<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>An Accimap Waiting to Happen: Using Multi-coding Frameworks to Accelerate Risk Analysis and Management</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Thomas Richard McEvoy</string-name>
          <email>richard.mcevoy@dxc.com</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Norway</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>STPIS'20: 6th International Workshop on Socio-Technical Perspective in IS development</institution>
          ,
          <addr-line>Online</addr-line>
        </aff>
      </contrib-group>
      <fpage>186</fpage>
      <lpage>194</lpage>
      <abstract>
        <p>We present a proposed framework for conducting data analysis and gathering for the Accimap methodology, a sociotechnical analysis method, for a given domain area (in this case, cybersecurity) which we believe will help address the acknowledged defects of the method when applied to predictive risk analysis and management. The approach combines a generic framework for Accimap with an enhanced version of Rasmussen's original model of complex sociotechnical systems on which the Accimap approach is based, reflecting 'known good' cybersecurity principles as well as common factors underlying system breakdowns in other areas of safety and security. As well as its immediate application to risk analysis and management, we believe the framework may have value as a teaching and research tool.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;Accimap</kwd>
        <kwd>qualitative interviews</kwd>
        <kwd>qualitative coding</kwd>
        <kwd>sociotechnical</kwd>
        <kwd>security incident analysis</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        1. Introduction
Safety research has shown that human and organizational factors are implicated in over 50
percent of accidents[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], pointing to the requirement to analyze such incidents using
sociotechnical systems methods [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ]. We believe that similar findings will be evident in the field of
cybersecurity and highlight the need for adopting sociotechnical approaches to cybersecurity[
        <xref ref-type="bibr" rid="ref1 ref3">3,
1</xref>
        ]. This approach of using artifacts from safety analysis in security also has precedent. For
example, fault tree analysis has been adopted in the form of attack trees [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] and Accimap has
been used to analyze security incidents [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>
        But predictive risk analysis rather than post-hoc accident analysis is regarded as the
primary technique of cybersecurity practice in communicating security requirements to management[
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
Accident analysis techniques such as Accimap are usually applied after the fact and require
considerable investment in time and resources (which is, of course, justified by the
seriousness of the accident) and this factor, along with others, undermines their use as techniques for
predictive risk analysis[
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        By combining domain knowledge (‘common body of knowledge’) [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] from cybersecurity
with common factors underlying accidents in other domains (based on a literature search –
see section 2), we believe that these weaknesses can be overcome in the case of Accimap.
      </p>
      <p>
        The propsosed approach uses a multi-coding framework which combines a generic
Accimap coding framework[
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] with a domain-specific framework which has previously been
used for analyzing weaknesses resulting from human and organizational factors in cybersecurity[
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
The framework is supplied in the form of a wiki1.
      </p>
      <p>
        It should be applied by undertaking and analyzing the results of a series of semi-structured
qualitative interviews (similar to those which might be used in a cybersecurity capability
maturity review [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]). The results can be underpinned by documentary evidence and
quantitative surveys. This makes it possible carry out the data gathering, reporting and analysis
in the same period of time and using similar human resources to a normal cybersecurity
maturity review – rendering the technique commercially feasible – but the end result is not a
set of scores but a ‘rich picture’ of potentially negative behaviors by the organization which
could represent potential underlying weaknesses exposing the organization to the
possibility of a serious cybersecurity breach and can be addressed in cultural change programs and
organizational and work design.
      </p>
      <p>
        This makes it possible to communicate with the management of the organization in an
intuitive fashion which allows them to “join the dots” in terms of understanding how
organizational failings can contribute to an incident and to its impact. It allows them not just to
prioritize addressing threats at the technical level, but similarly address vulnerabilities within
the organization at higher levels, tackling cultural and structural issues as well as process and
technical aspects [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. In short, to adopt a sociotechnical approach to cybersecurity risk
analysis and management.
      </p>
      <p>The end result is that recommendations for risk treatment at the technical level can be
enriched by the proposal of additional organizational and cultural measures to address the
underlying causes which lead to such control failings in the first place.</p>
      <p>
        We believe the approach also has value for pedagogical and research purposes. It could be
used as the basis for simulating cybersecurity incidents during training or study in the context
of a poorly prepared organization[
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] highlighting the role organizational failings could play
in exacerbating the effects of a cybersecurity incident, or be used as a springboard for analysis
of the interaction of specific factors by researchers.
      </p>
      <p>
        Future work will involve undertaking full studies with the framework, treating it as an
artifact of design science [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], seeking to refine and improve it and considering ways to
semiautomate the derivation of findings.
      </p>
      <p>
        Section 2 provides related literature on the area. Section 3 lists the current failings of
Accimap in terms of predictive risk analysis and management. Section 4 summarizes the overall
approach. Section 5 describes the multi-coding framework, its contents, construction and use.
Section 7 shows how it should be applied within organizations. We discuss our approach in
section 8 and we conclude and outline future work in section 9.
2. Related Work
The use of Accimap for accident investigation in various contexts, including information
systems security, is well attested in the literature [
        <xref ref-type="bibr" rid="ref5 ref9">9, 5</xref>
        ] and its strengths as well as its flaws are
recognized [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        The concept of improving on the capability to use Accimap more readily comes from [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ],
based on identifying generic factors. However, we argue in this paper that for specific
do1https://github.com/thomasrichardmcevoy/FASST
mains and in the context of specific organizations, we can make use of specialist domain
knowledge to further accelerate this process. The domain knowledge is derived from our
research into sociotechnical factors in information security failures [
        <xref ref-type="bibr" rid="ref1 ref3">1, 3</xref>
        ] combined with known
technical countermeasures [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and a simplified threat model which covers common forms of
breaches that have had devestating effects at organizational level[
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
      </p>
      <p>
        Both the generic Accimap framework and the FASST framework we employ are modeled
on Rasmussen’s model of complex sociotechnical systems[
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. The difference between them
is that the generic Accimap approach divides the organization into levels and then considers
factors, whereas the FASST framework takes the factors which Rasmussen identified – cost
evasion, work evasion and control and feedback (further divided into workflow, learning
and external monitoring) – and maps potential organizational and human factors which
contribute to security failure as potential subfactors. The mapping between the two frameworks
hence allows the analyst to consider potential cause and effect across levels.
      </p>
      <p>
        The overall aim of the exercise is to improve the communication of risk in the organization
by not only being able to justify technical or procedural countermeasures on a business case
basis [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], but also to encourage business managers to take a humanistic approach to their
security decision-making in line with the philosophy of sociotechnical design [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. Such an
approach would represent a joint optimization of security and human aims. For example,
poor design of security procedures can be shown to represent a security weakness rather
than a strength [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. Our approach allows these kinds of weaknesses to be detected.
      </p>
      <p>
        The methodology for applying the system is carried out in a way which is similar to a
capability maturity exercise, but rather than being completed with a scoring of the organization’s
capabilities [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], the approach ends with a clear communication of potential risky scenarios
where human and organizational factors are already creating exposures in the organization’s
security posture.
      </p>
      <p>
        The overall approach is based on design science where the multicoding framework acts as
the artifact which will be developed recursively and reflexively over a set of research studies
into the effectiveness of its application to the problem of incorporating sociotechnical systems
thinking into cyber security risk analysis and management [
        <xref ref-type="bibr" rid="ref1 ref13">13, 1</xref>
        ].
      </p>
      <p>
        Finally, we believe our approach should allow the further development of pedagogical
efforts to teach security skills by allowing organizational and human failings to be incorporated
into training in cybersecurity ranges to create more realistic scenarios [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ].
3. Problem
Accimap offers several advantages which explains its popularity as a method [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] –
1. It offers an approach to identifying failures at the sharp and across the entire
organization.
2. It is simple to learn but has a strong theoretical underpinning.
3. It allows system failures and inadequacies to be identified.
4. It offers and exhaustive description of accidents.
5. The output is visual and easily interpreted.
6. It is a generic approach which can be applied to any domain.
7. It removes apportioning of blame to individuals and promotes the development of
systematic countermeasures.
Its disadvantages are [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] –
1. It can be time consuming (and hence costly)
2. It suffers from problems of hindsight analysis and may lead to oversimplified causality
and counterfactual reasoning.
3. The quality of the analysis is dependent on the quality of the data
4. The output does not explicitly generate remedial measures or countermeasures
5. There is an absence of taxonomies of failure types which raises questions over its
reliability
6. The approach can only be applied retrospectively
7. The accident analysis can become large and unwieldy
      </p>
      <p>
        Our task is to seek to overcome some, or all, of these disadvantages to make Accimap
useable as a predictive risk analysis method which tackles sociotechnical aspects of risk
exposure.
4. Approach
The approach combines a generic coding framework for Accimap which addresses various
aspects of accidents occurring across different levels of the organization [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] – already being
used to accelerate analysis – with a coding framework (now extended and augmented) for
addressing organizational and human factors underlying cybersecurity risk exposure [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] and
technical elements (security countermeasures) and risks (potential security incidents).
      </p>
      <p>The mapping between the two frameworks, first, allows human and organizational factors
to be considered from the perspective of different levels of the organization and, second, helps
to identify causal dependencies and effects between levels, including how such failings can
undermine the provision of procedural and technical countermeasures. The framework has
a strong theoretical underpinning based on on an adapted version of Rasmussen’s model of
complex sociotechnical systems (see section 5).</p>
      <p>
        The method for applying the technique is based on the approach used with the original
human and organizational factors framework in [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], using as primary input a set of qualitative
interviews with individuals from different parts and levels of the organization. The only
different is that the analysis technique uses multi-coding [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] to create an enriched picture of
organizational dynamics.
      </p>
      <p>The approach potentially addresses some of the flaws in using Accimap –
1. It should reduce the time to complete a study
2. It avoids hindsight bias – the approach can be used predictively
3. The use of the framework means that a more structured approach is taken to data
gathering which can contribute to a higher quality of data or, at least, better identification of
gaps
4. The approach explicitly generates countermeasures and remedial actions which can
form part of security program
5. The associated risk model gives an initial taxonomy of failure types which can
augmented as required
6. The scope of the analysis is contained in the framework - though this may be a
disadvantage in some cases (see section 8).
Public Opinion
Threat Actors
Regulators
Assessors
Company
Manage
-ment
Staff
Work</p>
      <p>
        Politics
Markets
Skills
Technology
5. Underlying Model and Coding Structure
5.1. Model
Accimap is based on Rasmussen’s model of complex sociotechnical systems [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. This was
used as the basis for the generic Accimap coding framework [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Based on an adaptation of
this model specifically for the purposes of cybersecurity [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], we created a coding framework
which looked at the factors Rasmussen identified in his model – cost evasion, work evasion
and breakdowns in various control and feedback processes.
      </p>
      <p>
        For the purposes of this analysis, we specifically identified three types of breakdown – loss
of control and feedback (over the security workflows), weaknesses in learning culture and
lack of monitoring external circumstances which could be significant in cybersecurity terms.
This is not the only possible categorization, but suits our purpose. The model is summarized
in Figures 1 and 2. Furthermore, we increased the granularity of our analysis by considering
a further categorization, using these factors, of behaviors we had previously identified in [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
We call the resulting model FASST,standing for ‘factorial analysis - sociotechnical security
thinking’.
      </p>
      <p>We created a mapping between the two frameworks which means that a category on one
framework will have one or more corresponding categories in other framework and vice
versa. This mapping reflects intuitions concerning relevance and causality between the
frameworks.</p>
      <p>For example, the category ‘Culture’ appears several times in the Generic Accimap
framework and is linked to aspects such as ‘Communication’, ‘Mental Models’ and ‘Ethics’ in the
FASST framework. In turn, each of those categories points back to other organizational layers
External
Threats &amp;
Pressures</p>
      <p>Real Security
Boundary
(invisible)
Actual Working
Practices</p>
      <p>Economic
Failure</p>
      <p>Workflow Integration</p>
      <p>Learning</p>
      <p>External Monitoring
Unacceptable
Workload
of the Generic Accimap model and should allow the analyst to consider possible causal links
or associations both within and between layers of the organization.</p>
      <p>The FASST framework not only identifies potential underlying causes which expose an
organization to security incidents occurring but also possible countermeasures which could
be instituted by the organization to address these underlying weaknesses.</p>
      <p>
        Finally, we can associate potential failures with a simple threat model to identify risks. This
risk selection creates the ‘Accident (Security Incident)’ category in the generic Accimap. For
example, the threats of a cybersecurity attack leading to data theft, a denial of service attack,
a malicious action by an insider,force majeure and regulatory breaches can serve as an initial
set of risk categories allowing potential underlying exposures to such attacks and subsequent
failings in security working practice to contribute to probability assessments that attacks may
succeed. Combined with a quantitative analysis of risk, this can justify expenditure on
cultural and other initiatives to address these problems [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
6. Wiki Structure
The Wiki structure is headed by two files ‘HeadsBySTCategory’ and ’GenAccimap’. All files
are written in Markdown.
      </p>
      <p>The ‘HeadsBySTCategory’ file contains the codes and basic definitions for different patterns
of behavior or activity in an organization. For example, ‘PJM’ is the code for project
management. The code heading is given in URL form and points to ‘***Define’ file in the structure
– here ‘PJMDefine’ which contains a more detailed definition of the capability or behavior
and of the potential consequences of any deficits. For example, weak project management
could lead to security requirements being omitted or delays in delivering such requirements,
increasing the risk exposure of the organization.</p>
      <p>In turn, the ‘***Define’ files have URLs pointing to categories in the ‘GenericAccimap’
structure which allow the researcher to link deficits in capabilities or behaviors to different levels
of the organization and to consider further effects on other behaviors. Again, to give an
example, poor project management may lead to security resources being delivered late. This
relates to an area coded ‘MAT’ for technical capability and materials. Deficits in this area will
point to other category levels in the ‘GenericAccimap’.</p>
      <p>Countermeasures for improving areas are provided in turn 2, e.g., training project
managers, having a structured project management methodology and so forth.</p>
      <p>It is also possible to start with the ‘GenAccimap’ file and read across all possible behaviors
or capabilities in the model which might affect this area. This kind of approach might be used
when building a set of interview questions – see section 7.
7. Proposed Application
The overall structure is intended to promote an exploration of how the organization functions
as well as identifying possible countermeasures. The researcher is encouraged to use the
initial coding as a basis for further coding and interpretation of the organization’s behavior
and to revisit interviews or other evidence where appropriate.</p>
      <p>The end result of the exploration will be a ‘rich picture’ of organizational issues which are
interlinked and may entail risk exposure. This becomes the basis for building representative
Accimaps of the organization for each of the major risks.</p>
      <p>The multi-coding framework can be used in several ways. As has already been discussed
in section 2, the initial analysis is based on qualitative semi-structured interviews, which can
subsequently be backed up by quantitative analysis (based on testing hypotheses derived
from the qualitative analysis) and other evidence such as documentation, emails, discussion
boards and so forth.</p>
      <p>
        The framework provides a structure for developing leading questions in the semi-structured
interviews. It could be potentially used interactively during the interview to follow up on
topics. If a more formal approach to interviews is preferred, for example, when using novice
interviewers, the same structure can be used to create diagnostic interview sets [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
      </p>
      <p>The coding process will itself create connections across the framework which may spring
further queries in the security experts mind and guide the search for evidence as well as
hypotheses relating to potential failures built into patterns of behavior in the organization.</p>
      <p>
        Ultimately, of course, the aim of the process is to produce several hypothetical Accimaps
showing how human and management failures as well as weaknesses in process and
technology may be contributing directly or indirectly to one or more potential security incidents
and to use these as the basis for managing risk in the organization by determining on a set of
feasible countermeasures which not only addresses immediate technical flaws but also
underlying failings in organization and culture. This process could also be extended to examining
the organization’s ability to respond to or recover from security incidents [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>Obviously, the approach can also be applied to security incident analysis and we consider
that it may be possible to apply it as a pedagogical and research framework covering the
2These are currently in draft, but further detail is being added along with literature references which may
prove useful.
human and organizational issues we have identified.</p>
    </sec>
    <sec id="sec-2">
      <title>8. Discussion</title>
      <p>
        At this stage, there is no claim that the framework is ‘complete’ or ‘correct’. It is a proposed
way of working with an organization, using the Accimap method predictively. As an artefact
of design science, the approach is likely to be refined over several studies [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ].. What we
do argue is that the framework combines extensive experience with the use of Accimap with
a coding approach based on specific knowledge and experience in the information systems
domain and, as such, it addresses many of the flaws in Accimap, particularly addressing the
predictive element which was missing.
      </p>
      <p>
        It could be argued that the framework may limit the scope of inquiry. It specifies a search
for certain patterns of behavior and proposes specific countermeasures. Arguably, additional
categories of behavior will be present outside the scope of the framework and some
countermeasures may not be suitable for some kinds of organization, or fail to deal with the identified
patterns of behavior. But qualitative coding techniques allow for additional ‘in vivo’ coding if
required to cover novel patterns of experience outside those potentially expected [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. At the
same time, the results of the exercise should be open to discussion with experts, management
and staff on the ground, if novel solutions are required. As with any sociotechnical approach,
the aim is to conjoint optimization of desirable outcomes.
      </p>
      <p>A final consideration is that different sectors of information security (such as telecomms or
industrial control systems) may require additional work on the coding frameworks to draw
in additional domain specific knowledge. This may ultimately result in creating either an
expanded framework or specific frameworks for each subdomain area.</p>
    </sec>
    <sec id="sec-3">
      <title>9. Conclusion and Future Work</title>
      <p>This paper presents a proposed approach to sociotechnical analysis of cybersecurity risks
using the Accimap methodology. The original Accimap approach is seen as flawed for
cybersecurity risk analysis due to cost and time considerations and because it does not lend itself
to predictive risk assessments.</p>
      <p>We address these issues by combining a generic Accimap coding framework with an
encoding of specific domain knowledge applicable to negative patterns of human and
organizational behavior in information systems and those which are generically applicable to risk
management such as good communication.</p>
      <p>Data gathering and analysis is done on the basis of several qualitative interviews in the
same format, with the same time and resource usage, as a cybersecurity maturity interview,
making the approach commercially feasible. The findings in the qualitative interviews can be
confirmed through follow up quantitative studies or using documentary evidence in various
formats.</p>
      <p>Future work will require applying and refining the approach as an artifact of design science
to several organizations, preferably in different sub-domains of information systems such as
telecomms, banking systems or industrial control systems. The resulting knowledge gain is
not only expected to make risk analysis including sociotechnical aspects easier in each of these
areas but could also contribute to security incident analysis and to further teaching, training
and research.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <surname>McEvoy</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kowalski</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Cassandra's calling card: Socio-technical risk analysis and management in cyber security systems</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Qureshi</surname>
            ,
            <given-names>Z.H.:</given-names>
          </string-name>
          <article-title>A review of accident modelling approaches for complex critical sociotechnical systems</article-title>
          .
          <source>Technical report, DEFENCE SCIENCE AND TECHNOLOGY ORGANISATION EDINBURGH</source>
          (
          <article-title>AUSTRALIA) COMMAND</article-title>
          . . . (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>McEvoy</surname>
            ,
            <given-names>T.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kowalski</surname>
            ,
            <given-names>S.J.:</given-names>
          </string-name>
          <article-title>Deriving cyber security risks from human and organizational factors-a socio-technical approach</article-title>
          .
          <source>Complex Systems Informatics and Modeling Quarterly (18)</source>
          (
          <year>2019</year>
          )
          <fpage>47</fpage>
          -
          <lpage>64</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Mauw</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Oostdijk</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Foundations of attack trees</article-title>
          .
          <source>In: International Conference on Information Security and Cryptology</source>
          , Springer (
          <year>2005</year>
          )
          <fpage>186</fpage>
          -
          <lpage>198</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Wienen</surname>
            ,
            <given-names>H.C.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bukhsh</surname>
            ,
            <given-names>F.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vriezekolk</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Wieringa</surname>
          </string-name>
          , R.J.:
          <article-title>Applying generic accimap to a ddos attack on a western-european telecom operator</article-title>
          .
          <source>In: ISCRAM</source>
          . (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <surname>Baskerville</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          :
          <article-title>Risk analysis: an interpretive feasibility tool in justifying information systems security</article-title>
          .
          <source>European Journal of Information Systems</source>
          <volume>1</volume>
          (
          <issue>2</issue>
          ) (
          <year>1991</year>
          )
          <fpage>121</fpage>
          -
          <lpage>130</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Salmon</surname>
            ,
            <given-names>P.M.</given-names>
          </string-name>
          :
          <article-title>Human factors methods and accident analysis: practical guidance and case study applications</article-title>
          .
          <source>Ashgate Publishing</source>
          , Ltd. (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Hallett</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Larson</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rashid</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Mirror, mirror, on the wall: What are we teaching them all? characterising the focus of cybersecurity curricular frameworks</article-title>
          .
          <source>In: 2018 {USENIX} Workshop on Advances in Security Education ({ASE} 18)</source>
          . (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Salmon</surname>
            ,
            <given-names>P.M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hulme</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Walker</surname>
            ,
            <given-names>G.H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Waterson</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Berber</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stanton</surname>
            ,
            <given-names>N.A.</given-names>
          </string-name>
          :
          <article-title>Something for everyone: A generic accimap contributory factor classification scheme</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Rea-Guaman</surname>
            ,
            <given-names>A.M.</given-names>
          </string-name>
          , San Feliu, T.,
          <string-name>
            <surname>Calvo-Manzano</surname>
            ,
            <given-names>J.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sanchez-Garcia</surname>
            ,
            <given-names>I.D.</given-names>
          </string-name>
          :
          <article-title>Comparative study of cybersecurity capability maturity models</article-title>
          .
          <source>In: International Conference on Software Process Improvement and Capability Determination</source>
          , Springer (
          <year>2017</year>
          )
          <fpage>100</fpage>
          -
          <lpage>113</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Bostrom</surname>
            ,
            <given-names>R.P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Heinen</surname>
            ,
            <given-names>J.S.:</given-names>
          </string-name>
          <article-title>Mis problems and failures: A socio-technical perspective. part i: The causes</article-title>
          .
          <source>MIS quarterly</source>
          (
          <year>1977</year>
          )
          <fpage>17</fpage>
          -
          <lpage>32</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Østby</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Berg</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kianpour</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Katt</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kowalski</surname>
            ,
            <given-names>S.J.:</given-names>
          </string-name>
          <article-title>A socio-technical framework to improve cyber security training: A work in progress</article-title>
          ,
          <source>CEUR Workshop Proceedings</source>
          (
          <year>2019</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Hevner</surname>
            ,
            <given-names>A.R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>March</surname>
          </string-name>
          , S.T.,
          <string-name>
            <surname>Park</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ram</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          :
          <article-title>Design science in information systems research</article-title>
          . MIS quarterly (
          <year>2004</year>
          )
          <fpage>75</fpage>
          -
          <lpage>105</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Shen</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          :
          <article-title>The nist cybersecurity framework: Overview and potential impacts</article-title>
          .
          <source>Scitech Lawyer</source>
          <volume>10</volume>
          (
          <issue>4</issue>
          ) (
          <year>2014</year>
          )
          <fpage>16</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Rasmussen</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          , et al.:
          <article-title>Risk management in a dynamic society: a modelling problem</article-title>
          .
          <source>Safety science 27(2)</source>
          (
          <year>1997</year>
          )
          <fpage>183</fpage>
          -
          <lpage>213</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Mumford</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          :
          <article-title>The story of socio-technical design: Reflections on its successes, failures and potential</article-title>
          .
          <source>Information systems journal 16(4)</source>
          (
          <year>2006</year>
          )
          <fpage>317</fpage>
          -
          <lpage>342</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Sasse</surname>
            ,
            <given-names>M.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Brostoff</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weirich</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          :
          <article-title>Transforming the 'weakest link'-a human/computer interaction approach to usable and effective security</article-title>
          .
          <source>BT technology journal 19(3)</source>
          (
          <year>2001</year>
          )
          <fpage>122</fpage>
          -
          <lpage>131</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Saldaña</surname>
            ,
            <given-names>J.:</given-names>
          </string-name>
          <article-title>The coding manual for qualitative researchers</article-title>
          .
          <source>Sage</source>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Perkins</surname>
            ,
            <given-names>R.W.</given-names>
          </string-name>
          :
          <article-title>Diagnostic interviewing for consultants and auditors: A collaborative approach to problem solving</article-title>
          .
          <source>Consulting to Management</source>
          <volume>8</volume>
          (
          <issue>3</issue>
          ) (
          <year>1995</year>
          )
          <fpage>70</fpage>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>