Literature DB >> 27935146

Resilience of Cyber Systems with Over- and Underregulation.

Viktoria Gisladottir1, Alexander A Ganin1,2, Jeffrey M Keisler3, Jeremy Kepner4, Igor Linkov1.   

Abstract

Recent cyber attacks provide evidence of increased threats to our critical systems and infrastructure. A common reaction to a new threat is to harden the system by adding new rules and regulations. As federal and state governments request new procedures to follow, each of their organizations implements their own cyber defense strategies. This unintentionally increases time and effort that employees spend on training and policy implementation and decreases the time and latitude to perform critical job functions, thus raising overall levels of stress. People's performance under stress, coupled with an overabundance of information, results in even more vulnerabilities for adversaries to exploit. In this article, we embed a simple regulatory model that accounts for cybersecurity human factors and an organization's regulatory environment in a model of a corporate cyber network under attack. The resulting model demonstrates the effect of under- and overregulation on an organization's resilience with respect to insider threats. Currently, there is a tendency to use ad-hoc approaches to account for human factors rather than to incorporate them into cyber resilience modeling. It is clear that using a systematic approach utilizing behavioral science, which already exists in cyber resilience assessment, would provide a more holistic view for decisionmakers.
© 2016 Society for Risk Analysis.

Entities:  

Keywords:  Cyber network; regulation; resilience

Year:  2016        PMID: 27935146     DOI: 10.1111/risa.12729

Source DB:  PubMed          Journal:  Risk Anal        ISSN: 0272-4332            Impact factor:   4.000


  3 in total

1.  Stochastic Counterfactual Risk Analysis for the Vulnerability Assessment of Cyber-Physical Attacks on Electricity Distribution Infrastructure Networks.

Authors:  Edward J Oughton; Daniel Ralph; Raghav Pant; Eireann Leverett; Jennifer Copic; Scott Thacker; Rabia Dada; Simon Ruffle; Michelle Tuveson; Jim W Hall
Journal:  Risk Anal       Date:  2019-02-27       Impact factor: 4.000

2.  Who Should Pay for Interdependent Risk? Policy Implications for Security Interdependence Among Airports.

Authors:  Gabriel Kuper; Fabio Massacci; Woohyun Shim; Julian Williams
Journal:  Risk Anal       Date:  2020-02-22       Impact factor: 4.000

3.  The Work-Averse Cyberattacker Model: Theory and Evidence from Two Million Attack Signatures.

Authors:  Luca Allodi; Fabio Massacci; Julian Williams
Journal:  Risk Anal       Date:  2021-05-07       Impact factor: 4.302

  3 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.