Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management

被引:85
|
作者
Ganin, Alexander A. [1 ]
Quach, Phuoc [2 ]
Panwar, Mahesh [2 ]
Collier, Zachary A. [1 ]
Keisler, Jeffrey M. [3 ]
Marchese, Dayton [1 ]
Linkov, Igor [4 ]
机构
[1] Univ Virginia, Dept Syst & Informat Engn, Charlottesville, VA USA
[2] US Army, Engn Res & Dev Ctr, Concord, MA USA
[3] Univ Massachusetts, Coll Management, Boston, MA 02125 USA
[4] US Army, Engn Res & Dev Ctr, Environm Lab, Concord, MA USA
关键词
Cybersecurity; MCDA; risk management; vulnerability assessment; SECURITY ASSESSMENT; METRICS; TRENDS;
D O I
10.1111/risa.12891
中图分类号
R1 [预防医学、卫生学];
学科分类号
1004 ; 120402 ;
摘要
Risk assessors and managers face many difficult challenges related to novel cyber systems. Among these challenges are the constantly changing nature of cyber systems caused by technical advances, their distribution across the physical, information, and sociocognitive domains, and the complex network structures often including thousands of nodes. Here, we review probabilistic and risk-based decision-making techniques applied to cyber systems and conclude that existing approaches typically do not address all components of the risk assessment triplet (threat, vulnerability, consequence) and lack the ability to integrate across multiple domains of cyber systems to provide guidance for enhancing cybersecurity. We present a decision-analysis-based approach that quantifies threat, vulnerability, and consequences through a set of criteria designed to assess the overall utility of cybersecurity management alternatives. The proposed framework bridges the gap between risk assessment and risk management, allowing an analyst to ensure a structured and transparent process of selecting risk management alternatives. The use of this technique is illustrated for a hypothetical, but realistic, case study exemplifying the process of evaluating and ranking five cybersecurity enhancement strategies. The approach presented does not necessarily eliminate biases and subjectivity necessary for selecting countermeasures, but provides justifiable methods for selecting risk management actions consistent with stakeholder and decisionmaker values and technical data.
引用
收藏
页码:183 / 199
页数:17
相关论文
共 50 条
  • [1] PRISM: a strategic decision framework for cybersecurity risk assessment
    Goel, Rajni
    Kumar, Anupam
    Haddow, James
    INFORMATION AND COMPUTER SECURITY, 2020, 28 (04) : 591 - 625
  • [2] A Multicriteria Decision Analysis Model and Risk Assessment Framework for Carbon Capture and Storage
    Choptiany, John Michael Humphries
    Pelot, Ronald
    RISK ANALYSIS, 2014, 34 (09) : 1720 - 1737
  • [3] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Wang, Yunpeng
    Wang, Yinghui
    Qin, Hongmao
    Ji, Haojie
    Zhang, Yanan
    Wang, Jian
    AUTOMOTIVE INNOVATION, 2021, 4 (03) : 253 - 261
  • [4] A simulation framework for automotive cybersecurity risk assessment
    Jayaratne, Don Nalin Dharshana
    Kamtam, Suraj Harsha
    Shaikh, Siraj Ahmed
    Ramli, Muhamad Azfar
    Lu, Qian
    Mepparambath, Rakhi Manohar
    Nguyen, Hoang Nga
    Rakib, Abdur
    SIMULATION MODELLING PRACTICE AND THEORY, 2024, 136
  • [5] A Systematic Risk Assessment Framework of Automotive Cybersecurity
    Yunpeng Wang
    Yinghui Wang
    Hongmao Qin
    Haojie Ji
    Yanan Zhang
    Jian Wang
    Automotive Innovation, 2021, 4 : 253 - 261
  • [6] Yet another cybersecurity risk assessment framework
    Ekstedt, Mathias
    Afzal, Zeeshan
    Mukherjee, Preetam
    Hacks, Simon
    Lagerstrom, Robert
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2023, 22 (06) : 1713 - 1729
  • [7] Yet another cybersecurity risk assessment framework
    Mathias Ekstedt
    Zeeshan Afzal
    Preetam Mukherjee
    Simon Hacks
    Robert Lagerström
    International Journal of Information Security, 2023, 22 : 1713 - 1729
  • [8] A Multicriteria Decision Framework for the Management of Maintenance Spares - A Case Study
    Ferreira, Luis Miguel D. F.
    Maganha, Isabela
    Magalhaes, Vanessa S. M.
    Almeida, Mauro
    IFAC PAPERSONLINE, 2018, 51 (11): : 531 - 537
  • [9] Assets focus risk management framework for critical infrastructure cybersecurity risk management
    Kure, Halima Ibrahim
    Islam, Shareeful
    IET CYBER-PHYSICAL SYSTEMS: THEORY & APPLICATIONS, 2019, 4 (04) : 332 - 340
  • [10] Cybersecurity: Risk management framework and investment cost analysis
    Lee, In
    BUSINESS HORIZONS, 2021, 64 (05) : 659 - 671