How Do Organizations Seek Cyber Assurance? Investigations on the Adoption of the Common Criteria and Beyond

03/03/2022
by   Nan Sun, et al.
0

Cyber assurance, which is the ability to operate under the onslaught of cyber attacks and other unexpected events, is essential for organizations facing inundating security threats on a daily basis. Organizations usually employ multiple strategies to conduct risk management to achieve cyber assurance. Utilizing cybersecurity standards and certifications can provide guidance for vendors to design and manufacture secure Information and Communication Technology (ICT) products as well as provide a level of assurance of the security functionality of the products for consumers. Hence, employing security standards and certifications is an effective strategy for risk management and cyber assurance. In this work, we begin with investigating the adoption of cybersecurity standards and certifications by surveying 258 participants from organizations across various countries and sectors. Specifically, we identify adoption barriers of the Common Criteria through the designed questionnaire. Taking into account the seven identified adoption barriers, we show the recommendations for promoting cybersecurity standards and certifications. Moreover, beyond cybersecurity standards and certifications, we shed light on other risk management strategies devised by our participants, which provides directions on cybersecurity approaches for enhancing cyber assurance in organizations.

READ FULL TEXT
research
01/19/2022

Defining Security Requirements with the Common Criteria: Applications, Adoptions, and Challenges

Advances of emerging Information and Communications Technology (ICT) tec...
research
05/24/2019

The Concept of Cyber Defence Exercises (CDX): Planning, Execution, Evaluation

This paper discusses the concept of cyber defence exercises -CDX- that a...
research
10/23/2019

A Strategic Cyber Crime and Security Awareness Information System using a Dedicated Portal

A real time portal (www.ganamoscybersecure.org) to enlighten people on h...
research
04/28/2023

A Systematization of Cybersecurity Regulations, Standards and Guidelines for the Healthcare Sector

The growing adoption of IT solutions in the healthcare sector is leading...
research
01/11/2020

Optimizing Investments in Cyber Hygiene for Protecting Healthcare Users

Cyber hygiene measures are often recommended for strengthening an organi...
research
06/09/2020

Sustainability of ICT hardware procurement in Switzerland – A status-quo analysis of the public procurement sector

Sustainable procurement requires organizations to align their purchasing...
research
07/17/2018

An Adaptable Maturity Strategy for Information Security

The lack of security in information systems has caused numerous financia...

Please sign up or login with your details

Forgot password? Click here to reset