Prioritising IT service outages Personal proposal by Per-Arne Andersen D5 · Spring 2027 https://thesis.uya.no/proposals/protect-the-services-people-need/ Show which municipal services would be affected by an IT incident. TECHNICAL - Build a dependency viewer with an editable service-priority rubric. - Compare graph and table views containing the same dependencies and priority information. DATA (planned) 12 services, 20 systems, 30 outage narratives Create required-dependency links, service criticality, outage duration and workarounds. Include shared identity/network/storage outages; exclude failover modelling. METHOD 4 IT staff and 4 service owners review 10 disjoint incidents. Measure omitted service impacts, time and rank-change reasons. Verify affected-service sets against independent hand-traced answers; technical-severity ranking is a descriptive reference. OUTPUT Dependency viewer, incident set and ranking comparison. BACHELOR Task: Build an IT-service dependency viewer with a fixed outage-priority rubric. Data: 12 services, 20 systems, 30 outage narratives (planned) Create required-dependency links, service criticality, outage duration and workarounds. Include shared identity/network/storage outages; exclude failover modelling. Requires: Recruit both roles and an independent key reviewer; comparable public-service organisations can participate. Method: Use the fictional service graph; test reachability and impact counts, then observe prioritisation tasks. Plan 4 participant sessions. Output: A service-impact dashboard with correct graph calculations. Use relevant literature to justify the established approach; a new research contribution is not the aim of this proposal. MASTER Test whether service graphs help dependency reasoning but hinder exact priority lookup. Derive task-specific predictions from cognitive-fit research; compare graph/table with identical facts and separate graph correctness from priority judgement. Intended contribution: Evidence about which outage tasks benefit from dependency visualisation and why. STARTING PAPERS Vessey & Galletta (1991) — Cognitive Fit: https://pubsonline.informs.org/doi/10.1287/isre.2.1.63 Test whether a representation helps one kind of task more than another. Wang & Strong (1996) — Beyond Accuracy: https://www.tandfonline.com/doi/abs/10.1080/07421222.1996.11518099 Distinguish accuracy, completeness, representation and fitness for the task. Search Scopus or Web of Science and ACM Digital Library using the topic query, then follow citations to the thesis start date. Record searches and compare methods, data, findings and limitations in literature-matrix.csv. Use that review to confirm or revise the gap and choose a current comparator. The linked papers are starting points. START HERE Tools: Python, NetworkX, Streamlit 1. Draw the dependency graph and write 3 incidents with manually traced affected services. 2. Define the priority rubric and technical-severity scores independently of the ranking algorithm. 3. Validate graph traversal against the 3 answer keys before creating remaining incidents. Literature search: municipal cyber risk service impact decision support Study controls: - Graph/table comparisons must contain identical dependencies and the same rubric. - Graph precision/recall tests implementation correctness, not whether priorities are socially appropriate. - Use rank correlations with ties for the separate role-comparison study; no consensus ranking is ground truth. - Before collecting participant data, agree consent, storage and withdrawal handling with the supervisor. Use participant codes, not names, in study files. - Separate silent timed tasks from retrospective interviews. Timing during think-aloud sessions is descriptive, not an isolated interface-speed effect. - For the master’s study, use the research task above to define the factors and comparisons in this pilot plan. Preregister one primary outcome and feasible scope after the literature review; do not add every possible model or interface variant. REQUIRES Recruit both roles and an independent key reviewer; comparable public-service organisations can participate. -------------------- NON-TECHNICAL - Create paper incident summaries with technical severity and service consequences. - Ask IT staff and service managers to rank incidents independently. DATA (planned) 10 incident cards + 8 interviews Recruit 4 municipal IT staff and 4 service managers. Give both groups the same fictional incidents and service descriptions. METHOD Compare group rankings using rank correlation; code explanations for disagreements about service importance and response responsibility. OUTPUT Disagreement matrix and a shared prioritisation template. BACHELOR Task: Document how staff currently decide which outage to handle first. Data: 10 incident cards (planned) Give both groups the same fictional incidents and service descriptions. Requires: Recruit both municipal roles. Method: Discuss fictional outages with IT and service staff; collect criteria and disagreement points. Plan 4 participant sessions. Output: A practical prioritisation rubric with unresolved decisions. Use relevant literature to justify the established approach; a new research contribution is not the aim of this proposal. MASTER Explain disagreement between IT and service owners on outage priority. Compare their interpretations of impact and responsibility using the same incidents; distinguish missing facts from different organisational objectives. Intended contribution: A role-based explanation of prioritisation conflicts and decision ownership. STARTING PAPERS Orlikowski & Gash (1994) — Technological Frames: https://dl.acm.org/doi/10.1145/196734.196745 Compare how roles interpret the purpose, operation and use of the same system. Wang & Strong (1996) — Beyond Accuracy: https://www.tandfonline.com/doi/abs/10.1080/07421222.1996.11518099 Distinguish accuracy, completeness, representation and fitness for the task. Search Scopus or Web of Science and ACM Digital Library using the topic query, then follow citations to the thesis start date. Record searches and compare methods, data, findings and limitations in literature-matrix.csv. Use that review to confirm or revise the gap and choose a current comparator. The linked papers are starting points. START HERE Tools: LibreOffice Writer/Calc, audio recorder with consent; no programming required. 1. Prepare a pilot with 2 examples from: 10 incident cards + 8 interviews. Write the task questions and a reference answer sheet. 2. Write a recruitment message, information sheet and consent form for the participants named above. Agree privacy handling with the supervisor before contact. 3. Pilot one session after approval; revise unclear questions, freeze the task sets and coding categories, then recruit the planned sample. Literature search: municipal cyber risk service impact decision support qualitative scenario study Study controls: - Before collecting participant data, agree consent, storage and withdrawal handling with the supervisor. Use participant codes, not names, in study files. - Pilot separately, then freeze the questions and coding plan. Check objective answer keys independently; keep an audit trail of coding, including disagreements. - For comparisons, counterbalance order and case assignment; do not show a person both versions of one case. Report participant-level findings, not repeated tasks as independent people. REQUIRES Recruit both municipal roles. Bachelor: apply established methods and evaluate a practical solution or study. Master: position a research question in current scientific literature, investigate a mechanism or unresolved problem, and explain the contribution. Final scope is agreed with me. Study sizes are proposed; participant recruitment and planned materials are not already arranged.