Evaluating Cyber Security Evidence for Policy Advice: The Other Human Dimension
Evaluating Cyber Security Evidence for Policy Advice: The Other Human Dimension
批准号:
EP/P011691/1
负责人:
Madeline Carr
金额:
$29.83万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --
中文摘要
一个国家应对网络安全挑战的能力正迅速被视为全球竞争力的一个重要因素。该项目旨在了解英国政策制定界在解释、评估和理解有关网络安全的证据方面面临的挑战。政策制定者有时缺乏相关的专业知识,通常在时间紧迫的情况下,被要求评估来自各种来源的证据,包括官方威胁情报、学术来源和行业威胁报告。然后,利用这种多样化的证据基础对威胁、风险、缓解措施和后果作出判断,并提供建议,形成国家监管格局、国内外安全政策以及一系列公共和私营部门举措。这一人文因素对英国的网络安全具有重要意义,也是本提案的主要关注点。在这种情况下,证据评估是政策制定的一个特殊问题,原因有三:首先,一些证据是相互矛盾的,和/或可能带有特定的议程或目标,这可能会妨碍其严谨性和可靠性。网络安全证据的“政治化”问题日益严重,因为一些国家有时会对来自其主权境内来源的威胁情报给予特权,而不是基于其研究的质量;其次,事实证明,要确定网络攻击的原因并量化网络不安全的成本是极其困难的。这些挑战意味着,证据只能在一定程度上支持决策者对网络安全风险、威胁和后果的决策和评估;最后,网络安全领域发展迅速,涉及国家安全、人权、商业问题和相关基础设施脆弱性等多个领域。因此,决策者必须努力平衡一系列有时相互冲突的利益,这些利益争夺注意力,他们必须在一个几乎没有先例可借鉴的领域做到这一点。在探索网络安全的人为维度的问题(和可能的补救措施)时,许多人关注的是最终用户。虽然这一点很重要,但同样重要的是决策的人的层面和公务员提供的建议,他们共同影响着政策层面对网络威胁的反应。本项目重点关注英国的政策制定者,特别是那些为应对具体危机事件或在能力建设的长期规划背景下提供短期和长期政策建议的公务员。这一群体尤其重要,因为它们目前面临着一系列独特的技术、行为和政策挑战。他们是一个相对较小和不同的群体,拥有不同水平的技术和行为经验;-他们的责任和影响远远超出了他们自己的组织,以塑造国家和国际格局;最后,缺乏支持这一特定群体的研究,无论是在确定他们面临的具体挑战方面,还是在制定更有效的机制方面。这就引出了几个问题:在这种情况下,英国政策制定者依据的是什么证据?证据的质量如何?基于这些证据对威胁、风险、缓解和后果的判断是否有效?了解英国政策制定者如何选择证据,为什么他们对一个来源给予特权,以及他们在识别证据中可能存在的弱点或缺陷方面有多熟练,是解决这些问题的关键。
英文摘要
The quality of a state's capacity to respond to the challenges of cyber security is rapidly coming to be recognised as an important element of global competitiveness. This project seeks to understand the challenges faced by the UK's policy making community in interpreting, evaluating and understanding evidence about cyber security. Policy makers, sometimes with little relevant expertise and often in time-critical scenarios, are asked to assess evidence from a mix of sources including official threat intelligence, academic sources, and industry threat reports. Such a diverse evidence base is then used to make judgments on threat, risk, mitigation and consequences, and offer advice shaping the national regulatory landscape, foreign and domestic security policy, and a range of public and private sector initiatives. This element of the human dimension has significant relevance for the cyber security of the UK and is the main focus of this proposal. Assessment of evidence is a particular problem for policy making in this context for three reasons: First, some of the evidence is contradictory and/or potentially carries within it particular agendas or goals that may impede upon its rigour and reliability. The 'politicisation' of cyber security evidence is increasingly problematic as states sometimes privilege threat intelligence from sources located within their sovereign borders rather than based on the quality of the research they produce; Secondly, it has proven to be extremely difficult to conclusively attribute cyber attacks and to quantify the cost of cyber insecurity. These challenges mean that evidence can only support policy makers' decisions and evaluation of cyber security risks, threats and consequences to an extent;Finally, the landscape of cyber security is developing rapidly and spans many issue areas including national security, human rights, commercial concerns, and related infrastructure vulnerabilities. Consequently, policy makers must work to balance a range of sometimes conflicting interests that compete for attention and they must do so in a field with little precedent to draw upon.When exploring the problems (and possible remedies) of the human dimension of cyber security, many focus on end users. While this is important, equally important is the human dimension of decision making and advice offered by civil servants who collectively influence policy level responses to cyber threats. This project focuses on policy makers in the UK, specifically those civil servants who provide short and long term policy advice, either in response to specific crisis incidents or in the context of longer term planning for capacity building. This cohort is of particular importance given:- the unique set of technological, behavioural and policy challenges they currently face. They are a relatively small and disparate group, possessing varying levels of technical and behavioural experience;- their responsibility and impact goes well beyond their own organisations to shape the national and international landscape; and finally, - the lack of research to support this particular community, either in identifying specific challenges they face or in developing more effective mechanisms for doing so.This leads to several questions: what evidence do UK policy makers rely upon in this context? What is the quality of that evidence? How effective are the judgements about threats, risks, mitigation and consequences based on that evidence? Understanding how UK policy makers select evidence, why they privilege one source over another, and how adept they are at recognising possible weaknesses or flaws in evidence is central to addressing these questions.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Cyber Metrics: Getting the conversation straight between technical and non-technical actors
网络指标:技术和非技术参与者之间的直接对话
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
[Carr M]
通讯作者:
Carr M
'An Evidence Quality Assessment Model for Cybersecurity Policymaking'
“网络安全政策制定的证据质量评估模型”
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
[Hussain A]
通讯作者:
Hussain A
Using games to assess evidence informed cybersecurity policymaking
使用游戏来评估基于证据的网络安全决策
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
[Hussain A]
通讯作者:
Hussain A
RISCS Annual Report 2018
2018年RISCS年度报告
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
[Carr M]
通讯作者:
Carr M
Cyber capacity building and knowledge sharing: The UK policy community's perception of the National Cyber Security Centre
网络能力建设和知识共享:英国政策界对国家网络安全中心的看法
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
[Carr M]
通讯作者:
Carr M
共 9 条
International Cooperation on Cyber Security for Critical Information Infrastructure Protection (Cybersecurity of the Internet of Things Hub)
-
批准号:EP/N022785/2
-
项目类别:Research Grant
-
资助金额:$12.55万
-
财政年份:2017
-
负责人:Madeline Carr
-
依托单位:
Evaluating Cyber Security Evidence for Policy Advice: The Other Human Dimension
-
批准号:EP/P011691/2
-
项目类别:Research Grant
-
资助金额:$25.81万
-
财政年份:2017
-
负责人:Madeline Carr
-
依托单位:
International Cooperation on Cyber Security for Critical Information Infrastructure Protection (Cybersecurity of the Internet of Things Hub)
-
批准号:EP/N022785/1
-
项目类别:Research Grant
-
资助金额:$20.17万
-
财政年份:2016
-
负责人:Madeline Carr
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Cyber体系脆弱性仿真分析方法研究
-
批准号:61403400
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2014
-
负责人:许相莉
-
依托单位:
基于复杂网络理论的Cyber体系效能仿真分析方法研究
-
批准号:61374179
-
项目类别:面上项目
-
资助金额:77.0万元
-
批准年份:2013
-
负责人:胡晓峰
-
依托单位:
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
-
批准号:61300132
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2013
-
负责人:王竹晓
-
依托单位:
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
-
批准号:61174035
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2011
-
负责人:贺筱媛
-
依托单位:
基于Cyber空间的体系脆弱性仿真分析方法研究
-
批准号:61174156
-
项目类别:面上项目
-
资助金额:59.0万元
-
批准年份:2011
-
负责人:胡晓峰
-
依托单位: