Contemporary cybersecurity governance assumes that professionals apply risk reasoning. Yet major organisational failures persist despite investment in tools, staffing, and credentials. This study investigates the structural source of that paradox. Cybersecurity speaks the language of risk, but its training architecture has shaped the profession to think in terms of threats. A sequential mixed-methods design integrated four analyses; NLP of the NIST NICE Framework v2.0.0 (2,111 TKS statements), SEM (n = 126 cybersecurity professionals), a control-group comparison (n = 133 general professionals), and thematic coding of seven leadership interviews. Four convergent findings emerged. First, "likelihood" and "probability" appear zero times across all TKS statements. Risk management content accounts for 4.5% of high-confidence semantic classifications, ranking 18th of 29 competency domains. NICE codifies threat-management activity while invoking risk mainly at the category level. Second, SEM showed that training exposure significantly predicts risk management competence directly and indirectly through conceptual salience, for a total effect of Beta = .629. However, the theoretically four-dimensional competence construct collapsed into a single factor, indicating epistemic compression. Third, cybersecurity professionals showed no measurable advantage over the general professional population in foundational risk reasoning; only 11.9% showed high differentiation. Fourth, all seven leaders expected Likelihood x Impact reasoning, yet five did not articulate the formula themselves. These findings support a structural conclusion: cybersecurity has taken professional form as a threat-management discipline that has borrowed risk vocabulary. Remediation requires redesign of professional formation, not marginal curriculum reform.


翻译:当代网络安全治理假设专业人员运用风险推理。然而,尽管在工具、人员和资质认证方面投入巨大,重大组织失败仍持续发生。本研究揭示了这一悖论的结构性根源。网络安全领域虽使用风险语言,但其培训架构已将该专业塑造成以威胁为中心的思维方式。通过顺序混合方法设计,本研究整合了四项分析:对NIST NICE框架v2.0.0(2,111个TKS陈述)的自然语言处理、结构方程模型(n=126名网络安全专业人员)、对照组比较(n=133名普通专业人员)以及七位领导访谈的主题编码。研究得出四个收敛性发现。第一,"可能性"和"概率"在所有TKS陈述中出现次数为零。风险管理内容占高置信度语义分类的4.5%,在29个能力领域中排名第18位。NICE框架在主要依赖类别层面提及风险的同时,对威胁管理活动进行了系统化编码。第二,结构方程模型显示,培训经历直接且通过概念显著性间接显著预测风险管理能力,总效应为Beta=0.629。然而,理论上四维度的能力结构压缩为单一因子,表明存在认知压缩。第三,网络安全专业人员与普通人群在基础风险推理方面未显示出可衡量的优势;仅11.9%表现出高区分度。第四,所有七位领导者预期使用"可能性×影响"推理模式,但其中五位未能明确表述该公式。这些发现支持一个结构性结论:网络安全已以威胁管理学科的形式形成专业形态,并借用了风险词汇。补救措施需要重构专业培养体系,而非边缘性课程改革。

0
下载
关闭预览

相关内容

《人工智能在网络防御中的机遇》
专知会员服务
12+阅读 · 6月8日
探索大型语言模型在网络安全中的作用:一项系统综述
专知会员服务
22+阅读 · 2025年4月27日
《自动化的网络防御:综述》2023最新32页长综述
专知会员服务
34+阅读 · 2023年6月19日
【2023新书】人工智能在网络安全中的应用,215页pdf
专知会员服务
105+阅读 · 2023年5月5日
网络安全态势感知浅析
计算机与网络安全
18+阅读 · 2017年10月13日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
20+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
10+阅读 · 2012年12月31日
Arxiv
0+阅读 · 3月26日
Arxiv
0+阅读 · 3月9日
Arxiv
23+阅读 · 2023年3月8日
VIP会员
相关主题
最新内容
非对称防御中的自组织临界性:俄乌战争
专知会员服务
6+阅读 · 8月10日
《战争中的大语言模型监管》
专知会员服务
5+阅读 · 8月10日
《边缘计算关键技术分析及美军作战实践应用》
边缘计算的军事应用
专知会员服务
9+阅读 · 8月9日
一种考虑资源机动性的武器目标分配混合算法
专知会员服务
11+阅读 · 8月8日
相关基金
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
20+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
2+阅读 · 2014年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
10+阅读 · 2012年12月31日
Top
微信扫码咨询专知VIP会员