IT Security and the Normalization of Deviance.¶
Schneier, B. (2016). IT Security and the Normalization of Deviance. Schneier on Security.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Normalization of Deviance
- In cybersecurity and software operations, expired certificates left in place, security exceptions extended past sunset, alert fatigue muting once-actionable signals, and "temporary" workarounds living in production for years all run the same ratchet.
This sourceExplicitly transfers Vaughan's normalization-of-deviance mechanism to information security and software operations, arguing that procedural shortcuts, ignored warnings, and accepted security lapses become invisible to insiders the more they recur, exactly the cybersecurity/software ratchet (expired certificates, extended exceptions, alert fatigue, lingering "temporary" workarounds) the marker asserts.
- In cybersecurity and software operations, expired certificates left in place, security exceptions extended past sunset, alert fatigue muting once-actionable signals, and "temporary" workarounds living in production for years all run the same ratchet.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:42b3c7d6758b · see in the full table