Characterising assurance: scepticism and mistrust in cyber security

被引:3
|
作者
Spencer, Matt [1 ]
机构
[1] Univ Warwick, Ctr Interdisciplinary Methodol, Coventry, W Midlands, England
基金
英国科研创新办公室;
关键词
Cyber security; assurance; characterisation; mistrust; narrative; TECHNOLOGY; SCIENCE;
D O I
10.1080/17530350.2022.2098515
中图分类号
G [文化、科学、教育、体育]; C [社会科学总论];
学科分类号
03 ; 0303 ; 04 ;
摘要
This paper presents an analysis of recent transformations in cyber security assurance, a field of evaluation that aims to establish whether technical products are secure. I work from a set of narratives about problems with assurance, drawn from interviews with practitioners based in the UK. I focus on characterisation: the stories practitioners tell, the cast of characters that populate them, and how such stories act to problematise the domain. Mistrust, it is argued, can be understood in terms of the capacities of sceptical narratives to efface the power of security certifications to be taken on 'face value.' A text-based view of mistrust is thus developed that can be differentiated from the conventional disposition-centred view. Examining mistrust, then, leads us to ask not how to change dispositions to make them 'more trusting,' but rather to critical questions about the palette of characters that feature in cyber security. I close the essay by offering a commentary on the way characterisation leads to the anticipation of experts in formulations of policy and on the possible 'counter-characterisation' that might be developed, for instance around 'caring' characters.
引用
收藏
页数:16
相关论文
共 50 条
  • [1] Cyber Mission Assurance for Cyber Security
    MacKay M.
    ITNOW, 2020, 62 (01) : 32 - 33
  • [2] Importance of Cyber Security in Software Quality Assurance
    Haider, Ammar
    Bhatti, Wafa
    2022 17TH INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES (ICET'22), 2022, : 6 - 11
  • [3] A Requirements Optimization Method for Automotive Cyber Security Assurance
    Zhou, Zhengshu
    Yang, Xinqi
    Long, Qian
    Wang, Gaihua
    Zhi, Qiang
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT X, ICIC 2024, 2024, 14871 : 506 - 513
  • [4] Systems and Software Assurance - A Model Cyber Security Course
    Jovanovic, V.
    Harris, J. K.
    2016 39TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2016, : 923 - 927
  • [5] Model-Driven Cyber Range Training: A Cyber Security Assurance Perspective
    Somarakis, Iason
    Smyrlis, Michail
    Fysarakis, Konstantinos
    Spanoudakis, George
    COMPUTER SECURITY: ESORICS 2019 INTERNATIONAL WORKSHOPS, IOSEC, MSTEC, AND FINSEC, 2020, 11981 : 172 - 184
  • [6] Cyber security assurance process from the internal audit perspective
    Kahyaoglu, Sezer Bozkus
    Caliyurt, Kiymet
    MANAGERIAL AUDITING JOURNAL, 2018, 33 (04) : 360 - 376
  • [7] Security Assurance Cases for Medical Cyber-Physical Systems
    Ray, Arnab
    Cleaveland, Rance
    IEEE DESIGN & TEST, 2015, 32 (05) : 56 - 65
  • [8] International cyber security strategy as a tool for comprehensive security assurance of civil aviation security: methodological considerations
    Grygorov, Oleksandr
    Basysta, Albina
    Yedeliev, Roman
    Paziuk, Andrii
    Tropin, Zakhar
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2021, 21 (09): : 332 - 338
  • [9] Cyber security与assurance的内涵及中译名
    南湘浩
    中国科技术语, 2014, 16 (06) : 22+24 - 22
  • [10] Cyber Security and Global Information Assurance: Threat Analysis and Response Solutions
    Kessler, Gary C.
    JOURNAL OF DIGITAL FORENSICS SECURITY AND LAW, 2009, 4 (03) : 57 - 59