Not moved. There is a clear absence of consensus to move, and a well-stated concern that there is a topic of "computer security" which includes physical securit
| This is an archive of past discussions about Computer security. Do not edit the contents of this page. If you wish to start a new discussion or revive an old one, please do so on the current talk page. |
| Archive 1 | Archive 2 | Archive 3 | Archive 4 |
Not moved. There is a clear absence of consensus to move, and a well-stated concern that there is a topic of "computer security" which includes physical security of the hardware, and other forms of security against threats not transmitted via the internet. The proposal to develop Cybersecurity as a separate subtopic article focusing on internet-related security seems reasonable. bd2412 T 18:26, 19 December 2017 (UTC)
Computer security → Cybersecurity – "Cybersecurity" or "cyber security" is a much more commonly used name to refer to this field, compared to "computer security". Perhaps 10 years ago, this wasn't the case, but it's different now.
I did a quick survey of the article's references, and the results were: 3 sources (1, 4, 21) used the term "computer security", 18 sources (6, 94, 104, 143, 149, 150, 151, 153, 155, 156, 157, 158, 163, 165, 170, 171, 193, 199) used the term "cyber security", and 16 sources (29, 36, 44, 71, 84, 85, 93, 172, 181, 182, 183, 184, 190, 191, 192, 194, 198) used the term "cybersecurity". 3 more sources also used "cybersecurity" (under "Further reading" section), while 2 more sources also used "computer security" (under "External links" section).
This gives a total of 5 sources using "computer security", 18 sources using "cyber security", and 19 sources using "cybersecurity".
Additionally, several government agencies use the term "cyber security" instead of "computer security", such as the Cyber Security Agency of Singapore, the National Cyber Security Centre of the United Kingdom, the Australian Cyber Security Centre, the National Cyber Security Centre of Ireland, and the National Cybersecurity Center of Excellence of the United States.
Furthermore, a quick search reveals that countless different companies and organisations such as BAE Systems, Oxford University, Coursera, Horangi, Ernst & Young, the Institute of Systems Science, the United States Department of Homeland Security, the University of Maryland University College, and Raytheon, all use the term "cybersecurity" or "cyber security". However, very few use "computer security" instead.
Therefore, I believe it is reasonable to suggest that either "cybersecurity" or "cyber security" would be a much better article title than "computer security", given their much more widespread usage as compared to the latter.
Note: Even if WP:SNOW consensus is reached on moving the page, please don't move this page until consensus is also reached on whether "cybersecurity" or "cyber security" should be used as the new article title. Weslam123 (talk • contrib) 14:20, 11 December 2017 (UTC)
*'''Support''' or *'''Oppose''', then sign your comment with ~~~~. Since polling is not a substitute for discussion, please explain your reasons, taking into account Wikipedia's policy on article titles.Alternative possibility: Split Cyber-security out to a separate article on governmental computer security and counter-"cyberspy" activities, while leaving the overall computer security topic as-is. These really are separate though related subjects. — SMcCandlish ☏ ¢ >ʌⱷ҅ᴥⱷʌ< 08:44, 13 December 2017 (UTC)
I'd like to add: the decision made for this page should also apply for "Category:Computer security"; so if this page is moved to "cybersecurity" (or "cyber security"), the category should move to the same name as well. Weslam123 (talk • contrib) 14:33, 11 December 2017 (UTC)
the name that is most commonly used-- "cyber security" in this case -- per WP:COMMONNAME, even though I'm personally fine with either of them like I said above. -- ChamithN (talk) 06:11, 13 December 2017 (UTC)
SMcCandlish, you make a very good argument. However, you're missing the point here. Like I said, the term "computer security" may have had commonplace usage in the past, but that does not mean it has commonplace usage in this current time. Your first link, to book sources, does have merit to it. However, it's severely oudated; the search results are only between 1990 and 2008. A lot can happen in the span of a decade, and the internet has found greatly increased widespread usage in that time period. For example, 10 years ago, few people would probably consider "app" as a word. However, it's now considered to be a proper word, having a different meaning to it's origin word, "application". And this change was brought around through common usage, by common people. So perhaps 10 years ago, the word "app" may have just been seen as a short form of "application", but nowadays, it has a separate meaning of its own.
Likewise, of course "computer security" is going to have more search results in academic materials: that's because "computer security" is a term that has been around for a significantly longer time than "cyber security" or "cybersecurity". But, like I said, word usage can change, and nowadays, "computer security" is very rarely used. As I've given in my examples of government agencies, as well as companies and organisations, they all use "cyber security" or "cybersecurity". If you can find a government agency that's named "Computer Security Agency", or something similar, do let me know. A simple Google search of "cyber security" gives 85,600,000 results, while "cybersecurity" adds another 31,400,000 results to that. In comparison, "computer security" yields only 32,600,000 hits. You're absolutely free to scroll through the first few pages of each search result, and count for yourself how many companies, organisations, and agencies use each term.
If you had made this argument 10, even 5, years ago, you'd be right. But you can't deny that terms used can change over time. Especially with much greater and widespread usage of the internet in the past decade, I think it might be safe to say that the "cyber-" prefix (meaning internet-related stuff) will have more meaning than the "computer-" prefix (meaning... computer), because nowadays if you want to hack someone's stuff, you're probably gonna do it over the internet, instead of stealing the physical computer from their home.
And as Mr. Guye agrees, basing the article title based off its sources isn't a bad thing to do; in fact, I think it might be the ideal option. If your sources tell you that "cyber security" is more commonly used than "computer security", then you name your article as "cyber security". Likewise, if your sources tell you that "computer security" is more commonly used than "cyber security", then you name your article as "computer security". If you feel that the article has "poor sources", and "Reliable ones on the topic overwhelmingly use "computer security"", then you're absolutely free to add in your reliable sources into the article. If you feel that the article doesn't have good sources, you feel that other sources are better, you can always just add your preferred sources into the article, instead of complaining.
Finally, as ChamithN pointed out, we should probably name the article based on common usage, as per WP:COMMONNAME. So if people use "cyber security" more, you name the article as "cyber security". An apple might be scientifically known as "Malus pumila", but nobody uses that term; everyone just calls that fruit an "apple". So therefore, the article is titled as "apple".
If you wish to insist that "cyber security" is just some word made up by journalists to sound impressive, then sure. But if that's so, why is it that government agencies, companies, and organisations all almost entirely use "cyber security", instead of "computer security"? Weslam123 (talk • contrib) 10:23, 13 December 2017 (UTC)
determined by its prevalence in a significant majority of independent, reliable English-language sources. So, in the end, books and other academic material must take precedent over a Google Trends query when it comes to determining the most commonly used term. (Apologies to you Weslam123, If I caused any confusion.) But, If we were to go by SMcCandlish's argument that "this is lowest-common-denominator pandering to poor sources", the issue then arises is that the article itself is "pandering to poor sources" as only 5 sources cited in the article were using the term "computer security" as opposed to 18 using "cyber security" and 19 using "cybersecurity". -- ChamithN (talk) 10:42, 13 December 2017 (UTC)
As the main author of WP:Specialized-style fallacy, I'm of course mindful of the problem of over-depending on technical, insider language. But "computer security" is not technical insider language, despite being favored by the actual technical insiders as well as by people who don't think cyber- is still nifty. "Computer security" is just normal English. It's "cyber[-]security" that's the weird one out; it's become technology-policy lingo for, more or less, "what the government and its contractors are doing about computer security within the spheres of governmental and commercial infrastructure, especially with regard to widescale system cracking and disruption attacks, industrial espionage, and traditional espionage through computers and other gadgets and stuff". It's the flip side of "cyber[-]war[fare]". We're probably stuck with that term in it's various permutations, but "cyber[-]security" should either be a redir to this article as it is now, or a WP:SPINOFF about the actual current usual scope of the term.
PS: yes, it should by hyphenated or fully compounded; cyber- is a prefix, not a word, and "cyber security" is just poor English by people who forgot to use a dictionary. There's slang stand-alone verb [to] cyber (from the noun cyber-sex), and it means 'to masturbate while chatting or camming online'. That's definitely not what is meant here, or in cyber[-]war[fare]!
PPS: Government agencies are unreliable on a great many things, especially when it comes to security matters (they often have a mandate to lie, directly or by omission, about them for national security reasons) and on language usage, because they have their own internal bureaucratese lingo that even has its own style guides (e.g. The GPO Style Manual) which sharply diverge from normal English on many points. But I wasn't making any kind of point about the "cyber[-]security" sources that happen to be in this article, anyway; for all I know they're amazingly fantastic works. What I see in broad usage is that journos and politicians use the silly term, and people who actually know a computer and its security from their elbow do not [except in a technology-policy context like national security and industrial espionage, and they often don't use it then, either].
— SMcCandlish ☏ ¢ >ʌⱷ҅ᴥⱷʌ< 13:58, 13 December 2017 (UTC); [revised slightly, 07:25, 14 December 2017 (UTC)]
To add something else, because both SMcCandlish and Zanhe have made pretty good points: if you guys are unhappy about this article move, because you feel that "computer security" and "cyber security" aren't the same thing, we can always move the article to cyber security first (because this article seems to cover both internet-related and non-internet-related stuff together), and then any content that's "offline" (not related to internet stuff) can always be moved out of this article to a new article. So we'll end up with this article talking about "cyber security" (internet-related security), while we can move some of the non-internet-related stuff to another article and call that one "computer security" (non-internet-related security) or something. Keep in mind, like I said: maybe in the 1990s or 2000s, "computer security" was a more often used term to describe this field, maybe because the internet was less widespread, but nowadays, most people use "cyber security", as I've explained above. The article's contents also mostly talk about internet-related securities and stuff, so I don't think it's as logical to move all the interet-related content out of this article to a separate one. It would seem to me that both Internet security and "computer security" are both branches of the main "cyber security" field. What do you guys think? Weslam123 (talk • contrib) 05:47, 14 December 2017 (UTC)
We just don't do that. We have a standard operating procedure for cases like this. If cyber-security, a politicized subtopic of the computer-science topic of community security, has become a notable enough thing on its own (and it very clearly has), then we WP:SPINOFF a new article about it, any time that just having a section on it in the main article would be too long or if it would unbalance the material in the general-topic article to be overwhelmingly about the subtopic (both of which would clearly happen in this case.
— SMcCandlish ☏ ¢ >ʌⱷ҅ᴥⱷʌ< 07:05, 18 December 2017 (UTC)
Alright, the seven day period is up and we haven't been able to reach a consensus yet, so I'm going to ask if everyone can get together and see if we're able to reach some sort of agreement. Otherwise, I think I'll just start WP:RFC to see if we can get more people to join the discussion. Mr. Guye, ChamithN, SMcCandlish, Zanhe, ZXCVBNM, CookieMonster755, Zokie, and JFG, any comments? Weslam123 (talk • contrib) 05:46, 18 December 2017 (UTC)
That component is one of the things that makes cybersecurity a clearly distinct topic. Computer security in and of itself (i.e. as a science, a philosophy, a study, a bunch of code, a testing methodology, a series of best practices, etc., etc., in the generalized abstract) has no particular connection to the intelligence/counterintelligence world, while cybersecurity is intimately bound up with it. To an extent, "cybersecurity" is where espionage and computer security intersect (both at the NatSec/infrastructure level and the economic one, where the industrial espionage, financial systems, etc. concerns live).
— SMcCandlish ☏ ¢ >ʌⱷ҅ᴥⱷʌ< 07:56, 18 December 2017 (UTC)
"government computer security" supposed to be different from "normal" computer security(In fact, they are related), but because a separate article regarding the "governmental computer security" could serve as a "{{see also}}" article/supplement. However, looking at it from your perspective, I see now that it'd only mislead people further into believing that "cyber security" and "computer security" are two different things. Instead, putting a short explanation in the lead to differentiate "Cyber security" from "Internet security", like you said, might be a good compromise. Yes, I think you were right about the discussion getting sidetracked, for which I'm equally guilty. An RFC might help get it back on track. -- ChamithN (talk) 07:49, 18 December 2017 (UTC)
ChamithN, it's more about public policy, impact, infrastructure, politics, regulatory frameworks, etc; "cyberspy" stuff is a small component of it. What all these thing have in common is that they aren't computer science, even in the applied sense.
— SMcCandlish ☏ ¢ >ʌⱷ҅ᴥⱷʌ< 07:59, 18 December 2017 (UTC)
24.231.148.135 (talk) 01:13, 9 March 2018 (UTC)== Some initial ideas on a split and an overhaul ==
I would think the place to start would be the large "Systems at risk" section. This where a large chunk of the material segues from technical to social/policy/public-impact material. That whole section, and "Impact of security breaches" immediately after it, could be the reduced to short WP:SUMMARY paragraphs in this article but retained in full glory as some of the core material at Cybersecurity. There's an elephant missing from the room, to mix a metaphor: the tiny "government" subsection is badly underdeveloped, given that the likelihood of Russian tampering in the most recent US presidential election is a massive international "extended incident" that is still unfolding with potentially serious global consequences. (Some would consider the loose cannon in the White House to already be serious global consequences, but I digress).
Cybersecurity will also need most of the material on the legal/regulatory frameworks, and so on. We have a lot of that in "Legal issues and global regulation" (though not all legal issues are cybersecurity matters – we should be careful here, and avoid anachronism in particular, e.g. the Morris worm pre-dates any notion of "cybersecurity", and various legal issues have to do with privacy, civil torts for damages, and so on). "Role of government" is obviously next, then the bulk of the "International actions" and "National actions" materials. "Modern warfare", too.
The "Job market" section is basically sloppy original research (specifically WP:SYNTH conflating different sources talking about different things to reach a novel, mixed-together conclusion). It's badly confusing professional computer security work in general (both a component and focus of modern sysadmin work, and a specialization one can now get professional certifications in), with "cybersecurity" work which is primarily a government, institutional, and "big data" careeer, a line of work that has more to do with infrastructural and organizational policy than coding. They're both distinct from data forensics and various other specializations used frequently in "cyberspying" and "cyberwarfare". Superficial journalism is apt to commingle all of these things imprecisely; we have use such source more carefully, and use better sources.
Much of the rest of this is general computer security information – mostly computer science technical material and systems design-philosophy stuff. This includes the sections "Vulnerabilities and attacks" for the most part,
"Information security culture": a lot to cover here. It is at least half a general computer-security topic, but the material we have right now is pretty much all institutional cybersecurity stuff, so it should move. The spinoff article actually needs more in-depth material than this, too. The governmental cybersecurity culture (centered in the US on the "DC metroplex", and composed of both actual govt. employees and a whole microcosm of "Beltway bandit" contractors, much of the work of whom requires a security clearance) is quite distinct from that of the major-corporation world, which is diffuse geographically but institutionalized a system of certifications (I've been through some of this training, and can attest that much of it's infrastructural and organizational in addition to technical – there's a thick management-and-policy layer to it).
However, for the Computer security article, we'll need a similar section with new material in it, since neither the government or commercial infosec "cultures" (a misuse of that word) are closely related to either hacker subculture (i.e. what produced Linux and most of modern computer security as an applied matter) and academic computer science (which provided the foundation on which that work was possible, and also did the really hard part like making encryption that's reliable, which is far more difficult that most people realize). A lengthy aside: The fact that there's a sharp divide between the hacker world (including white-hat hackers who made the Internet as we know it happen, not just black-hat system crackers, scriptkiddies, the darknet, etc.) and the tech-savvy sides that can be found in the government and institutional worlds is very well-documented since the mid-1990s in secondary works by Stephen Levy, Bruce Sterling (in his non-fiction) and many others. These spheres have been interfacing warily with each other at events like DefCon and places like MIT for decades, but a sharp socio-politico-cultural divide between them remains, similar to that between the DIY computer culture that launched Silicon Valley and still fuels tech startups all over the world, and the "big data and brogrammers" world that dominates Silicon Valley, Redmond, the DC Metroplex, etc., today.
"Attacker motivation" is another big subtopic, but all we have is a paltry {{sect-stub}}. Material on this needs better development at both articles in different ways, in summary form at the main one, and in detailed sections for some attacker types at the cybersecurity article. The latter should cover in detail at least the following: financial motivations (from attacks on the financial system to ransomware); foreign-policy-related ones (espionage and cyberwarfare (on which we have an entire article to just summarize and link to with {{Main}}); organized crime ones (increased gang and mob use of technology, domestic terrorism, yadda yadda); corporation-versus-corporation ones (trade secrets and industrial espionage, which are also often tied to national interests, e.g. steal pre-patent biochem research from a company in another country); anti-authoritarianism ones (Anonymous, Snowden, Wikileaks, sousveillance, cryptoancharcism, etc.); and – from the other direction – authoritarian ones (police abuse of surveillance authority, the Great Firewall, NSA mass-snooping on national and intl. civilian communications, ECHELON and the EU's reaction to it, pressure on Apple to back-door the iPhone – there's lots of stuff going on in the "cyber-insecurity" sector, much of which goes back to the 1990s, e.g. the Clipper Chip, CALEA, the Bernstein case, and other government efforts to thwart civilian communications security).
On that last bit, it is a PoV problem to rule out governmental forces as "attackers"; they not only attack each other's security, they often attack that of their own populations. That said, the bulk of the cybersecurity material is going to be from the perspective of the governmental position being the "mainstream" one. This is another of the ways in which "computer security" and "cybersecurity" are absolutely distinct topics. Computer security in general is neutral and agnostic when it comes to who the attacker is: that's anyone trying to get in who is not the system owner/controller and parties authorized by them. Period. Many computer security solutions have been rolled out, from PGP onward, with the specific intent of thwarting bad-acting governments. EFF, where I worked for a decade or so, was founded on such concerns, and CRF, whose CCO I was after that, was entirely focused on producing communications security solutions for human rights workers, war-zone journalists, and others (i.e., the entire threat model was bad-acting governments and wanna-be governments).
Moving on: "Notable attacks and breaches" is probably all Computer security not Cybersecurity material. The latter would be more like infrastructural things – affecting elections, cyberwarfare targeting of power grids and financial systems, attempts to breach governmental computer systems for organized not just "curious teenage hacker" purposes, and so on. Many of these are more theoretical "arms race" matters than incident reports, though there have been some, despite both government and major institutions being reticent about breaches (for reasons we call "WP:BEANS" over here in WP land).
The "Terminology" section is Computer security not Cybersecurity material, though a short glossary could be worked over there, of terms of art that are unique to information technology policy materials. The terminology section we have now should actually be worked up into a glossary article, if we don't already have one in Category:Glossaries of computers. If this is done smartly, as a template-structed glossary, we can use a template to link to terms from any article, obviating the need to redundantly define terms (in-situ or in a terms section) in both articles. (Summary: it works by creating a topical Template:Glossary link wrapper, like {{cuegloss}} for Glossary of cue sports terms, e.g. a {{csgloss}} in this case. We could do something like "" without having to keep putting in "{{csgloss|Endpoint security}} verification can mitigate a {{csgloss|CoT}} failure and ...[[Glossary of computer science terms#endpoint security|Endpoint]]", "[[Glossary of computer science terms#chain of trust|CoT]]" and so on.)
"Scholars" is classic unencyclpedic listcruft, pointlessly duplicating the functionality of a category. It's salvageable, though. By IDing some of the key notable figures, we've already decided who to write about in proper prose. This should probably done chronologically, and would serve as the beginnings of the missing "History" section which would actually be of vastly more value, near the start of the article, than an article-end pile of "name dropping".
That's all from just a quick skim; as I look at various sub-sub-sections I see a lot of commingling of technical material and socio-political/infrastructure-policy material that will need to be teased apart. Basically this entire article is a huge palimpsest of people trying to write about security from an academic, technical, practices, philosophy, and history manner coming into conflict people people trying to write about it from a regulatory/legal, infrastructure protection, industry protection, spying/war/politics, and societal impacts direction, with jumbled results.
I'm going to point some related wikiprojects to this page and hopefully get some additional input on how we should proceed. — SMcCandlish ☏ ¢ >ʌⱷ҅ᴥⱷʌ< 09:41, 18 December 2017 (UTC)
— SMcCandlish ☏ ¢ >ʌⱷ҅ᴥⱷʌ< 09:41, 18 December 2017 (UTC)
Just as a FYI, the 2017 paper "Towards a More Representative Definition of Cyber Security" (ref'd in the first sentence of our article), concludes that an accurate definition of "cyber security" would be:
...but note that "this definition will become less fitting or relevant as social, political, and technological developments in this space progress". - Snori (talk) 01:50, 12 October 2018 (UTC)
Please consider incorporating any useful material from the above submission into this article. The submission is eligible for deletion in 6 months. ~Kvng (talk) 13:45, 29 November 2018 (UTC)
Recent edit by user:Lesliany D Vargas because:
- Snori (talk) 03:44, 7 April 2020 (UTC)
The article covers many ways of compromising a computer or a network, it describes vulnerabilities, but nowhere does it use the word 'compromise' or 'compromised computer', meaning successful exploit of a vulnerability. This is a bit Nelsonian, as though attacks can always be defeated. But I can't see how to integrate it anywhere, can anyone else do so? --John Maynard Friedman (talk) 19:45, 5 September 2021 (UTC)
This article was the subject of a Wiki Education Foundation-supported course assignment, between 29 August 2018 and 12 December 2018. Further details are available on the course page. Student editor(s): Mguinko.
Above undated message substituted from Template:Dashboard.wikiedu.org assignment by PrimeBOT (talk) 18:15, 16 January 2022 (UTC)
This article was the subject of a Wiki Education Foundation-supported course assignment, between 16 May 2019 and 24 August 2019. Further details are available on the course page. Student editor(s): CCastano97. Peer reviewers: CCastano97.
Above undated message substituted from Template:Dashboard.wikiedu.org assignment by PrimeBOT (talk) 19:24, 17 January 2022 (UTC)
This article was the subject of a Wiki Education Foundation-supported course assignment, between 6 January 2020 and 25 April 2020. Further details are available on the course page. Student editor(s): Lesliany D Vargas. Peer reviewers: Rmoli039.
Above undated message substituted from Template:Dashboard.wikiedu.org assignment by PrimeBOT (talk) 19:24, 17 January 2022 (UTC)
The use of Curlie in the "External links" section appears to be in violation of WP:ELNO#9. -- Otr500 (talk) 11:59, 2 April 2022 (UTC)
Computer security cyber security 41.191.105.93 (talk) 19:00, 24 November 2022 (UTC)
If anyone is feeling so inclined, the article Privacy software has no citations whatever and so needs some tlc. 𝕁𝕄𝔽 (talk) 18:14, 7 December 2022 (UTC)
This article was the subject of a Wiki Education Foundation-supported course assignment, between 17 January 2023 and 15 May 2023. Further details are available on the course page. Student editor(s): D0a80276 (article contribs).
— Assignment last updated by D0a80276 (talk) 08:13, 12 February 2023 (UTC)
Digital security does seem to be a small, long-standing article that is a synonym; it also has some concerns regarding advertising. Readers might therefore best be served by a selective merge and redirect of that other article to here. Klbrain (talk) 10:28, 18 February 2023 (UTC)
The result of the move request was: not moved. The consensus was to create a new category or page for cybersecurity than move the current one. (non-admin closure) Captain Jack Sparrow (talk) 12:52, 11 July 2023 (UTC)
Computer security → Cybersecurity – Google Ngrams speaks for itself on the fact that cybersecurity is the WP:COMMONNAME by a wide margin. ᴢxᴄᴠʙɴᴍ (ᴛ) 10:54, 4 July 2023 (UTC)
I am planning on fixing grammar and style issues and cleaning up the article in general. If you disagree with with any of the content removal, please let me know. Thanks. — Preceding unsigned comment added by 208.250.65.158 (talk • contribs) 13:13, July 17, 2007 (UTC)
Can you be more specific about changes Tonymetz 💬 16:36, 1 April 2024 (UTC)
Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.