The good, the bad and the ugly: a study of security decisions in a cyber-physical systems game
Abstract
Motivation: The security of any system is a direct consequence of stakeholders' decisions regarding security requirements. Such decisions are taken with varying degrees of expertise, and little is currently understood about how various demographics - security experts, general computer scientists, managers - approach security decisions and the strategies that underpin those decisions. What are the typical decision patterns, the consequences of such patterns and their impact on the security of the system in question? Nor is there any substantial understanding of how the strategies and decision patterns of these different groups contrast. Is security expertise necessarily an advantage when making security decisions in a given context? Answers to these questions are key to understanding the "how" and "why" behind security decision processes.
BibTeX
@inproceedings{Frey-al:ICSE18,
author = {Sylvain Frey and
Awais Rashid and
Pauline Anthonysamy and
Maria Pinto{-}Albuquerque and
Syed Asad Naqvi},
title = {The good, the bad and the ugly: a study of security decisions in a cyber-physical systems game},
booktitle = {ICSE},
pages = {496},
publisher = {{ACM}},
year = {2018},
}