Learning from Cyber Incidents: Adapting Aviation Safety Models to Cybersecurity

Page 58

Research Agenda The primary goal of this workshop has been to identify research questions around adapting lesson learning systems from aviation, and we have identified a great many such questions, spanning the hard and social sciences. We are also very aware that these lesson learning systems have an opportunity to act as “platforms”, enabling further research. Doing so is, of course, not free, and in this section, we lay out a series of recurrent issues that we could not resolve within the workshop and that require further analysis and science. We then set out specific research questions tied to each section of the report.

Recurrent Issues and Themes There were a set of recurrent issues which we grappled with through the workshop. They include: • The intelligent adversary problem • Complexities of the regulatory context • Framing of safety, security, systems or resilience • Organizational structures of boards • Costs and benefits of investigative boards • Access to data Each deserves its own workshop and research agenda.

The Intelligent Adversary Problem The NTSB investigates accidents; criminal and/or terrorist activity is outside their remit. The existence of an intelligent adversary in cyber incidents adds complexity or challenges to each part of the process.

50

Learning from Cyber Incidents: Adapting Aviation Safety Models to Cybersecurity


Turn static files into dynamic content formats.

Create a flipbook
Issuu converts static files into: digital portfolios, online yearbooks, online catalogs, digital photo albums and more. Sign up and create your flipbook.