Cargando…

Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation

It is important to have and use standardized terminology and develop a comprehensive common understanding of what is meant by cyber security and cyber security risk given the multidisciplinary nature of cyber security and the pervasiveness of cyber security concerns throughout society. Using expert...

Descripción completa

Detalles Bibliográficos
Autores principales: Cains, Mariana G., Flora, Liberty, Taber, Danica, King, Zoe, Henshel, Diane S.
Formato: Online Artículo Texto
Lenguaje:English
Publicado: John Wiley and Sons Inc. 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9543401/
https://www.ncbi.nlm.nih.gov/pubmed/33586204
http://dx.doi.org/10.1111/risa.13687
_version_ 1784804364816220160
author Cains, Mariana G.
Flora, Liberty
Taber, Danica
King, Zoe
Henshel, Diane S.
author_facet Cains, Mariana G.
Flora, Liberty
Taber, Danica
King, Zoe
Henshel, Diane S.
author_sort Cains, Mariana G.
collection PubMed
description It is important to have and use standardized terminology and develop a comprehensive common understanding of what is meant by cyber security and cyber security risk given the multidisciplinary nature of cyber security and the pervasiveness of cyber security concerns throughout society. Using expert elicitation methods, collaborating cyber researchers from multiple disciplines and two sectors (academia, government–military) were individually interviewed and asked to define cyber security and cyber security risk. Data‐driven thematic analysis was used to identify the most salient themes within each definition, sector, and cyber expert group as a whole with results compared to current standards definitions. Network analysis was employed to visualize the interconnection of salient themes within and across sectors and disciplines. When examined as a whole group, “context‐driven,” “resilient system functionality,” and “maintenance of CIA (confidentiality, integrity, availability)” were the most salient themes and influential network nodes for the definition of cyber security, while “impacts of CIA vulnerabilities,” “probabilities of outcomes,” and “context‐driven” were the most salient themes for cyber security risk. We used this expert elicitation process to develop comprehensive definitions of cyber security (cybersecurity) and cyber security risk that encompass the contextual frameworks of all the disciplines represented in the collaboration and explicitly incorporates human factors as significant cyber security risk factors.
format Online
Article
Text
id pubmed-9543401
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher John Wiley and Sons Inc.
record_format MEDLINE/PubMed
spelling pubmed-95434012022-10-14 Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation Cains, Mariana G. Flora, Liberty Taber, Danica King, Zoe Henshel, Diane S. Risk Anal Original Research Articles It is important to have and use standardized terminology and develop a comprehensive common understanding of what is meant by cyber security and cyber security risk given the multidisciplinary nature of cyber security and the pervasiveness of cyber security concerns throughout society. Using expert elicitation methods, collaborating cyber researchers from multiple disciplines and two sectors (academia, government–military) were individually interviewed and asked to define cyber security and cyber security risk. Data‐driven thematic analysis was used to identify the most salient themes within each definition, sector, and cyber expert group as a whole with results compared to current standards definitions. Network analysis was employed to visualize the interconnection of salient themes within and across sectors and disciplines. When examined as a whole group, “context‐driven,” “resilient system functionality,” and “maintenance of CIA (confidentiality, integrity, availability)” were the most salient themes and influential network nodes for the definition of cyber security, while “impacts of CIA vulnerabilities,” “probabilities of outcomes,” and “context‐driven” were the most salient themes for cyber security risk. We used this expert elicitation process to develop comprehensive definitions of cyber security (cybersecurity) and cyber security risk that encompass the contextual frameworks of all the disciplines represented in the collaboration and explicitly incorporates human factors as significant cyber security risk factors. John Wiley and Sons Inc. 2021-02-14 2022-08 /pmc/articles/PMC9543401/ /pubmed/33586204 http://dx.doi.org/10.1111/risa.13687 Text en © 2021 The Authors. Risk Analysis published by Wiley Periodicals LLC on behalf of Society for Risk Analysis. https://creativecommons.org/licenses/by-nc-nd/4.0/This is an open access article under the terms of the http://creativecommons.org/licenses/by-nc-nd/4.0/ (https://creativecommons.org/licenses/by-nc-nd/4.0/) License, which permits use and distribution in any medium, provided the original work is properly cited, the use is non‐commercial and no modifications or adaptations are made.
spellingShingle Original Research Articles
Cains, Mariana G.
Flora, Liberty
Taber, Danica
King, Zoe
Henshel, Diane S.
Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation
title Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation
title_full Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation
title_fullStr Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation
title_full_unstemmed Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation
title_short Defining Cyber Security and Cyber Security Risk within a Multidisciplinary Context using Expert Elicitation
title_sort defining cyber security and cyber security risk within a multidisciplinary context using expert elicitation
topic Original Research Articles
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9543401/
https://www.ncbi.nlm.nih.gov/pubmed/33586204
http://dx.doi.org/10.1111/risa.13687
work_keys_str_mv AT cainsmarianag definingcybersecurityandcybersecurityriskwithinamultidisciplinarycontextusingexpertelicitation
AT floraliberty definingcybersecurityandcybersecurityriskwithinamultidisciplinarycontextusingexpertelicitation
AT taberdanica definingcybersecurityandcybersecurityriskwithinamultidisciplinarycontextusingexpertelicitation
AT kingzoe definingcybersecurityandcybersecurityriskwithinamultidisciplinarycontextusingexpertelicitation
AT hensheldianes definingcybersecurityandcybersecurityriskwithinamultidisciplinarycontextusingexpertelicitation