Location
Hilton Waikoloa Village, Hawaii
Event Website
https://hicss.hawaii.edu/
Start Date
7-1-2025 12:00 AM
End Date
10-1-2025 12:00 AM
Description
The field of cybersecurity is still relatively young, having grown up alongside mass adoption of the Internet. As the field has evolved, “Best Practices,” “Top 10,” and other similarly titled lists have emerged as an apparent means of simplifying an otherwise complex endeavor. We became curious about such lists: their audience, composition, length, similarity, and themes. To this end, from among the dozens of best practices lists in circulation, we studied a sample of 25 lists drawn from a range of sources. We find that there are many different view-points as to what best practices should be, with the lists more dissimilar than alike, on average. While our analysis suggests that resilience to adverse cyber events appears to be a common if implicit goal among the lists surveyed, we advance the premise that until the scientific underpinnings of cybersecurity are more firmly established, such lists are unlikely to converge.
Recommended Citation
Llanso, Thomas, "Viewing the State of Cybersecurity Through Its “Best Practices” and “Top 10” Lists" (2025). Hawaii International Conference on System Sciences 2025 (HICSS-58). 2.
https://aisel.aisnet.org/hicss-58/st/cybersecurity_and_sw_assurance/2
Viewing the State of Cybersecurity Through Its “Best Practices” and “Top 10” Lists
Hilton Waikoloa Village, Hawaii
The field of cybersecurity is still relatively young, having grown up alongside mass adoption of the Internet. As the field has evolved, “Best Practices,” “Top 10,” and other similarly titled lists have emerged as an apparent means of simplifying an otherwise complex endeavor. We became curious about such lists: their audience, composition, length, similarity, and themes. To this end, from among the dozens of best practices lists in circulation, we studied a sample of 25 lists drawn from a range of sources. We find that there are many different view-points as to what best practices should be, with the lists more dissimilar than alike, on average. While our analysis suggests that resilience to adverse cyber events appears to be a common if implicit goal among the lists surveyed, we advance the premise that until the scientific underpinnings of cybersecurity are more firmly established, such lists are unlikely to converge.
https://aisel.aisnet.org/hicss-58/st/cybersecurity_and_sw_assurance/2