• DocumentCode
    1500528
  • Title

    Demythifying Cybersecurity

  • Author

    Talbot, Edward B. ; Frincke, Deborah ; Bishop, Matt

  • Author_Institution
    Sandia Nat. Labs., Albuquerque, NM, USA
  • Volume
    8
  • Issue
    3
  • fYear
    2010
  • Firstpage
    56
  • Lastpage
    59
  • Abstract
    A large part of computer security education is tackling myths that support much of the practice in the field. By examining these myths and the underlying truths or heuristics they reflect, we learn three things. First, students and practitioners learn to separate what is empirically and theoretically supported from what is supported solely by untested anecdotes or handeddown "best practices." Second, a key part of education is the human dimension of convincing others that stories that sound right aren\´t proven and might in fact be wrong. They aren\´t necessarily wrong-but this possibility must be considered. Finally, we can consider myths from the perspective of teaching stories, because many evolve from activities that at one time were true or that have some accurate elements.
  • Keywords
    computer aided instruction; security of data; computer security education; demythifying cybersecurity; untested anecdotes; Best practices; Computer science education; Computer security; Humans; computer science education; computer security; cybersecurity; defense in depth; layered defense; security and privacy; system complexity; three-factor authentication; trusted computing;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSP.2010.95
  • Filename
    5470955