Print Email Facebook Twitter A cyber-risk framework for coordination of the prevention and preservation of behaviours Title A cyber-risk framework for coordination of the prevention and preservation of behaviours Author Parkin, S.E. (TU Delft Organisation & Governance) Chua, Yi Ting (University of South Alabama) Date 2022 Abstract Cybersecurity controls are deployed to manage risks posed by malicious behaviours or systems. What is not often considered or articulated is how cybersecurity controls may impact legitimate users (often those whose use of a managed system needs to be protected, and preserved). This oversight characterises the blunt' nature of many cybersecurity controls. Here we present a framework produced from consideration of concerns across methods from cybercrime opportunity reduction and behaviour change, and existing risk management guidelines. We illustrate the framework and its principles with a range of examples and potential applications, including management of suspicious emails in organizations, and social media controls. The framework describes a capacity to improve the precision of cybersecurity controls by examining shared determinants of negative and positive behaviours in a system. This identifies opportunities for risk owners to better protect legitimate users while simultaneously acting to prevent malicious activity in a managed system. We describe capabilities for a novel approach to managing sociotechnical cyber risk which can be integrated alongside elements of typical risk management processes. This includes consideration of user activities as a system asset to protect, and a consideration of how to engage with other stakeholders in the identification of behaviours to preserve in a system. Subject cyber riskRisk managementsociotechnical security To reference this document use: http://resolver.tudelft.nl/uuid:04369cd2-d7be-4e12-a472-d24bf93a8789 DOI https://doi.org/10.3233/JCS-210047 ISSN 0926-227X Source Journal of Computer Security, 30 (3), 327-356 Part of collection Institutional Repository Document type journal article Rights © 2022 S.E. Parkin, Yi Ting Chua Files PDF jcs_2022_30_3_jcs_30_3_jc ... 210047.pdf 482.25 KB Close viewer /islandora/object/uuid:04369cd2-d7be-4e12-a472-d24bf93a8789/datastream/OBJ/view