The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan

08/03/2022
by   Katja Tuma, et al.
0

Cybersecurity threat and risk analysis (RA) approaches are used to identify and mitigate security risks early-on in the software development life-cycle. Existing approaches automate only parts of the analysis procedure, leaving key decisions in identification, feasibility and risk analysis, and quality assessment to be determined by expert judgement. Therefore, in practice teams of experts manually analyze the system design by holding brainstorming workshops. Such decisions are made in face of uncertainties, leaving room for biased judgement (e.g., preferential treatment of category of experts). Biased decision making during the analysis may result in unequal contribution of expertise, particularly since some diversity dimensions (i.e., gender) are underrepresented in security teams. Beyond the work of risk perception of non-technical threats, no existing work has empirically studied the role of diversity in the risk analysis of technical artefacts. This paper proposes an experimental plan for identifying the key diversity factors in RA.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/08/2019

Finding Security Threats That Matter: An Industrial Case Study

Recent trends in the software engineering (i.e., Agile, DevOps) have sho...
research
04/01/2021

The best laid plans or lack thereof: Security decision-making of different stakeholder groups

Cyber security requirements are influenced by the priorities and decisio...
research
05/23/2019

Perceptions of Gender Diversity's impact on mood in software development teams

Recent studies show that gender diversity in IT teams has a positive imp...
research
08/02/2022

Human Aspect of Threat Analysis: A Replication

Background: Organizations are experiencing an increasing demand for secu...
research
07/05/2023

Security Risk Analysis Methodologies for Automotive Systems

Nowadays, systematic security risk analysis plays a vital role in the au...
research
12/29/2017

Threat Modeling Data Analysis in Socio-technical Systems

Our decision-making processes are becoming more data driven, based on da...
research
07/13/2023

Assessing MSDs before Introduction of a Cobot: Psychosocial Aspects and Employee's Subjective Experience

Musculoskeletal disorders (MSDs) are one of the main causes of work disa...

Please sign up or login with your details

Forgot password? Click here to reset