An Adversarial Risk Analysis Framework for Cybersecurity

03/18/2019
by   David Ríos Insua, et al.
0

Cyber threats affect all kinds of organisations. Risk analysis is an essential methodology for cybersecurity as it allows organisations to deal with the cyber threats potentially affecting them, prioritise the defence of their assets and decide what security controls should be implemented. Many risk analysis methods are present in cybersecurity models, compliance frameworks and international standards. However, most of them employ risk matrices, which suffer shortcomings that may lead to suboptimal resource allocations. We propose a comprehensive framework for cybersecurity risk analysis, covering the presence of both adversarial and non-intentional threats and the use of insurance as part of the security portfolio. A case study illustrating the proposed framework is presented, serving as template for more complex cases.

READ FULL TEXT
research
12/21/2022

A Comparative Risk Analysis on CyberShip System with STPA-Sec, STRIDE and CORAS

The widespread use of software-intensive cyber systems in critical infra...
research
07/07/2022

A Methodology to Support Automatic Cyber Risk Assessment Review

Cyber risk assessment is a fundamental activity for enhancing the protec...
research
08/22/2021

Framework for Managing Cybercrime Risks in Nigerian Universities

Universities in developing countries, including those in Nigeria, experi...
research
03/04/2020

Vessels Cybersecurity: Issues, Challenges, and the Road Ahead

Vessels cybersecurity is recently gaining momentum, as a result of a few...
research
07/05/2023

Security Risk Analysis Methodologies for Automotive Systems

Nowadays, systematic security risk analysis plays a vital role in the au...
research
03/05/2019

Risk Assessment of Autonomous Vehicles Using Bayesian Defense Graphs

Recent developments have made autonomous vehicles (AVs) closer to hittin...
research
07/20/2023

ESASCF: Expertise Extraction, Generalization and Reply Framework for an Optimized Automation of Network Security Compliance

The Cyber threats exposure has created worldwide pressure on organizatio...

Please sign up or login with your details

Forgot password? Click here to reset