Abstract
Computer security incident response teams (CSIRTs) are critical to maintaining business continuity in the face of cyber-attacks. Yet there has been little research conducted in the last decade to understand the root causes of the challenges they face to sustain their effectiveness. Moreover, they operate in complex sociotechnical multiteam systems, making it challenging to understand the causes of problems and how to bring about improvements. This paper proposes the use of a Systemic Design approach to develop a more in-depth understanding of the complex sociotechnical system(s) of cyber security incident response, in order to find intervention points that can be leveraged in one area to transition the whole system into a better state. We present the first steps of a case study that uses Gigamap workshops and in-depth interviews with a range of stakeholders to frame the system and understand its effectiveness.
| Original language | English |
|---|---|
| Title of host publication | NSPW '24: Proceedings of the New Security Paradigms Workshop |
| Publisher | Association for Computing Machinery |
| Pages | 71-83 |
| Number of pages | 13 |
| ISBN (Electronic) | 9798400711282 |
| DOIs | |
| Publication status | Published - 16 Jan 2025 |
Publication series
| Name | 2024 New Security Paradigms Workshop, NSPW 2024 |
|---|
Bibliographical note
Publisher Copyright:Copyright © 2024 held by the owner/author(s).
Fingerprint
Dive into the research topics of 'Adopting a Systemic Design Approach to Cyber Security Incident Response'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver