Visible to the public Leveraging behavioral science to mitigate cyber security riskConflict Detection Enabled

TitleLeveraging behavioral science to mitigate cyber security risk
Publication TypeJournal Article
Year of Publication2012
AuthorsShari Lawrence Pfleegera, Deanna Caputo
JournalScience Direct
Volume31
Start Page597
Issue4
Pagination597 - 611
Date PublishedJune 2012
KeywordsArticles of Interest, C3E 2019, Cognitive Security, Cognitive Security in Cyber
Abstract

Most efforts to improve cyber security focus primarily on incorporating new technological approaches in products and processes. However, a key element of improvement involves acknowledging the importance of human behavior when designing, building and using cyber security technology. In this survey paper, we describe why incorporating an understanding of human behavior into cyber security products and processes can lead to more effective technology. We present two examples: the first demonstrates how leveraging behavioral science leads to clear improvements, and the other illustrates how behavioral science offers the potential for significant increases in the effectiveness of cyber security. Based on feedback collected from practitioners in preliminary interviews, we narrow our focus to two important behavioral aspects: cognitive load and bias. Next, we identify proven and potential behavioral science findings that have cyber security relevance, not only related to cognitive load and bias but also to heuristics and behavioral science models. We conclude by suggesting several next steps for incorporating behavioral science findings in our technological design, development and use.

URLhttps://www.sciencedirect.com/science/article/pii/S0167404811001659?via%3Dihub
DOIhttps://doi.org/10.1016/j.cose.2011.12.010
Citation Keynode-62491