Vis enkel innførsel

dc.contributor.authorOfte, Håvard Jakobsen
dc.date.accessioned2024-08-22T10:48:22Z
dc.date.available2024-08-22T10:48:22Z
dc.date.created2024-08-16T09:09:55Z
dc.date.issued2024
dc.identifier.issn1615-5262
dc.identifier.urihttps://hdl.handle.net/11250/3147548
dc.description.abstractSecurity operation centers (SOCs) are increasingly established to meet the growing threat against cyber security. The operators of SOCs respond to complex incidents under time constraints. Within critical infrastructure, the consequences of human error or low performance in SOCs may be detrimental. In other domains, situation awareness (SA) has proven useful to understand and measure how operators use information and decide the correct actions. Until now, SA research in SOCs has been restricted by a lack of in-depth studies of SA mechanisms. Therefore, this study is the first to conduct a goal-directed task analysis in a SOC for critical infrastructure. The study was conducted through a targeted series of unstructured and semi-structured interviews with SOC operators and their leaders complemented by a review of documents, incident reports, and in situ observation of work within the SOC and real incidents. Among the presented findings is a goal hierarchy alongside a complete overview of the decisions the operators make during escalated incidents. How the operators gain and use SA in these decisions is presented as a complete set of SA requirements. The findings are accompanied by an analysis of contextual differences in how the operators prioritize goals and use information in network incidents and security incidents. This enables a discussion of what SA processes might be automated and which would benefit from different SA models. The study provides a unique insight into the SA of SOC operators and is thus a steppingstone for bridging the knowledge gap of Cyber SA.en_US
dc.description.abstractThe awareness of operators: a goal-directed task analysis in SOCs for critical infrastructureen_US
dc.language.isoengen_US
dc.publisherSpringeren_US
dc.rightsNavngivelse 4.0 Internasjonal*
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/deed.no*
dc.subjectKritisk infrastrukturbeskyttelseen_US
dc.subjectCritical Infrastructure Protectionen_US
dc.subjectSituasjonsforståelseen_US
dc.subjectSituational awarenessen_US
dc.subjectMenneskelige faktoreren_US
dc.subjectHuman factorsen_US
dc.subjectCyber securityen_US
dc.subjectCyber securityen_US
dc.subjectHendelseshåndteringen_US
dc.subjectIncident responseen_US
dc.titleThe awareness of operators: a goal-directed task analysis in SOCs for critical infrastructureen_US
dc.title.alternativeThe awareness of operators: a goal-directed task analysis in SOCs for critical infrastructureen_US
dc.typePeer revieweden_US
dc.typeJournal articleen_US
dc.description.versionpublishedVersionen_US
dc.subject.nsiVDP::Informasjons- og kommunikasjonssystemer: 321en_US
dc.subject.nsiVDP::Information and communication systems: 321en_US
dc.source.journalInternational Journal of Information Securityen_US
dc.identifier.doi10.1007/s10207-024-00872-6
dc.identifier.cristin2286913
dc.relation.projectNorges forskningsråd: 333900en_US
dc.relation.projectNorges forskningsråd: 310105en_US
cristin.ispublishedtrue
cristin.fulltextoriginal
cristin.qualitycode2


Tilhørende fil(er)

Thumbnail

Denne innførselen finnes i følgende samling(er)

Vis enkel innførsel

Navngivelse 4.0 Internasjonal
Med mindre annet er angitt, så er denne innførselen lisensiert som Navngivelse 4.0 Internasjonal