A Methodology to Support Automatic Cyber Risk Assessment Review

07/07/2022
by   Marco Angelini, et al.
0

Cyber risk assessment is a fundamental activity for enhancing the protection of an organization, identifying and evaluating the exposure to cyber threats. Currently, this activity is carried out mainly manually and the identification and correct quantification of risks deeply depend on the experience and confidence of the human assessor. As a consequence, the process is not completely objective and two parallel assessments of the same situation may lead to different results. This paper takes a step in the direction of reducing the degree of subjectivity by proposing a methodology to support risk assessors with an automatic review of the produced assessment. Our methodology starts from a controls-based assessment performed using well-known cybersecurity frameworks (e.g., ISO 27001, NIST) and maps security controls over infrastructural aspects that can be assessed automatically (e.g., ICT devices, organization policies). Exploiting this mapping, the methodology suggests how to identify controls needing revision. The approach has been validated through a case study from the healthcare domain and a set of statistical analyses.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/18/2019

An Adversarial Risk Analysis Framework for Cybersecurity

Cyber threats affect all kinds of organisations. Risk analysis is an ess...
research
12/21/2022

A Comparative Risk Analysis on CyberShip System with STPA-Sec, STRIDE and CORAS

The widespread use of software-intensive cyber systems in critical infra...
research
12/16/2017

Uncertainty in Cyber Security Investments

When undertaking cyber security risk assessments, we must assign numeric...
research
02/17/2020

A New Methodology for Information Security Risk Assessment for Medical Devices and Its Evaluation

As technology advances towards more connected and digital environments, ...
research
06/19/2021

Cyber Security in Cloud: Risk Assessment Models

The present paper shows a proposal of the characteristics Cloud Risk Ass...
research
02/04/2020

TRAP: A Predictive Framework for Trail Running Assessment of Performance

Trail running is an endurance sport in which athletes face severe physic...

Please sign up or login with your details

Forgot password? Click here to reset