Issues with CSI Cybercrime Survey
Jiri (?) from the brand new Security Weblog commented on my issues with the CSI survey and pointed out two great papers by Mich Kabay about the inherent flaws in computer security studies.
Agree. There is an old saying that goes something like statistics is just a sientific way of fooling people. Pelle points out that the interpretataion of CSI survey is dubious. What's more, sampling on which the survey was based is funny as well. Survey is responded to by security professionals from large organisations. This inevitably affects the results (that are then interpreted in the way outlined by Pelle). And BTW, there are two relevant papers on cyber crime surveys from Mich Kabay who happens to be a security professional and at the same time holds PhD in statistics.[Security weblog]
10:05:57 PM comment []
|