Introducing and Interfacing with Cybersecurity – a Cards Approach

35 Pages Posted: 2 Nov 2023

See all articles by Ryan Shah

Ryan Shah

Heriot-Watt University

Manuel Maarek

Heriot-Watt University

Shenando Stals

Heriot-Watt University

Lynne Baillie

Heriot-Watt University

Sheung Chi Chan

Heriot-Watt University

Robert Stewart

Heriot-Watt University

Hans-Wolfgang Loidl

Heriot-Watt University

Olga Chatzifoti

The Glasgow School of Art

Abstract

Cybersecurity is an important topic which is often viewed as one that is inaccessible due to steep learning curves and a perceived requirement of needing specialist knowledge. With a constantly changing threat landscape, practical solutions such as best-practices are employed, but the number of critical cybersecurity-related incidents remains high. To address these concerns, the National Cyber Security Centre published a Cybersecurity Body of Knowledge (CyBOK) to provide a comprehensive information base used to advise and underpin cybersecurity learning. Unfortunately, CyBOK contains over 1000 pages of in-depth material and may not be easy to navigate for novice individuals. Furthermore, it does not allow for easy expression of various cybersecurity scenarios that such individuals may be exposed to. As a solution to these two issues, we propose the use of a playing cards format to provide introductory cybersecurity knowledge that supports learning and discussion, using CyBOK as the foundation for the technical content. Upon evaluation in two user studies, we found that 80% of the participants agreed the cards provided them with introductory knowledge of cybersecurity topics, and 70% agreed the cards provided an interface for discussing topics and enabled them to make links between attacks, vulnerabilities and defences.

Keywords: Cybersecurity, cybersecurity knowledge, cybersecurity cards, Knowledge management, CyBOK

Suggested Citation

Shah, Ryan and Maarek, Manuel and Stals, Shenando and Baillie, Lynne and Chan, Sheung Chi and Stewart, Robert and Loidl, Hans-Wolfgang and Chatzifoti, Olga, Introducing and Interfacing with Cybersecurity – a Cards Approach. Available at SSRN: https://ssrn.com/abstract=4621045 or http://dx.doi.org/10.2139/ssrn.4621045

Ryan Shah

Heriot-Watt University ( email )

Riccarton
Edinburgh EH14 4AS, EH14 1AS
United Kingdom

Manuel Maarek (Contact Author)

Heriot-Watt University ( email )

Shenando Stals

Heriot-Watt University ( email )

Riccarton
Edinburgh EH14 4AS, EH14 1AS
United Kingdom

Lynne Baillie

Heriot-Watt University ( email )

Riccarton
Edinburgh EH14 4AS, EH14 1AS
United Kingdom

Sheung Chi Chan

Heriot-Watt University ( email )

Riccarton
Edinburgh EH14 4AS, EH14 1AS
United Kingdom

Robert Stewart

Heriot-Watt University ( email )

Riccarton
Edinburgh EH14 4AS, EH14 1AS
United Kingdom

Hans-Wolfgang Loidl

Heriot-Watt University ( email )

Riccarton
Edinburgh EH14 4AS, EH14 1AS
United Kingdom

Olga Chatzifoti

The Glasgow School of Art ( email )

167 Renfrew Street
Glasgow
United Kingdom

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
15
Abstract Views
128
PlumX Metrics