Cybersecurity Career Professional Paper

Tarraino V Turner Jr.

11/24/24

The Relationship Between Cybersecurity Auditors and The Principles of Social Science

Cybersecurity auditors are professionals who help protect organizations by evaluating their security systems. They check for weaknesses in the way companies handle sensitive information and recommend ways to improve safety. While cybersecurity might seem like a purely technical field, auditors also rely on principles from social science, such as psychology, sociology, and organizational behavior. These areas of study help auditors understand human behavior and social dynamics, which are critical in preventing security breaches and creating safer systems for everyone. This paper explores how social science research and principles shape the work of cybersecurity auditors and how they affect marginalized groups and society as a whole.

Connection Between Cybersecurity and Social Science

Cybersecurity isn’t just about computers; it’s also about how people behave. Social science helps auditors understand why people might make mistakes, like clicking on a phishing link or forgetting to follow security rules. Research in psychology helps auditors recognize behavioral biases like how people tend to trust emails from familiar sources or how they might overlook security practices when they feel overwhelmed. By understanding these psychological factors, auditors can recommend ways to train employees to be more aware of security threats and improve the overall security culture in an organization. Sociology also plays a role in cybersecurity. Social science research helps auditors understand how people and organizations work together. For example, if employees are not sharing information properly or if security policies are not clear, the entire organization can be vulnerable to attacks. Auditors use knowledge from sociology to improve communication within an organization and ensure that everyone understands the importance of following security guidelines.

Vulnerabilities Through Social Science

One of the key tasks of a cybersecurity auditor is identifying vulnerabilities, or weaknesses, in a system. This requires an understanding of how people work within organizations. Research in organizational behavior helps auditors understand how information flows and how decisions are made. For example, if an organization has a culture where employees don’t feel comfortable reporting security concerns, a breach might go unnoticed until it’s too late. By recognizing these organizational issues, auditors can suggest better ways to manage security and prevent problems. Another important aspect of auditing is understanding how social connections within an organization can impact security. Social network analysis, a method used in sociology, can help auditors figure out which individuals or teams have the most access to sensitive information and whether those people are following security protocols. Understanding these social networks can help auditors spot potential risks and improve security policies.

Addressing Marginalized Groups

Cybersecurity auditors must also be mindful of how marginalized groups, such as people with disabilities or those from lower-income backgrounds, might face different challenges when it comes to technology. Many people in these groups may not have access to the latest devices or cybersecurity tools. This digital divide can leave them more vulnerable to cyber-attacks. For example, a person who can’t afford a secure smartphone might use outdated or unsafe technology to access sensitive information. Social science research on socioeconomic issues and disability studies helps auditors understand these challenges and find ways to make cybersecurity practices more accessible to everyone, no matter their background. Cybersecurity systems should also be inclusive of people with disabilities. For example, people with visual impairments may struggle with security systems that rely on sight, like CAPTCHA tests or visual security alerts. Social science principles related to universal design help auditors make sure that security systems are designed to be used by everyone, regardless of their abilities.

The broad view

Cybersecurity isn’t just about protecting businesses it’s also about protecting individuals and society at large. The work of cybersecurity auditors affects everyone, from individuals who trust companies with their personal data to communities that rely on secure online systems for services like healthcare and education. Auditors have to consider the social ethics of their work, ensuring that their actions benefit society and do not unfairly harm certain groups. For example, a data breach at a company can affect many people, but marginalized groups might be at greater risk. Auditors must ensure that organizations respond fairly to these breaches and take steps to protect those most vulnerable to harm. Moreover, cybersecurity auditors must also think about how different social groups are impacted by cybersecurity practices. For example, people in lower-income communities may be more vulnerable to certain types of cyber-attacks, like fraud, because they lack the resources to secure their online information. Auditors should be aware of these inequalities and ensure that the security systems they recommend do not unfairly disadvantage certain groups.

Conclusion

In conclusion, cybersecurity auditing is not just a technical job it involves understanding how people interact with technology and how social factors influence security practices. Social science research and principles, including psychology, sociology, and ethics, help cybersecurity auditors make informed decisions that protect both organizations and individuals. By considering the needs of marginalized groups and the broader impact of cybersecurity on society, auditors can help create safer, more inclusive systems that benefit everyone.

References

  1. Anderson, R. (2020). Security Engineering: A Guide to Building Dependable Distributed Systems. Wiley.
  2. Friedman, B., Kahn, P. H., & Borning, A. (2006). Value Sensitive Design and Information Systems. In Human-Computer Interaction: Development Process (pp. 111-128). Springer.
  3. Margolis, R., & Murnane, R. J. (2021). A Digital Divide: Internet Access and the Marginalized Groups. Oxford University Press.