Cyber Security Maturity Assessment Framework for Technology Startups: A Systematic Literature Review

被引:0
|
作者
Marican, Mohamed Noordin Yusuff [1 ]
Abd Razak, Shukor [2 ]
Selamat, Ali [1 ,3 ,4 ,5 ]
Othman, Siti Hajar [1 ]
机构
[1] Univ Teknol Malaysia, Fac Comp, Johor Baharu 81310, Malaysia
[2] Univ Sultan Zainal Abidin, Fac Informat & Comp, Kuala Terengganu 21300, Malaysia
[3] Univ Teknol Malaysia, Malaysia Japan Inst Technol, Kuala Lumpur 54100, Malaysia
[4] Univ Teknol Malaysia, MaGICX Media & Game Innovat Ctr Excellence, Johor Baharu 81310, Malaysia
[5] Univ Hradec Kralove, Fac Informat & Management, Hradec Kralove 50003, Czech Republic
关键词
Cyberattack; Multiaccess communication; Organizations; Investment; Computer security; Capability maturity model; Systematics; Cyber security risk; cyber security maturity; cyber security framework; cyber risk quantification; return of security investment; technology startup; TOOL;
D O I
10.1109/ACCESS.2022.3229766
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity has gained increasing importance among firms of different sizes and industries due to the significant rise of cyber-attacks over time. Technology startups are particularly vulnerable to cyber-attacks due to the lack of cyber security measures. This is because of limited human capital and financial resources to quantify cyber risks and allocate appropriate investments to cyber security. Technology startups are suppliers and vendors to large organisations such as MNCs, government and financial institutions. They could possibly have a network connection back to the large organisations and might even store confidential information of these large organisations such as financial records, personal data and other proprietary information. As such, with the lack of appropriate cyber security measures, technology startups may be an attack vector for malicious hackers to gain entry to the large organisations. Focusing on technology startups, this study conducted a systematic literature review on cyber security maturity assessment frameworks. This study addressed five research questions on the existing cyber security maturity assessment frameworks in various industries, the target for implementation, cyber security maturity level, shared control domains of these frameworks, and the quantification of the return of cyber security investments. Referring to the Preferred Reporting Items for Systematic Reviews and Meta-Analysis (PRISMA) checklist, a detailed analysis was performed on 24 published research articles (out of 650) from reputable journals and conference proceedings from January 2011 to June 2022. The results revealed the lack of an end-to-end cyber security maturity assessment framework for technology startups. Despite the similarities in the cyber security maturity level for certain frameworks, the results revealed no singular framework that can evaluate the cyber security maturity level of technology startups. The results further revealed the lack of studies on the quantification of the return of cyber security investments in an end-to-end cyber security maturity assessment framework for technology startups. This put the startup in a vulnerable position since management is not able to obtain relevant data on the startup's cyber maturity posture and without such information, they are not able to appropriately justify their security investments to mitigate the evolving cyber risks.
引用
收藏
页码:5442 / 5452
页数:11
相关论文
共 50 条
  • [1] Information and cyber security maturity models: a systematic literature review
    Rabii, Anass
    Assoul, Saliha
    Ouazzani Touhami, Khadija
    Roudies, Ounsa
    [J]. INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 627 - 644
  • [2] Systematic Literature Review for Modeling a Cyber Risk Assessment Framework
    Amin, Zahari Mohd
    Anwar, Norizan
    Shoid, Mohd Shamsul Mohd
    Samuri, Suzaliana
    [J]. ENVIRONMENT-BEHAVIOUR PROCEEDINGS JOURNAL, 2024, 9 : 189 - 195
  • [3] Systematic Literature Review for Modeling a Cyber Risk Assessment Framework
    Amin, Zahari Mohd
    Anwar, Norizan
    Shoid, Mohd Shamsul Mohd
    Samuri, Suzaliana
    [J]. ENVIRONMENT-BEHAVIOUR PROCEEDINGS JOURNAL, 2024, 9 : 189 - 195
  • [4] A systematic literature review of blockchain cyber security
    Taylor, Paul J.
    Dargahi, Tooska
    Dehghantanha, Ali
    Parizi, Reza M.
    Choo, Kim-Kwang Raymond
    [J]. DIGITAL COMMUNICATIONS AND NETWORKS, 2020, 6 (02) : 147 - 156
  • [5] A systematic literature review of mitigating cyber security risk
    Syafila Kamarudin
    Lian Tang
    Jusang Bolong
    Nor Azura Adzharuddin
    [J]. Quality & Quantity, 2024, 58 (4) : 3251 - 3273
  • [6] A Systematic Literature Review on Cyber Security Education for Children
    Saglam, Rahime Belen
    Miller, Vincent
    Franqueira, Virginia N. L.
    [J]. IEEE TRANSACTIONS ON EDUCATION, 2023, 66 (03) : 274 - 286
  • [7] A technology maturity assessment framework for Industry 5.0 machine vision systems based on systematic literature review in automotive manufacturing
    Konstantinidis, Fotios K.
    Myrillas, Nikolaos
    Tsintotas, Konstantinos A.
    Mouroutsos, Spyridon G.
    Gasteratos, Antonios
    [J]. INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 2023,
  • [8] A synthesized framework for the formation of startups' innovation ecosystem A systematic literature review
    Ojaghi, Hamed
    Mohammadi, Mahdi
    Yazdani, Hamid Reza
    [J]. JOURNAL OF SCIENCE AND TECHNOLOGY POLICY MANAGEMENT, 2019, 10 (05) : 1063 - 1097
  • [9] Cyber Security Risk Management for Ports - A Systematic Literature Review
    Drummond, Barbara M.
    Machado, Raphael C. S.
    [J]. 2021 IEEE INTERNATIONAL WORKSHOP ON METROLOGY FOR THE SEA (METROSEA 2021), 2021, : 406 - 411
  • [10] Internet governance and cyber-security: a systematic literature review
    Yusif, Salifu
    Hafeez-Baig, Abdul
    Anachanser, Charles
    [J]. INFORMATION SECURITY JOURNAL, 2024, 33 (02): : 158 - 171