Leveraging behavioral science to mitigate cyber security risk
Title | Leveraging behavioral science to mitigate cyber security risk |
Publication Type | Journal Article |
Year of Publication | 2012 |
Authors | Shari Lawrence Pfleegera, Deanna Caputo |
Journal | Science Direct |
Volume | 31 |
Start Page | 597 |
Issue | 4 |
Pagination | 597 - 611 |
Date Published | June 2012 |
Keywords | Articles of Interest, C3E 2019, Cognitive Security, Cognitive Security in Cyber |
Abstract | Most efforts to improve cyber security focus primarily on incorporating new technological approaches in products and processes. However, a key element of improvement involves acknowledging the importance of human behavior when designing, building and using cyber security technology. In this survey paper, we describe why incorporating an understanding of human behavior into cyber security products and processes can lead to more effective technology. We present two examples: the first demonstrates how leveraging behavioral science leads to clear improvements, and the other illustrates how behavioral science offers the potential for significant increases in the effectiveness of cyber security. Based on feedback collected from practitioners in preliminary interviews, we narrow our focus to two important behavioral aspects: cognitive load and bias. Next, we identify proven and potential behavioral science findings that have cyber security relevance, not only related to cognitive load and bias but also to heuristics and behavioral science models. We conclude by suggesting several next steps for incorporating behavioral science findings in our technological design, development and use. |
URL | https://www.sciencedirect.com/science/article/pii/S0167404811001659?via%3Dihub |
DOI | https://doi.org/10.1016/j.cose.2011.12.010 |
Citation Key | node-62491 |