Behavioral Science and the NIST CSF Identify Pillar
Building on our current elevator pitch this post will talk about how and why we apply behavioral science to the Identify pillar of the NIST CSF . On the face of it, the Identity pillar is the pillar that everyone "gets" because it is so delightfully straightforward and lacking in veils of technological mystery: list all the digital assets your cybersecurity is supposed to protect. There are at least three complicating factors here when I watch this process in action in the wild: the problem of obviousness, the problem of obscurity and the problem of command. Each of these problems has their solution in behavioral science, not technology or methodology. What Is A Digital Asset? In this context, a digital asset is a data set or computer system that you need to do your job. Sounds pretty simple, doesn't it? The Obvious Is Not Always Obvious The commonplace gets overlooked, we all know this. This facet of human nature bites you twice in this process. First, you will tend to...