A systematic review of cyber-resilience assessment frameworks

被引:25
|
作者
Estay, Daniel A. Sepulveda [1 ]
Sahay, Rishikesh [3 ]
Barfod, Michael B. [1 ]
Jensen, Christian D. [2 ]
机构
[1] Tech Univ Denmark, Dept Technol Management & Econ, Lyngby, Denmark
[2] Tech Univ Denmark, Dept Appl Math & Comp Sci, Lyngby, Denmark
[3] Man Energy Solut, Holeby, Denmark
关键词
Literature review; Cyber-resilience; Recovery frameworks; Cyber-attack response; RISK-ASSESSMENT FRAMEWORK; DATA INJECTION ATTACKS; PHYSICAL SYSTEMS; REGULATORY FRAMEWORK; SECURITY FRAMEWORK; SWITCHING ATTACKS; PROTECTION; OPTIMIZATION; MITIGATION; MANAGEMENT;
D O I
10.1016/j.cose.2020.101996
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-attacks are regarded as one of the most serious threats to businesses worldwide. Organizations dependent on Information Technology (IT) derive value not only from preventing cyber-attacks, but also from responding promptly and coherently when cyber-attacks happen so as to minimize their disruptive effect on operations. This capacity is known as cyber-resilience. As multiple cyber-resilience frameworks (CRF) have been proposed in literature, an increased clarity about the scope, characteristics, synergies and gaps in existing CRFs will facilitate scientific research advancement in this area. This paper uses a systematic literature review to identify extant research on CRFs. The analysis is based on a sample representing 36 different industries and 25 different research areas. Through the use of descriptive analysis and thematic categorization, this paper makes a contribution by identifying CRFs as either strategic or operational, by the hierarchy of their decision influence, by the attacks addressed, and through the methods used and the places and institutions doing CRF research. As a result, this work presents an overview map of the current CRF research landscape, identifies relevant research gaps, highlights similarities and synergies between CRFs, and proposes opportunities for interdisciplinary research, as a contribution to guide future research in this area. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Cyber-resilience in the EU
    Kaufmann, Mareile
    [J]. INTERNASJONAL POLITIKK, 2013, 71 (02) : 274 - 283
  • [2] Program Synthesis for Cyber-Resilience
    Catano, Nestor
    [J]. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2023, 49 (03) : 962 - 972
  • [3] A Vision for Improving Business Continuity through Cyber-resilience Mechanisms and Frameworks
    Hernandez Bejarano, Miguel
    Rodriguez, Ricardo J.
    Merseguer, Jose
    [J]. PROCEEDINGS OF 2021 16TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI'2021), 2021,
  • [4] Challenges in Maritime Cyber-Resilience
    Jensen, Lars
    [J]. TECHNOLOGY INNOVATION MANAGEMENT REVIEW, 2015, : 35 - 39
  • [5] CYBER-RESILIENCE, RISKS AND RAMIFICATIONS
    Morrison, Gordon
    [J]. JOURNAL OF THE INSTITUTE OF TELECOMMUNICATIONS PROFESSIONALS, 2013, 7 : 18 - 21
  • [6] Cyber-Resilience Evaluation of Cyber-Physical Systems
    Segovia, Mariana
    Rubio-Hernan, Jose
    Cavalli, Ana R.
    Garcia-Alfaro, Joaquin
    [J]. 2020 IEEE 19TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA), 2020,
  • [7] Editorial: Cyber-Resilience in Supply Chains
    McPhee, Chris
    Khan, Omera
    [J]. TECHNOLOGY INNOVATION MANAGEMENT REVIEW, 2015, : 3 - 5
  • [8] Building Cyber-Resilience into Supply Chains
    Davis, Adrian
    [J]. TECHNOLOGY INNOVATION MANAGEMENT REVIEW, 2015, : 19 - 27
  • [9] A Survey on Cyber-Resilience Approaches for Cyber-Physical Systems
    Segovia-Ferreira, Mariana
    Rubio-Hernan, Jose
    Cavalli, Ana Rosa
    Garcia-Alfaro, Joaquin
    [J]. ACM COMPUTING SURVEYS, 2024, 56 (08)
  • [10] The tensions of cyber-resilience: From sensemaking to practice
    Dupont, Benoit
    Shearing, Clifford
    Bernier, Marilyne
    Leukfeldt, Rutger
    [J]. COMPUTERS & SECURITY, 2023, 132