usenix conference policies
A Human Capital Model for Mitigating Security Analyst Burnout
Error message
You are not authorized to post comments.Sathya Chandran Sundaramurthy, Alexandru G. Bardas, Jacob Case, Xinming Ou, and Michael Wesch, Kansas State University; John McHugh, RedJack, LLC.; S. Raj Rajagopalan, Honeywell ACS Labs
Security Operation Centers (SOCs) are being operated by universities, government agencies, and corporations to defend their enterprise networks in general and in particular to identify malicious behaviors in both networks and hosts. The success of a SOC depends on having the right tools, processes and, most importantly, efficient and effective analysts. One of the worrying issues in recent times has been the consistently high burnout rates of security analysts in SOCs. Burnout results in analysts making poor judgments when analyzing security events as well as frequent personnel turnovers. In spite of high awareness of this problem, little has been known so far about the factors leading to burnout. Various coping strategies employed by SOC management such as career progression do not seem to address the problem but rather deal only with the symptoms. In short, burnout is a manifestation of one or more underlying issues in SOCs that are as of yet unknown. In this work we performed an anthropological study of a corporate SOC over a period of six months and identified concrete factors contributing to the burnout phenomenon. We use Grounded Theory to analyze our fieldwork data and propose a model that explains the burnout phenomenon. Our model indicates that burnout is a human capital management problem resulting from the cyclic interaction of a number of human, technical, and managerial factors. Specifically, we identified multiple vicious cycles connecting the factors affecting the morale of the analysts. In this paper we provide detailed descriptions of the various vicious cycles and suggest ways to turn these cycles into virtuous ones. We further validated our results on the fieldnotes from a SOC at a higher education institution. The proposed model is able to successfully capture and explain the burnout symptoms in this other SOC as well.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Sathya Chandran Sundaramurthy and Alexandru G. Bardas and Jacob Case and Xinming Ou and Michael Wesch and John McHugh and S. Raj Rajagopalan},
title = {A Human Capital Model for Mitigating Security Analyst Burnout},
booktitle = {Eleventh Symposium On Usable Privacy and Security (SOUPS 2015)},
year = {2015},
isbn = {978-1-931971-249},
address = {Ottawa},
pages = {347--359},
url = {https://www.usenix.org/conference/soups2015/proceedings/presentation/sundaramurthy},
publisher = {USENIX Association},
month = jul
}
connect with us