Affiliation:
1. School of Computer Science, Carleton University , 1125 Colonel By Drive, Ottawa, K1S 5B6 ON , Canada
Abstract
Abstract
We carry out a detailed analysis of the security advice coding method (SAcoding) of Barrera et al., which is designed to analyze security advice in the sense of measuring actionability and categorizing advice items as practices, policies, principles, or outcomes. The main part of our analysis explores the extent to which a second coder’s assignment of codes to advice items agrees with that of a first, for a dataset of 1013 security advice items nominally addressing Internet of Things devices. More broadly, we seek a deeper understanding of the soundness and utility of the SAcoding method, and the degree to which it meets the design goal of reducing subjectivity in assigning codes to security advice items. Our analysis results in suggestions for modifications to the coding tree methodology, and some recommendations. We believe the coding tree approach may be of interest for analysis of qualitative data beyond security advice datasets alone.
Publisher
Oxford University Press (OUP)
Subject
Law,Computer Networks and Communications,Political Science and International Relations,Safety, Risk, Reliability and Quality,Social Psychology,Computer Science (miscellaneous)
Reference28 articles.
1. SoK: Security Evaluation of Home-Based IoT Deployments;Alrawi,2019
2. DDoS in the IoT: Mirai and Other Botnets;Kolias;Computer,2017
3. CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements (ETSI EN 303 645),2020
4. Code of Practice for Consumer IoT Security,2018
5. Security Best Practices: A Critical Analysis Using IoT as a Case Study;Barrera;ACM Trans Priv Secur,2023