Acting in the unknown: the cynefin framework for managing cybersecurity risk in dynamic decision making

J. Dykstra, S. R. Orr
{"title":"Acting in the unknown: the cynefin framework for managing cybersecurity risk in dynamic decision making","authors":"J. Dykstra, S. R. Orr","doi":"10.1109/CYCONUS.2016.7836616","DOIUrl":null,"url":null,"abstract":"Researchers have shown that human decision making in complex environments like cyber is a significant risk factor. Unfortunately, much work on cyber situational awareness has been technology-focused, despite the ultimate importance of human decisions, especially in crisis situations like real-time cyber-attacks and data breaches. Cybersecurity practitioners and leaders require an appropriate framework to help decision makers at all levels guide and act while managing risk in unexpected and dynamic situations. Without such a framework, failure to enlighten the unknown leads to heightened risk, uncertainty, and insecurity. The ability to establish context, adapt, and apply the most appropriate decision-making style to unique situations increases the likelihood of security. We offer an application of the Cynefin Framework, a sensemaking solution, to cybersecurity which allows practitioners and leaders to identify the context and appropriate response type in complex situations using the cause-and-effect relationship. We also illustrate how orienting oneself in the five Cynefin domains – disorder, obvious, complicated, complex, and chaotic – can help manage risk. By comparing Cynefin to other decision-making frameworks, we show how this framework is uniquely appropriate for acting through complexity and risk in cyber.","PeriodicalId":358914,"journal":{"name":"2016 International Conference on Cyber Conflict (CyCon U.S.)","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 International Conference on Cyber Conflict (CyCon U.S.)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CYCONUS.2016.7836616","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9

Abstract

Researchers have shown that human decision making in complex environments like cyber is a significant risk factor. Unfortunately, much work on cyber situational awareness has been technology-focused, despite the ultimate importance of human decisions, especially in crisis situations like real-time cyber-attacks and data breaches. Cybersecurity practitioners and leaders require an appropriate framework to help decision makers at all levels guide and act while managing risk in unexpected and dynamic situations. Without such a framework, failure to enlighten the unknown leads to heightened risk, uncertainty, and insecurity. The ability to establish context, adapt, and apply the most appropriate decision-making style to unique situations increases the likelihood of security. We offer an application of the Cynefin Framework, a sensemaking solution, to cybersecurity which allows practitioners and leaders to identify the context and appropriate response type in complex situations using the cause-and-effect relationship. We also illustrate how orienting oneself in the five Cynefin domains – disorder, obvious, complicated, complex, and chaotic – can help manage risk. By comparing Cynefin to other decision-making frameworks, we show how this framework is uniquely appropriate for acting through complexity and risk in cyber.
在未知中行动:动态决策中管理网络安全风险的动态框架
研究人员表明,在网络等复杂环境中,人类的决策是一个重要的风险因素。不幸的是,尽管人类决策的最终重要性,特别是在实时网络攻击和数据泄露等危机情况下,许多关于网络态势感知的工作都是以技术为中心的。网络安全从业者和领导者需要一个适当的框架来帮助各级决策者在管理意外和动态情况下的风险时进行指导和行动。如果没有这样一个框架,就无法启发未知的事物,从而导致风险、不确定性和不安全感的增加。建立上下文、适应和应用最合适的决策风格的能力增加了安全的可能性。我们将Cynefin框架应用于网络安全,这是一种意义构建解决方案,允许从业者和领导者在复杂情况下使用因果关系识别上下文和适当的响应类型。我们还说明了如何将自己定位在五个Cynefin领域-无序,明显,复杂,复杂和混乱-可以帮助管理风险。通过将Cynefin与其他决策框架进行比较,我们展示了该框架如何独特地适用于应对网络中的复杂性和风险。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信