OBSERVING CYBER SECURITY INCIDENT RESPONSE:QUALITATIVE THEMES FROM FIELD RESEARCH

38Citations
Citations of this article
105Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Cyber security increasingly focuses on the challenges faced by network defenders. Cultural and securitydriven sentiments about external observation, as well as publication concerns, limit the ability of researchers to understand the context surrounding incident response. Context awareness is crucial to inform design and engineering. Furthermore, these perspectives can be heavily influenced by the targeted sector or industry of the research. Together, a lack of broad contextual understanding may be biasing approaches to improving operations, and driving faulty assumptions in cyber teams. A qualitative field study was conducted in three computer security incident response teams (CSIRTs) and included perspectives of government, academia, and private sector teams. Themes emerged and provide insights across multiple aspects of incident response, including information sharing, organization, learning, and automation. The need to focus on vertical integration of issues at different levels of the incident response system is also discussed. Future research will build upon these results, using them to inform technology advancement in CSIR settings.

Cite

CITATION STYLE

APA

Nyre-Yu, M., Gutzwiller, R. S., & Caldwell, B. S. (2019). OBSERVING CYBER SECURITY INCIDENT RESPONSE:QUALITATIVE THEMES FROM FIELD RESEARCH. In Proceedings of the Human Factors and Ergonomics Society (Vol. 63, pp. 437–431). SAGE Publications Inc. https://doi.org/10.1177/1071181319631016

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free