Cybersecurity incident response teams mitigate the impact of adverse cyber-related events in organisations. Field studies of IR teams suggest that at present the process of IR is under-developed with a focus on the technological dimension with little consideration of practice capability. To address this gap, we develop a scenario-based training approach to assist organisations to overcome socio-technical barriers to incident response. The training approach is informed by a comprehensive list of socio-technical barriers compiled from a comprehensive review of the literature. Our primary contribution is a novel meta-level framework to generate scenarios specifically targeting socio-technical issues. To demonstrate the utility of the framework, a proof-of-concept scenario is presented.
翻译:网络安全事件应对小组减轻组织内与网络有关的不利事件的影响。IR小组的实地研究表明,目前IR进程发展不足,其重点是技术层面,很少考虑实践能力。为弥补这一差距,我们制定了一种基于情景的培训方法,以协助各组织克服事故应对的社会技术障碍。培训方法参考了综合文献审查汇编的社会技术障碍综合清单。我们的主要贡献是一个新的元层面框架,以产生专门针对社会技术问题的情景。为了展示框架的效用,我们提出了一个概念证明情景。