2012
DOI: 10.1117/12.919338
|View full text |Cite
|
Sign up to set email alerts
|

Cyber situation awareness as distributed socio-cognitive work

Abstract: A key challenge for human cybersecurity operators is to develop an understanding of what is happening within, and to, their network. This understanding, or situation awareness, provides the cognitive basis for human operators to take action within their environments. Yet developing situation awareness of cyberspace (cyber-SA) is understood to be extremely difficult given the scope of the operating environment, the highly dynamic nature of the environment and the absence of physical constraints that serve to bo… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

1
12
0

Year Published

2013
2013
2021
2021

Publication Types

Select...
4
2
2

Relationship

0
8

Authors

Journals

citations
Cited by 12 publications
(13 citation statements)
references
References 32 publications
1
12
0
Order By: Relevance
“…Situation awareness (SA) literature specifically discusses how systems can support multiple levels of SA in relation to expertise, which can act as guidelines for system development and design [38]. Additional cyber SA literature and ongoing research [39][40][41][42] also may help guide application design specifically for cyber security.…”
Section: Implications For Technology Developmentmentioning
confidence: 99%
“…Situation awareness (SA) literature specifically discusses how systems can support multiple levels of SA in relation to expertise, which can act as guidelines for system development and design [38]. Additional cyber SA literature and ongoing research [39][40][41][42] also may help guide application design specifically for cyber security.…”
Section: Implications For Technology Developmentmentioning
confidence: 99%
“…The study of CSIRTs is different than cognitive expertise studies of individual analysts because CSIR is a distributed, team-based activity. A team-focused perspective was pervasive in the literature, including the study of situation awareness (e.g., Tyworth, Giacobe, & Mancuso, 2012). Work has examined CSIRTs in terms of large-scale issues, such as workforce development, team effectiveness and the social maturity of teams (Hoffman, Burley, & Toregas, 2012;Steinke et al, 2015;Tetrick et al, 2016).…”
Section: Prior Researchmentioning
confidence: 99%
“…Botta et al [60], [76] conduct interviews to investigate the organizational practices of cyberdefenders and how they achieve distributed cognition [77] within the organization. Tyworth et al [78] interviewed security analysts and similarly find that cyber SA is distributed across human operators and technological artifacts operating in four different functional areas: intrusion detection, threat landscape analysis, operations and policy and management. Each operational domain is separated by physical and virtual boundaries with individual communities of practice, which have distinct knowledge, terminologies, foci, understandings and practices and may even lie distributed outside the organization.…”
Section: Organizational Studies In Cybersecuritymentioning
confidence: 99%