首页> 外文会议>International Conference on Enterprise Information Systems >Towards Automated Modelling of Large-scale Cybersecurity Transformations: Potential Model and Methodology
【24h】

Towards Automated Modelling of Large-scale Cybersecurity Transformations: Potential Model and Methodology

机译:迈为大规模网络安全变换的自动建模:潜在模型和方法

获取原文

摘要

The purpose of this paper is to propose a proprietary methodology and model to generate a "cybersecurity transformation workplan" for large organizations that can improve their cybersecurity posture. The key input is based on risk-based assessment or maturity-based questionnaires depending on existing governance processes and available information. The original scoring can be then used to prioritize a portfolio of all possible initiatives by selecting the ones that are missing from typical foundation elements or would have high potential impact in relation to required investment and effort. Additional constraints such as budget limitation and FTE availability, logical sequencing and time requirements could be added to ensure effective use of company resources and actionability of the recommendations. The Gantt-like output would ease the burden on the security teams by providing an individualized set of activities to be implemented to improve risk posture.
机译:本文的目的是提出专有的方法和模型,为可以提高他们的网络安全姿势的大型组织生成“网络安全转换工作计划”。关键输入基于基于风险的评估或基于成熟的问卷,具体取决于现有的治理程序和可用信息。然后可以使用原始评分来优先考虑所有可能举措的投资组合,通过选择典型的基础元素中缺少的那些,或者与所需的投资和努力有很大的潜在影响。可以添加额外的约束,例如预算限制和FTE可用性,逻辑排序和时间要求,以确保有效地利用公司资源和建议的可行性。甘特特的产出将通过提供待实施的个性化活动来缓解安全团队的负担,以提高风险姿势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号