Yet another cybersecurity risk assessment framework

被引:0
|
作者
Mathias Ekstedt
Zeeshan Afzal
Preetam Mukherjee
Simon Hacks
Robert Lagerström
机构
[1] KTH Royal Institute of Technology,
[2] Digital University Kerala,undefined
[3] Stockholm University,undefined
关键词
Threat modeling; Enterprise IT risk; Risk assessment; Attack tree;
D O I
暂无
中图分类号
学科分类号
摘要
IT systems pervade our society more and more, and we become heavily dependent on them. At the same time, these systems are increasingly targeted in cyberattacks, making us vulnerable. Enterprise and cybersecurity responsibles face the problem of defining techniques that raise the level of security. They need to decide which mechanism provides the most efficient defense with limited resources. Basically, the risks need to be assessed to determine the best cost-to-benefit ratio. One way to achieve this is through threat modeling; however, threat modeling is not commonly used in the enterprise IT risk domain. Furthermore, the existing threat modeling methods have shortcomings. This paper introduces a metamodel-based approach named Yet Another Cybersecurity Risk Assessment Framework (Yacraf). Yacraf aims to enable comprehensive risk assessment for organizations with more decision support. The paper includes a risk calculation formalization and also an example showing how an organization can use and benefit from Yacraf.
引用
收藏
页码:1713 / 1729
页数:16
相关论文
共 50 条
  • [21] An assessment framework for explainable AI with applications to cybersecurity
    Calzarossa, Maria Carla
    Giudici, Paolo
    Zieni, Rasha
    ARTIFICIAL INTELLIGENCE REVIEW, 2025, 58 (05)
  • [23] YET ANOTHER FRAMEWORK FOR QUANTUM SIMULTANEOUS NONCOOPERATIVE BIMATRIX GAMES
    Saitoh, Akira
    Rahimi, Robabeh
    Nakahara, Mikio
    MOLECULAR REALIZATIONS OF QUANTUM COMPUTING 2007, 2009, 2 : 223 - +
  • [24] The 'Power Threat Meaning Framework': Yet Another Master Narrative?
    Rashed, Mohammed Abouelleil
    PHILOSOPHY PSYCHIATRY & PSYCHOLOGY, 2023, 30 (01) : 69 - 72
  • [25] JWIG: YET ANOTHER FRAMEWORK FOR MAINTAINABLE AND SECURE WEB APPLICATIONS
    Moller, Anders
    Schwarz, Mathias
    WEBIST 2009: PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, 2009, : 47 - 53
  • [26] THERAPY DYAD - YET ANOTHER LOOK AT DIAGNOSTIC ASSESSMENT
    BEUTLER, LE
    JOURNAL OF PERSONALITY ASSESSMENT, 1973, 37 (04) : 303 - 308
  • [27] Cybersecurity Risk Assessment for Space Systems
    Vessels, Ly
    Heffner, Kenneth
    Johnson, Daniel
    2019 IEEE SPACE COMPUTING CONFERENCE (SCC), 2019, : 11 - 19
  • [28] A Systems Approach for Cybersecurity Risk Assessment
    Meshkat, Leila
    Miller, Robert L.
    2022 68TH ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM (RAMS 2022), 2022,
  • [29] Digital Human in Cybersecurity Risk Assessment
    Jureviciene, Aiste
    Brilingaite, Agne
    Bukauskas, Linas
    AUGMENTED COGNITION, AC 2021, 2021, 12776 : 418 - 432
  • [30] YET ANOTHER
    不详
    EMERGENCY MEDICINE, 1977, 9 (09) : 241 - &