Risk-Based Cybersecurity Compliance Assessment System (RC2AS)

被引:4
|
作者
Alfaadhel, Afnan [1 ]
Almomani, Iman [1 ,2 ]
Ahmed, Mohanned [1 ]
机构
[1] Prince Sultan Univ, Comp Sci Dept, Secur Engn Lab, Riyadh 11586, Saudi Arabia
[2] Univ Jordan, King Abdullah Sch Informat Technol, Comp Sci Dept, Amman 11942, Jordan
来源
APPLIED SCIENCES-BASEL | 2023年 / 13卷 / 10期
关键词
compliance assessment; maturity model; cybersecurity; risk; ECC; Saudi Arabia;
D O I
10.3390/app13106145
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Cybersecurity attacks are still causing significant threats to individuals and organizations, affecting almost all aspects of life. Therefore, many countries worldwide try to overcome this by introducing and applying cybersecurity regularity frameworks to maintain organizations' information and digital resources. Saudi Arabia has taken practical steps in this direction by developing the essential cybersecurity control (ECC) as a national cybersecurity regulation reference. Generally, the compliance assessment processes of different international cybersecurity standards and controls (ISO2700x, PCI, and NIST) are generic for all organizations with different scopes, business functionality, and criticality level, where the overall compliance score is absent with no consideration of the security control risk. Therefore, to address all of these shortcomings, this research takes the ECC as a baseline to build a comprehensive and customized risk-based cybersecurity compliance assessment system (RC2AS). ECC has been chosen because it is well-defined and inspired by many international standards. Another motive for this choice is the limited related works that have deeply studied ECC. RC2AS is developed to be compatible with the current ECC tool. It offers an offline self-assessment tool that helps the organization expedite the assessment process, identify current weaknesses, and provide better planning to enhance its level based on its priorities. Additionally, RC2AS proposes four methods to calculate the overall compliance score with ECC. Several scenarios are conducted to assess these methods and compare their performance. The goal is to reflect the accurate compliance score of an organization while considering its domain, needs, resources, and risk level of its security controls. Finally, the outputs of the assessment process are displayed through rich dashboards that comprehensively present the organization's cybersecurity maturity and suggest an improvement plan for its level of compliance.
引用
收藏
页数:31
相关论文
共 50 条
  • [21] An Integrated Framework for Power and ICT System Risk-based Security Assessment
    Ciapessoni, Emanuele
    Cirio, Diego
    Pitto, Andrea
    Kjolle, Gerd
    Sforna, Marino
    2013 IEEE GRENOBLE POWERTECH (POWERTECH), 2013,
  • [22] Risk-based assessment of climate change impact on storm drainage system
    Alsaqqaf, Z.
    Zhang, H.
    Mohamed, S.
    FLOOD RECOVERY, INNOVATION AND RESPONSE II, 2010, 133 : 13 - 24
  • [23] Hierarchical Model-Based Cybersecurity Risk Assessment During System Design
    Jungebloud, Tino
    Nguyen, Nhung H.
    Kim, Dong Seong
    Zimmermann, Armin
    ICT SYSTEMS SECURITY AND PRIVACY PROTECTION, IFIP SEC 2023, 2024, 679 : 30 - 44
  • [24] A quantitative risk-based maintenance strategy for coastal RC structures
    Zheng, J. J.
    Shao, L.
    Mao, K. F.
    Li, C. Q.
    Wang, Z. F.
    STRUCTURAL HEALTH MONITORING AND INTELLIGENT INFRASTRUCTURE, VOLS 1 AND 2, 2006, : 1317 - 1321
  • [25] Application of multivariate statistics in a risk-based approach to regulatory compliance
    Lee, K. M.
    Herrman, T. J.
    Jones, B.
    FOOD CONTROL, 2009, 20 (01) : 17 - 26
  • [26] A quantitative optimization model for dynamic risk-based compliance management
    Mueller, S.
    Supatgiat, C.
    IBM JOURNAL OF RESEARCH AND DEVELOPMENT, 2007, 51 (3-4) : 295 - 307
  • [27] Risk-based reliability assessment and testing stop time based software system modeling
    Gupta, Priyanka
    Anand, Adarsh
    Tamura, Yoshinobu
    Ram, Mangey
    INTERNATIONAL JOURNAL OF QUALITY & RELIABILITY MANAGEMENT, 2023,
  • [28] Risk-based classification system of nanomaterials
    Tommi Tervonen
    Igor Linkov
    José Rui Figueira
    Jeffery Steevens
    Mark Chappell
    Myriam Merad
    Journal of Nanoparticle Research, 2009, 11 : 757 - 766
  • [29] Risk-based classification system of nanomaterials
    Tervonen, Tommi
    Linkov, Igor
    Figueira, Jose Rui
    Steevens, Jeffery
    Chappell, Mark
    Merad, Myriam
    JOURNAL OF NANOPARTICLE RESEARCH, 2009, 11 (04) : 757 - 766
  • [30] Risk-based Resilience Assessment Model Focusing on Urban Infrastructure System Restoration
    Ongkowijoyo, Citra S.
    Doloi, Hemanta
    7TH INTERNATIONAL CONFERENCE ON BUILDING RESILIENCE: USING SCIENTIFIC KNOWLEDGE TO INFORM POLICY AND PRACTICE IN DISASTER RISK REDUCTION, 2018, 212 : 1115 - 1122