首页> 外文期刊>Security Informatics >Factors influencing network risk judgments: a conceptual inquiry and exploratory analysis
【24h】

Factors influencing network risk judgments: a conceptual inquiry and exploratory analysis

机译:影响网络风险判断的因素:概念性探究和探索性分析

获取原文
           

摘要

Abstract Effectively assessing and configuring security controls to minimize network risks requires human judgment. Little is known about what factors network professionals perceive to make judgments of network risk. The purpose of this research was to examine first, what factors are important to network risk judgments (Study 1) and second, how risky/safe each factor is judged (Study 2) by a sample of network professionals. In Study 1, a complete list of factors was generated using a focus group method and validated on a broader sample using a survey method with network professionals. Factors detailing the adversary and organizational network readiness were rated highly important. Study 2 investigated the level of riskiness for each factor that is described in a vignette-based factor scenario. The vignette provided context that was missing in Study 1. The highest riskiness ratings were of factors detailing the adversary and the lowest riskiness ratings detailed the organizational network readiness. A significant relationships existed in Study 2 between the level of agreement on each factor’s rating across our sample of network professionals and the riskiness level each factor was judged. Factors detailing the adversary were highly agreed upon while factors detailing the organizational capability were less agreed upon. Computational risk models and network risk metrics ask professionals to perceive factors and judge overall network risk levels but no published research exists on what factors are important for network risk judgments. These empirical findings address this gap and factors used in models and metrics could be compared to factors generated herein. Future research and implications are discussed at the close of this paper.
机译:摘要有效评估和配置安全控制以最大程度地降低网络风险需要人工判断。对于网络专业人员认为哪些因素可以做出网络风险判断知之甚少。这项研究的目的是首先检查哪些因素对网络风险判断很重要(研究1),其次检查网络专业人员样本如何判断每个因素的风险/安全性(研究2)。在研究1中,使用焦点小组方法生成了因素的完整列表,并使用网络专业人员的调查方法对更广泛的样本进行了验证。评估对手和组织网络准备情况的因素被认为非常重要。研究2调查了在基于晕影的因素场景中描述的每个因素的风险水平。该插图提供了研究1中所缺少的背景。最高风险等级是详细说明对手的因素,而最低风险等级是详细说明组织网络准备情况的因素。在研究2中,在我们网络专业人员样本中对每个因素的评分的一致程度与对每个因素的风险程度的判断之间存在着显着的关系。高度详细地说明了对手的因素,而较少详细说明了组织能力的因素。计算风险模型和网络风险度量要求专业人士感知因素并判断总体网络风险水平,但尚无关于哪些因素对网络风险判断重要的公开研究。这些经验发现解决了这个空白,可以将模型和指标中使用的因素与此处生成的因素进行比较。本文的末尾讨论了未来的研究和意义。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号