Integrating Case Studies into Information Security Education
Alexandra Savelieva and
Sergey Avdoshin ()
Additional contact information
Alexandra Savelieva: Microsoft Corporation
Sergey Avdoshin: National Research University Higher School of Economics
A chapter in Emerging Trends in Information Systems, 2016, pp 99-115 from Springer
Abstract:
Abstract Today the demand is growing for information security experts capable of analyzing problems and making decisions in business situations that involve risk or uncertainty. These skills can be acquired through systematic studying of various information security incidents. In this paper we propose a framework of methods, tools and taxonomies for analysis of case studies in information security field. Our framework allows to study every situation in a formal rather than ad-hoc way, and apply a wide range of threat modeling, risk analysis and project management techniques under lifelike conditions. We illustrate it by providing two case studies based on real situations: a conflict between a free email service provider and a commercial bank, and an attack on a famous security company by a powerful hacktivist group. The first situation explores the risks of using cloud services, while the second highlights the importance of applying secure code principles for in-house software development. Although the cases are seemingly different, we demonstrate that they can be analyzed with similar tools.
Keywords: Case study; Information security; Education; Security incident; Event chain; Parkerian Hexad; Threat; STRIDE; Information asset; Risk; Attack lifecycle (search for similar items in EconPapers)
Date: 2016
References: Add references at CitEc
Citations:
There are no downloads for this item, see the EconPapers FAQ for hints about obtaining it.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:prochp:978-3-319-23929-3_9
Ordering information: This item can be ordered from
http://www.springer.com/9783319239293
DOI: 10.1007/978-3-319-23929-3_9
Access Statistics for this chapter
More chapters in Progress in IS from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().