article Open access

Review of Human Decision-making during Computer Security Incident Analysis

  • Digital Threats Research and Practice
  • Association for Computing Machinery
Research footprint

At a glance

Citations
1
References
106
Comments
0
Paper overview

Abstract

We review practical advice on decision-making during computer security incident response. Scope includes standards from the IETF, ISO, FIRST, and the US intelligence community. To focus on human decision-making, the scope is the evidence collection, analysis, and reporting phases of response, which includes human decision-making within and connecting these phases. The results indicate both strengths and gaps. A strength is available advice on how to accomplish many specific tasks. However, there is little guidance on how to prioritize tasks in limited time or how to interpret, generalize, and convincingly report results. Future work should focus on these gaps in explication and specification of decision-making during incident analysis.

Record transparency

Publication details

DOI
10.1145/3427787
OpenAlex
W2923299197
Document type
article
Language
EN
Source
Digital Threats Research and Practice
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.