首页> 外文会议>International Working Conference on Requirements Engineering: Foundation for Software Quality >The Role of Catalogues of Threats and Security Controls in Security Risk Assessment: An Empirical Study with ATM Professionals
【24h】

The Role of Catalogues of Threats and Security Controls in Security Risk Assessment: An Empirical Study with ATM Professionals

机译:威胁和安全控制目录在安全风险评估中的作用:与ATM专业人员的实证研究

获取原文

摘要

[Context and motivation] To remedy the lack of security expertise, industrial security risk assessment methods come with catalogues of threats and security controls. [Question/problem] We investigate in both qualitative and quantitative terms whether the use of catalogues of threats and security controls has an effect on the actual and perceived effectiveness of a security risk assessment method. In particular, we assessed the effect of using domain-specific versus domain-general catalogues on the actual and perceived efficacy of a security risk assessment method conducted by non-experts and compare it with the effect of running the same method by security experts but without catalogues. [Principal ideas/results] The quantitative analysis shows that non-security experts who applied the method with catalogues identified threats and controls of the same quality of security experts without catalogues. The perceived ease of use was higher when participants used method without catalogues albeit only at 10% significance level. The qualitative analysis indicates that security experts have different expectations from a catalogue than non-experts. Non-experts are mostly worried about the difficulty of navigating through the catalogue (the larger and less specific the worse it was) while expert users found it mostly useful to get a common terminology and a checklist that nothing was forgotten. [Contribution] This paper sheds light on the important features of the catalogues and discuss how they contribute into risk assessment process.
机译:[背景和动机]弥补缺乏安全专业知识,工业安全风险评估方法附有威胁和安全控制目录。 [问题/问题]我们以定性和定量术语调查,是否使用威胁和安全控制目录的使用对安全风险评估方法的实际和感知有效性有影响。特别是,我们评估了使用域特定的与域一般目录对非专家进行的安全风险评估方法的实际和感知疗效的影响,并将其与安全专家运行相同的方法的效果进行比较,但没有目录。 [主要思想/结果]定量分析表明,使用目录应用该方法的非安全专家确定了没有目录的相同安全专家质量的威胁和控制。当参与者使用过目录的方法时,感知的易用性更高,尽管仅以10%的显着性水平。定性分析表明,安全专家与非专家的目录不同的期望。非专家大多担心通过目录导航的难度(越来越且更差的情况),而专家用户发现它主要有用,以获得共同的术语和一份清单,没有任何遗忘。 [贡献]本文阐明了目录的重要特征,并讨论它们如何促进风险评估过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号