidence is central to addressing these questions.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Cyber Metrics: Getting the conversation straight between technical and non-technical actors
网络指标:技术和非技术参与者之间的直接对话
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
[Carr M]
通讯作者:
Carr M
'An Evidence Quality Assessment Model for Cybersecurity Policymaking'
“网络安全政策制定的证据质量评估模型”
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
[Hussain A]
通讯作者:
Hussain A
Using games to assess evidence informed cybersecurity policymaking
使用游戏来评估基于证据的网络安全决策
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
[Hussain A]
通讯作者:
Hussain A
RISCS Annual Report 2018
2018年RISCS年度报告
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
[Carr M]
通讯作者:
Carr M
Cyber capacity building and knowledge sharing: The UK policy community's perception of the National Cyber Security Centre
网络能力建设和知识共享:英国政策界对国家网络安全中心的看法
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
[Carr M]
通讯作者:
Carr M
共 9 条
International Cooperation on Cyber Security for Critical Information Infrastructure Protection (Cybersecurity of the Internet of Things Hub)
-
批准号:EP/N022785/2
-
项目类别:Research Grant
-
资助金额:$12.55万
-
财政年份:2017
-
负责人:Madeline Carr
-
依托单位:
Evaluating Cyber Security Evidence for Policy Advice: The Other Human Dimension
-
批准号:EP/P011691/2
-
项目类别:Research Grant
-
资助金额:$25.81万
-
财政年份:2017
-
负责人:Madeline Carr
-
依托单位:
International Cooperation on Cyber Security for Critical Information Infrastructure Protection (Cybersecurity of the Internet of Things Hub)
-
批准号:EP/N022785/1
-
项目类别:Research Grant
-
资助金额:$20.17万
-
财政年份:2016
-
负责人:Madeline Carr
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Cyber体系脆弱性仿真分析方法研究
-
批准号:61403400
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2014
-
负责人:许相莉
-
依托单位:
基于复杂网络理论的Cyber体系效能仿真分析方法研究
-
批准号:61374179
-
项目类别:面上项目
-
资助金额:77.0万元
-
批准年份:2013
-
负责人:胡晓峰
-
依托单位:
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
-
批准号:61300132
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2013
-
负责人:王竹晓
-
依托单位:
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
-
批准号:61174035
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2011
-
负责人:贺筱媛
-
依托单位:
基于Cyber空间的体系脆弱性仿真分析方法研究
-
批准号:61174156
-
项目类别:面上项目
-
资助金额:59.0万元
-
批准年份:2011
-
负责人:胡晓峰
-
依托单位: