{"title":"多样性在网络安全风险分析中的作用:一个实验计划","authors":"Katja Tuma, R. V. D. Lee","doi":"10.1145/3524501.3527595","DOIUrl":null,"url":null,"abstract":"Cybersecurity threat and risk analysis (RA) approaches are used to identify and mitigate security risks early-on in the software development life-cycle. Existing approaches automate only parts of the analysis procedure, leaving key decisions in identification, feasibility and risk analysis, and quality assessment to be determined by expert judgement. Therefore, in practice teams of experts manually analyze the system design by holding brainstorming workshops. Such decisions are made in face of uncertainties, leaving room for biased judgement (e.g., preferential treatment of category of experts). Biased decision making during the analysis may result in unequal contribution of expertise, particularly since some diversity dimensions (i.e., gender) are underrepresented in security teams. Beyond the work of risk perception of non-technical threats, no existing work has empirically studied the role of diversity in the risk analysis of technical artefacts. This paper proposes an experimental plan for identifying the key diversity factors in RA. ACM Reference Format: Katja Tuma and Romy Van Der Lee. 2022. The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan. In Third Workshop on Gender Equaliry, Diversity, and Inclusion in Software Engineering (GE@ICSE’22), May 20, 2022, Pittsburgh, PA, USA. ACM, New York, NY, USA, 7 pages. https://doi.org/10.1145/3524501.3527242","PeriodicalId":46962,"journal":{"name":"Equality Diversity and Inclusion","volume":"1 1","pages":"12-18"},"PeriodicalIF":2.0000,"publicationDate":"2022-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan\",\"authors\":\"Katja Tuma, R. V. D. Lee\",\"doi\":\"10.1145/3524501.3527595\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Cybersecurity threat and risk analysis (RA) approaches are used to identify and mitigate security risks early-on in the software development life-cycle. Existing approaches automate only parts of the analysis procedure, leaving key decisions in identification, feasibility and risk analysis, and quality assessment to be determined by expert judgement. Therefore, in practice teams of experts manually analyze the system design by holding brainstorming workshops. Such decisions are made in face of uncertainties, leaving room for biased judgement (e.g., preferential treatment of category of experts). Biased decision making during the analysis may result in unequal contribution of expertise, particularly since some diversity dimensions (i.e., gender) are underrepresented in security teams. Beyond the work of risk perception of non-technical threats, no existing work has empirically studied the role of diversity in the risk analysis of technical artefacts. This paper proposes an experimental plan for identifying the key diversity factors in RA. ACM Reference Format: Katja Tuma and Romy Van Der Lee. 2022. The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan. In Third Workshop on Gender Equaliry, Diversity, and Inclusion in Software Engineering (GE@ICSE’22), May 20, 2022, Pittsburgh, PA, USA. ACM, New York, NY, USA, 7 pages. https://doi.org/10.1145/3524501.3527242\",\"PeriodicalId\":46962,\"journal\":{\"name\":\"Equality Diversity and Inclusion\",\"volume\":\"1 1\",\"pages\":\"12-18\"},\"PeriodicalIF\":2.0000,\"publicationDate\":\"2022-05-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Equality Diversity and Inclusion\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1145/3524501.3527595\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"MANAGEMENT\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Equality Diversity and Inclusion","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3524501.3527595","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"MANAGEMENT","Score":null,"Total":0}
引用次数: 0
摘要
网络安全威胁和风险分析(RA)方法用于在软件开发生命周期的早期识别和减轻安全风险。现有的方法只能自动化部分分析过程,而将识别、可行性和风险分析以及质量评估中的关键决策留给专家判断。因此,在实践中,专家团队通过举行头脑风暴研讨会来手动分析系统设计。这类决定是在不确定的情况下作出的,给有偏见的判断留下了余地(例如,对某类专家给予优惠待遇)。在分析过程中有偏见的决策可能导致专业知识的贡献不平等,特别是因为某些多样性方面(即性别)在安全小组中代表性不足。除了非技术威胁的风险感知工作之外,没有现有的工作经验地研究了多样性在技术工件风险分析中的作用。本文提出了一种识别RA关键多样性因子的实验方案。ACM参考格式:Katja Tuma and Romy Van Der Lee. 2022。多样性在网络安全风险分析中的作用:一个实验计划。在性别平等,多样性和包容性软件工程(GE@ICSE ' 22)的第三次研讨会,2022年5月20日,匹兹堡,宾夕法尼亚州,美国。ACM,纽约,美国,7页。https://doi.org/10.1145/3524501.3527242
The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan
Cybersecurity threat and risk analysis (RA) approaches are used to identify and mitigate security risks early-on in the software development life-cycle. Existing approaches automate only parts of the analysis procedure, leaving key decisions in identification, feasibility and risk analysis, and quality assessment to be determined by expert judgement. Therefore, in practice teams of experts manually analyze the system design by holding brainstorming workshops. Such decisions are made in face of uncertainties, leaving room for biased judgement (e.g., preferential treatment of category of experts). Biased decision making during the analysis may result in unequal contribution of expertise, particularly since some diversity dimensions (i.e., gender) are underrepresented in security teams. Beyond the work of risk perception of non-technical threats, no existing work has empirically studied the role of diversity in the risk analysis of technical artefacts. This paper proposes an experimental plan for identifying the key diversity factors in RA. ACM Reference Format: Katja Tuma and Romy Van Der Lee. 2022. The Role of Diversity in Cybersecurity Risk Analysis: An Experimental Plan. In Third Workshop on Gender Equaliry, Diversity, and Inclusion in Software Engineering (GE@ICSE’22), May 20, 2022, Pittsburgh, PA, USA. ACM, New York, NY, USA, 7 pages. https://doi.org/10.1145/3524501.3527242