The concepts we use to describe and communicate affects how we think about phenomena. How we think about phenomena affects both research and practice. The project Security Culture has focused on a few concepts central to information security; concepts that are use both in practice and research.

We have mainly analysed five concepts: ‘security’ (specifically: ‘information security’), ‘information’ (specifically: ‘semantic information’), ‘privacy’, ‘anonymity’, and ‘culture’. The focal point of the analyses has been normative, i.e. the central question focuses on finding the best possible definition of these concepts. For example, what is the best way to conceptualise ‘information security’?

To develop new or improved definitions of concepts – such as information, security, privacy, anonymity, and culture – is an important part of creating tools for security research as well as practitioners. For example, we have contributed with a definition of information security that is more suitable for identification and analysis of security risks that are constituted by value conflicts. Such value conflicts include, e.g., security and privacy trade-offs.

This project has focused on conceptual analysis relating to both basic and applied research. We have often attempted to analyse the essence or fundamental nature of the studied concepts. The insights that our analyses bring can – as noted above – be used both in practice and in further research. The latter could lead to further analysis relating to the individual concepts or by promoting a framework intended for broader analysis. A few interesting examples include, e.g.: expanding on the analysis of the concept of information security by investigation whether the concept is part of one coherent security concept (or if there are several different security concepts). Another way to continue the analysis would be to test some of the projects definitions in practice (something that is best done in co-operation with more empirically focused researchers). A third option would be to focus on applied ethical challenges relating to security.

