Literature DB >> 28873246

Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management.

Alexander A Ganin1, Phuoc Quach2, Mahesh Panwar2, Zachary A Collier1, Jeffrey M Keisler3, Dayton Marchese1, Igor Linkov4.   

Abstract

Risk assessors and managers face many difficult challenges related to novel cyber systems. Among these challenges are the constantly changing nature of cyber systems caused by technical advances, their distribution across the physical, information, and sociocognitive domains, and the complex network structures often including thousands of nodes. Here, we review probabilistic and risk-based decision-making techniques applied to cyber systems and conclude that existing approaches typically do not address all components of the risk assessment triplet (threat, vulnerability, consequence) and lack the ability to integrate across multiple domains of cyber systems to provide guidance for enhancing cybersecurity. We present a decision-analysis-based approach that quantifies threat, vulnerability, and consequences through a set of criteria designed to assess the overall utility of cybersecurity management alternatives. The proposed framework bridges the gap between risk assessment and risk management, allowing an analyst to ensure a structured and transparent process of selecting risk management alternatives. The use of this technique is illustrated for a hypothetical, but realistic, case study exemplifying the process of evaluating and ranking five cybersecurity enhancement strategies. The approach presented does not necessarily eliminate biases and subjectivity necessary for selecting countermeasures, but provides justifiable methods for selecting risk management actions consistent with stakeholder and decisionmaker values and technical data. Published 2017. This article is a U.S. Government work and is in the public domain in the U.S.A.

Keywords:  Cybersecurity; MCDA; risk management; vulnerability assessment

Year:  2017        PMID: 28873246     DOI: 10.1111/risa.12891

Source DB:  PubMed          Journal:  Risk Anal        ISSN: 0272-4332            Impact factor:   4.000


  5 in total

1.  Dynamic real-time risk analytics of uncontrollable states in complex internet of things systems: cyber risk at the edge.

Authors:  Petar Radanliev; David De Roure; Max Van Kleek; Uchenna Ani; Pete Burnap; Eirini Anthi; Jason R C Nurse; Omar Santos; Rafael Mantilla Montalvo; La'Treall Maddox
Journal:  Environ Syst Decis       Date:  2020-11-22

2.  Developing and evaluating cybersecurity competencies for students in computing programs.

Authors:  Abdullah Alammari; Osama Sohaib; Sayed Younes
Journal:  PeerJ Comput Sci       Date:  2022-01-17

3.  Stochastic Counterfactual Risk Analysis for the Vulnerability Assessment of Cyber-Physical Attacks on Electricity Distribution Infrastructure Networks.

Authors:  Edward J Oughton; Daniel Ralph; Raghav Pant; Eireann Leverett; Jennifer Copic; Scott Thacker; Rabia Dada; Simon Ruffle; Michelle Tuveson; Jim W Hall
Journal:  Risk Anal       Date:  2019-02-27       Impact factor: 4.000

4.  The Role of the Digital Economy in Rebuilding and Maintaining Social Governance Mechanisms.

Authors:  Fengjuan Niu
Journal:  Front Public Health       Date:  2022-01-14

5.  Who Should Pay for Interdependent Risk? Policy Implications for Security Interdependence Among Airports.

Authors:  Gabriel Kuper; Fabio Massacci; Woohyun Shim; Julian Williams
Journal:  Risk Anal       Date:  2020-02-22       Impact factor: 4.000

  5 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.