Change that Respects Business Expertise: Stories as Prompts for a Conversation about Organisation Security

S. Parkin, Simon Arnell, Jeremy Ward
{"title":"Change that Respects Business Expertise: Stories as Prompts for a Conversation about Organisation Security","authors":"S. Parkin, Simon Arnell, Jeremy Ward","doi":"10.1145/3498891.3498895","DOIUrl":null,"url":null,"abstract":"Leaders of organisations must make investment decisions relating to the security of their organisation. This often happens through consultation with a security specialist. Consultations may be regarded as conversations taking place in a trading zone between the two domains. We propose that supporting the trading zone is a route to sustainable, workable security change improvements. Prompts for such improvements are already in place, in the security stories that reach business leaders through news media, or anecdotes from trusted peers. However, a shift in perspective is needed to view these stories and anecdotes as prompts for individual decision makers to enter into the trading zone with security specialists. We illustrate how to facilitate this shift by recasting security ontology tools, previously centred around security-specific expertise, as a support device to enrich conversations between business expertise and security advice toward finding workable security choices. We frame our proposal within a broader view of community transformation, exploring the important principle of identifying practical opportunities to inform discussions about security solutions that are appropriate in the business context. Community-level discussions have potential to lead to more lasting, effective improvements than those instigated by one-way interventions from security specialists. We extend the view, applying the paradigm to articulate the importance of two-way conversations between business peers and security specialists.","PeriodicalId":320273,"journal":{"name":"Proceedings of the 2021 New Security Paradigms Workshop","volume":"28 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-10-25","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 2021 New Security Paradigms Workshop","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3498891.3498895","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Leaders of organisations must make investment decisions relating to the security of their organisation. This often happens through consultation with a security specialist. Consultations may be regarded as conversations taking place in a trading zone between the two domains. We propose that supporting the trading zone is a route to sustainable, workable security change improvements. Prompts for such improvements are already in place, in the security stories that reach business leaders through news media, or anecdotes from trusted peers. However, a shift in perspective is needed to view these stories and anecdotes as prompts for individual decision makers to enter into the trading zone with security specialists. We illustrate how to facilitate this shift by recasting security ontology tools, previously centred around security-specific expertise, as a support device to enrich conversations between business expertise and security advice toward finding workable security choices. We frame our proposal within a broader view of community transformation, exploring the important principle of identifying practical opportunities to inform discussions about security solutions that are appropriate in the business context. Community-level discussions have potential to lead to more lasting, effective improvements than those instigated by one-way interventions from security specialists. We extend the view, applying the paradigm to articulate the importance of two-way conversations between business peers and security specialists.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
尊重业务专长的变革:组织安全对话的故事提示
组织的领导者必须做出与组织安全相关的投资决策。这通常是通过咨询安全专家来实现的。磋商可被视为在两个领域之间的贸易区内进行的对话。我们建议,支持自贸区是一条可持续、可行的安全变革改进之路。企业领导人通过新闻媒体了解到的安全故事,或者来自值得信赖的同行的轶事,都已经有了这种改进的提示。然而,需要转变观点,将这些故事和轶事视为促使个别决策者与安全专家进入交易区的提示。我们将通过重新定义安全本体工具(以前以特定于安全的专业知识为中心)来说明如何促进这种转变,将其作为一种支持设备,以丰富业务专业知识和安全建议之间的对话,从而找到可行的安全选择。我们在更广阔的社区转型视野中构建了我们的建议,探索了确定实际机会的重要原则,以便为有关适合业务环境的安全解决方案的讨论提供信息。社区层面的讨论比安全专家的单向干预有可能带来更持久、更有效的改进。我们扩展了这个观点,应用这个范例来阐明业务同行和安全专家之间双向对话的重要性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Blessed Are The Lawyers, For They Shall Inherit Cybersecurity COLBAC: Shifting Cybersecurity from Hierarchical to Horizontal Designs Change that Respects Business Expertise: Stories as Prompts for a Conversation about Organisation Security The tragedy of common bandwidth: rDDoS “Taking out the Trash”: Why Security Behavior Change requires Intentional Forgetting
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1