Literature DB >> 28679022

Cyber Risk Management for Critical Infrastructure: A Risk Analysis Model and Three Case Studies.

M-Elisabeth Paté-Cornell1, Marshall Kuypers1, Matthew Smith1, Philip Keller1.   

Abstract

Managing cyber security in an organization involves allocating the protection budget across a spectrum of possible options. This requires assessing the benefits and the costs of these options. The risk analyses presented here are statistical when relevant data are available, and system-based for high-consequence events that have not happened yet. This article presents, first, a general probabilistic risk analysis framework for cyber security in an organization to be specified. It then describes three examples of forward-looking analyses motivated by recent cyber attacks. The first one is the statistical analysis of an actual database, extended at the upper end of the loss distribution by a Bayesian analysis of possible, high-consequence attack scenarios that may happen in the future. The second is a systems analysis of cyber risks for a smart, connected electric grid, showing that there is an optimal level of connectivity. The third is an analysis of sequential decisions to upgrade the software of an existing cyber security system or to adopt a new one to stay ahead of adversaries trying to find their way in. The results are distributions of losses to cyber attacks, with and without some considered countermeasures in support of risk management decisions based both on past data and anticipated incidents.
© 2017 Society for Risk Analysis.

Keywords:  Cyber risk management; cyber security; infrastructure protection

Year:  2017        PMID: 28679022     DOI: 10.1111/risa.12844

Source DB:  PubMed          Journal:  Risk Anal        ISSN: 0272-4332            Impact factor:   4.000


  3 in total

1.  Using Advanced Analytic Techniques to Optimize Cyber-Physical Defensive Plans in Sports Infrastructures and Facilities.

Authors:  Rui Wang
Journal:  Comput Intell Neurosci       Date:  2022-06-11

2.  Stochastic Counterfactual Risk Analysis for the Vulnerability Assessment of Cyber-Physical Attacks on Electricity Distribution Infrastructure Networks.

Authors:  Edward J Oughton; Daniel Ralph; Raghav Pant; Eireann Leverett; Jennifer Copic; Scott Thacker; Rabia Dada; Simon Ruffle; Michelle Tuveson; Jim W Hall
Journal:  Risk Anal       Date:  2019-02-27       Impact factor: 4.000

3.  Who Should Pay for Interdependent Risk? Policy Implications for Security Interdependence Among Airports.

Authors:  Gabriel Kuper; Fabio Massacci; Woohyun Shim; Julian Williams
Journal:  Risk Anal       Date:  2020-02-22       Impact factor: 4.000

  3 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.