Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management. Issue 1 (5th September 2017)
- Record Type:
- Journal Article
- Title:
- Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management. Issue 1 (5th September 2017)
- Main Title:
- Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management
- Authors:
- Ganin, Alexander A.
Quach, Phuoc
Panwar, Mahesh
Collier, Zachary A.
Keisler, Jeffrey M.
Marchese, Dayton
Linkov, Igor - Abstract:
- Abstract: Risk assessors and managers face many difficult challenges related to novel cyber systems. Among these challenges are the constantly changing nature of cyber systems caused by technical advances, their distribution across the physical, information, and sociocognitive domains, and the complex network structures often including thousands of nodes. Here, we review probabilistic and risk‐based decision‐making techniques applied to cyber systems and conclude that existing approaches typically do not address all components of the risk assessment triplet (threat, vulnerability, consequence) and lack the ability to integrate across multiple domains of cyber systems to provide guidance for enhancing cybersecurity. We present a decision‐analysis‐based approach that quantifies threat, vulnerability, and consequences through a set of criteria designed to assess the overall utility of cybersecurity management alternatives. The proposed framework bridges the gap between risk assessment and risk management, allowing an analyst to ensure a structured and transparent process of selecting risk management alternatives. The use of this technique is illustrated for a hypothetical, but realistic, case study exemplifying the process of evaluating and ranking five cybersecurity enhancement strategies. The approach presented does not necessarily eliminate biases and subjectivity necessary for selecting countermeasures, but provides justifiable methods for selecting risk management actionsAbstract: Risk assessors and managers face many difficult challenges related to novel cyber systems. Among these challenges are the constantly changing nature of cyber systems caused by technical advances, their distribution across the physical, information, and sociocognitive domains, and the complex network structures often including thousands of nodes. Here, we review probabilistic and risk‐based decision‐making techniques applied to cyber systems and conclude that existing approaches typically do not address all components of the risk assessment triplet (threat, vulnerability, consequence) and lack the ability to integrate across multiple domains of cyber systems to provide guidance for enhancing cybersecurity. We present a decision‐analysis‐based approach that quantifies threat, vulnerability, and consequences through a set of criteria designed to assess the overall utility of cybersecurity management alternatives. The proposed framework bridges the gap between risk assessment and risk management, allowing an analyst to ensure a structured and transparent process of selecting risk management alternatives. The use of this technique is illustrated for a hypothetical, but realistic, case study exemplifying the process of evaluating and ranking five cybersecurity enhancement strategies. The approach presented does not necessarily eliminate biases and subjectivity necessary for selecting countermeasures, but provides justifiable methods for selecting risk management actions consistent with stakeholder and decisionmaker values and technical data. … (more)
- Is Part Of:
- Risk analysis. Volume 40:Issue 1(2020)
- Journal:
- Risk analysis
- Issue:
- Volume 40:Issue 1(2020)
- Issue Display:
- Volume 40, Issue 1 (2020)
- Year:
- 2020
- Volume:
- 40
- Issue:
- 1
- Issue Sort Value:
- 2020-0040-0001-0000
- Page Start:
- 183
- Page End:
- 199
- Publication Date:
- 2017-09-05
- Subjects:
- Cybersecurity -- MCDA -- risk management -- vulnerability assessment
Technology -- Risk assessment -- Periodicals
658.403 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1111/(ISSN)1539-6924 ↗
http://www.blackwellpublishers.co.uk/Online ↗
http://www.blackwellpublishing.com/journal.asp?ref=0272-4332 ↗
http://www.ingenta.com/journals/browse/bpl/risk ↗
http://www.wkap.nl/jrnltoc.htm/0272-4332 ↗
http://onlinelibrary.wiley.com/ ↗
http://firstsearch.oclc.org ↗
http://firstsearch.oclc.org/journal=0272-4332;screen=info;ECOIP ↗ - DOI:
- 10.1111/risa.12891 ↗
- Languages:
- English
- ISSNs:
- 0272-4332
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 7972.583000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 12562.xml