• DocumentCode
    2019601
  • Title

    Trustworthy and effective communication of cybersecurity risks: A review

  • Author

    Nurse, Jason R C ; Creese, Sadie ; Goldsmith, Michael ; Lamberts, Koen

  • Author_Institution
    Univ. of Warwick, Coventry, UK
  • fYear
    2011
  • fDate
    8-8 Sept. 2011
  • Firstpage
    60
  • Lastpage
    68
  • Abstract
    Slowly but surely, academia and industry are fully accepting the importance of the human element as it pertains to achieving security and trust. Undoubtedly, one of the main motivations for this is the increase in attacks (e.g., social engineering and phishing) which exploit humans and exemplify why many authors regard them as the weakest link in the security chain. As research in the socio-technical security and trust fields gains momentum, it is crucial to intermittently pause and reflect on their progress while also considering related domains to determine whether there are any established principles which may be transferred. Comparison of the states-of-the-arts may assist in planning work going forward and identifying useful future directions for the less mature socio-technical field. This paper seeks to fulfil several of these goals, particularly as they relate to the emerging cybersecurity-risk communication domain. The literature reviews which we conduct here are beneficial and indeed noteworthy as they pull together a number of the key aspects which may affect the trustworthiness and effectiveness of communications on cybersecurity risks. In particular, we draw on information-trustworthiness research and the established field of risk communication. An appreciation of these aspects and precepts is imperative if systems are to be designed that play to individuals´ strengths and assist them in maintaining security and protecting their applications and information.
  • Keywords
    risk management; security of data; cybersecurity risk communication; information security; information trustworthiness research; sociotechnical security; trust fields; Computer crime; Context; Decision making; Receivers; Visualization; Cybersecurity risk; information trustworthiness; risk perception and communication; security communication recommendations;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Socio-Technical Aspects in Security and Trust (STAST), 2011 1st Workshop on
  • Conference_Location
    Milan
  • Print_ISBN
    978-1-4577-1182-4
  • Type

    conf

  • DOI
    10.1109/STAST.2011.6059257
  • Filename
    6059257