Assets focus risk management framework for critical infrastructure cybersecurity risk management

被引:12
|
作者
Kure, Halima Ibrahim [1 ]
Islam, Shareeful [1 ]
机构
[1] Univ East London, Sch Architecture Comp & Engn, London E162RD, England
关键词
business continuity; critical infrastructures; security of data; risk management; critical infrastructure cybersecurity risk management; CI; asset focus risk management approach; critical assets; threats; critical infrastructure; power grid system;
D O I
10.1049/iet-cps.2018.5079
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Critical infrastructure (CI) is vital for the overall economic growth and its reliable and safe operation is essential for a nation's stability and people's safety. Proper operation of the assets is essential for such a system and any threats that could negatively impact the asset could have a severe disruption. Risk management is an important aspect of the protection of CI. There are several frameworks and methodologies for identifying assets, quantifying and analysing vulnerabilities. However, there is a lack of focus on the interdependencies among the assets and cascading effect of the inherent vulnerabilities on the asset. This study attempts to bridge that gap by presenting a novel asset focus risk management approach for the CI. It presents a systematic methodology for identifying and analysing critical assets, their potential vulnerabilities, threats and risks facing CI. This work taking into account cascading vulnerability impacts on assets leading to threats and causing risk. The authors use a running example from a smart grid system to demonstrate the usability of the approach. The result shows that some assets are prioritised and more vulnerable than other assets for the power grid system and it can severely impact on the overall business continuity.
引用
收藏
页码:332 / 340
页数:9
相关论文
共 50 条
  • [1] Cyber Threat Intelligence for Improving Cybersecurity and Risk Management in Critical Infrastructure
    Kure, Halima Ibrahim
    Islam, Shareeful
    [J]. JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2019, 25 (11) : 1478 - 1502
  • [2] Critical Infrastructure - from Risk Management towards the Protection Management Framework
    Bialas, Andrzej
    [J]. PROCEEDINGS OF THE 11TH SCIENTIFIC CONFERENCE INTERNET IN THE INFORMATION SOCIETY 2016, 2016, : 267 - 283
  • [3] An integrated cyber security risk management framework and risk predication for the critical infrastructure protection
    Halima Ibrahim Kure
    Shareeful Islam
    Haralambos Mouratidis
    [J]. Neural Computing and Applications, 2022, 34 : 15241 - 15271
  • [4] An integrated cyber security risk management framework and risk predication for the critical infrastructure protection
    Kure, Halima Ibrahim
    Islam, Shareeful
    Mouratidis, Haralambos
    [J]. NEURAL COMPUTING & APPLICATIONS, 2022, 34 (18): : 15241 - 15271
  • [5] From Risk Management to Resilience Management in Critical Infrastructure
    Rod, Bjarte
    Lange, David
    Theocharidou, Marianthi
    Pursiainen, Christer
    [J]. JOURNAL OF MANAGEMENT IN ENGINEERING, 2020, 36 (04)
  • [6] Cybersecurity Risk Management
    Katsumata, Peter
    Hemenway, Judy
    Gavins, Wes
    [J]. MILITARY COMMUNICATIONS CONFERENCE, 2010 (MILCOM 2010), 2010, : 890 - 895
  • [7] Investors' perceptions of the cybersecurity risk management reporting framework
    Yang, Ling
    Lau, Linda
    Gan, Huiqi
    [J]. INTERNATIONAL JOURNAL OF ACCOUNTING AND INFORMATION MANAGEMENT, 2020, 28 (01) : 167 - 183
  • [8] Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management
    Ganin, Alexander A.
    Quach, Phuoc
    Panwar, Mahesh
    Collier, Zachary A.
    Keisler, Jeffrey M.
    Marchese, Dayton
    Linkov, Igor
    [J]. RISK ANALYSIS, 2020, 40 (01) : 183 - 199
  • [9] Cybersecurity: Risk management framework and investment cost analysis
    Lee, In
    [J]. BUSINESS HORIZONS, 2021, 64 (05) : 659 - 671
  • [10] A Review of Cybersecurity Risk and Consequences for Critical Infrastructure
    Touhiduzzaman, Md
    Gourisetti, Sri Nikhil Gupta
    Eppinger, Crystal
    Somani, Abhishek
    [J]. 2019 RESILIENCE WEEK (RWS), 2019, : 7 - 13