O'Neill School of Public and Environmental Affairs, Indiana University, Bloomington, IN, USA.
Risk Anal. 2022 Aug;42(8):1643-1669. doi: 10.1111/risa.13687. Epub 2021 Feb 14.
It is important to have and use standardized terminology and develop a comprehensive common understanding of what is meant by cyber security and cyber security risk given the multidisciplinary nature of cyber security and the pervasiveness of cyber security concerns throughout society. Using expert elicitation methods, collaborating cyber researchers from multiple disciplines and two sectors (academia, government-military) were individually interviewed and asked to define cyber security and cyber security risk. Data-driven thematic analysis was used to identify the most salient themes within each definition, sector, and cyber expert group as a whole with results compared to current standards definitions. Network analysis was employed to visualize the interconnection of salient themes within and across sectors and disciplines. When examined as a whole group, "context-driven," "resilient system functionality," and "maintenance of CIA (confidentiality, integrity, availability)" were the most salient themes and influential network nodes for the definition of cyber security, while "impacts of CIA vulnerabilities," "probabilities of outcomes," and "context-driven" were the most salient themes for cyber security risk. We used this expert elicitation process to develop comprehensive definitions of cyber security (cybersecurity) and cyber security risk that encompass the contextual frameworks of all the disciplines represented in the collaboration and explicitly incorporates human factors as significant cyber security risk factors.
鉴于网络安全的多学科性质和网络安全问题在整个社会的普遍存在,拥有并使用标准化术语并对网络安全和网络安全风险有一个全面的共同理解非常重要。研究人员采用专家启发式方法,对来自多个学科和两个领域(学术界、政府-军队)的合作网络研究人员进行了单独访谈,并要求他们定义网络安全和网络安全风险。使用数据驱动的主题分析方法,确定了每个定义、每个领域以及整个网络专家群体中最突出的主题,并将结果与当前的标准定义进行了比较。网络分析用于可视化各个领域和学科内部以及跨领域的突出主题之间的相互联系。当作为一个整体群体进行检查时,“上下文驱动”、“弹性系统功能”和“维护 CIA(机密性、完整性、可用性)”是网络安全定义中最突出的主题和有影响力的网络节点,而“CIA 漏洞的影响”、“结果的可能性”和“上下文驱动”是网络安全风险中最突出的主题。我们使用这种专家启发式方法来制定全面的网络安全(网络安全)和网络安全风险定义,这些定义涵盖了合作中所有学科的上下文框架,并明确将人为因素作为重要的网络安全风险因素。