qualitylab

the station

The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise Level

tier II/2018/USENIX Security 2018/partly self-reported

https://www.usenix.org/conference/usenixsecurity18/presentation/stevens

Method

"Primarily observational study" using "group training sessions" followed by tracking "through analysis of 120 days of log data, and qualitatively, via pre-, post-, and 30-day-post-training surveys."

Population

"25 participants" representing "37% of the NYC3 workforce"

What it does not show

Evaluates one framework only, so it cannot compare structures or separate the structure from the effect of setting aside time. No control group of comparable untrained staff. The authors caution that organisational characteristics may make this workforce especially well or poorly suited to the practice.

Rock Stevens, Daniel Votipka, Elissa M. Redmiles, Michelle L. Mazurek, Colin Ahern, Patrick Sweeney

20 of 25 participants were still incorporating the method into daily duties 30 days after training without prompting. Over 120 days, participant-designed mitigations blocked 541 unique intrusion attempts, prevented the hijacking of five privileged accounts, and addressed three public-facing server vulnerabilities. Participants generated 147 distinct mitigation strategies, 64% of them new and unimplemented.

Tier II: Real enterprise deployment tracked through 120 days of production security-log data plus surveys at three points. A single organisation with no comparison group of untrained teams; adoption is self-reported while the blocked-attack counts come from logs.

Cited by