首页> 外文会议>European Conference on Cyber Warfare and Security >A Framework for Managing Cybersecurity Effectiveness in the Digital Context
【24h】

A Framework for Managing Cybersecurity Effectiveness in the Digital Context

机译:管理数字背景下的网络安全效果的框架

获取原文

摘要

The pace of digital transformation and new technology development and the growing sophistication of cyber criminals result in organisations facing greater scope and severity of cybersecurity attacks on a daily basis - estimated to cost between $375 and $575 billion per annum. It is anticipated that as more devices, systems, and infrastructure become interconnected and interdependent, and as more interfaces between customers, suppliers, and partners are leveraged, the IT 'attack surface' will continue to expand. Organisations vary in their approaches to attempting to prevent cybersecurity breaches: some are overly restrictive, making even routine business activities difficult, while others are too relaxed with poor oversight and inadequate protocols and procedures, creating unnecessary exposures. However, applying appropriate cybersecurity controls is now a particular necessity where digital leaders often have a higher tolerance and appetite for risk-taking and experimentation to identify key opportunities for the future. Organisations now need to rethink their cybersecurity management approaches, and recognise that traditional access control and perimeter defences alone are no longer sufficient. Rather holistic and proactive approaches that continually evolve and adapt to counter emerging threats and minimise the potential negative consequences of exposure are required. Understanding how effective the organisation is in its cybersecurity efforts is a prerequisite for ensuring controls remain abreast with, and appropriate for, the changing IT threat landscape. This paper presents a cybersecurity conceptual framework that can be used by organisations to provide a holistic analysis of their cybersecurity approaches. It details the key factors or management themes underpinning cybersecurity effectiveness and how the insights gained through assessing performance against these factors or management themes can be practically used to improve cybersecurity effectiveness.
机译:数字化改造和新技术的发展和网络犯罪的日益复杂的步伐导致面临着更大的范围和每天都在网络安全攻击的严重性组织 - 估计为$ 375和$ 575十亿每年之间的成本。据预计,随着越来越多的设备,系统和基础设施成为相互联系和相互依赖,并为客户,供应商和合作伙伴之间的多个接口杠杆,在它的攻击面“将继续扩大。组织在他们的方法有所不同试图阻止网络安全漏洞:有些过于严格,使得即使日常业务活动困难,而有些则是用得监督不力和不充分的方案和程序放宽,造成不必要的风险。然而,应用适当的网络安全控制现在是一个特别的必要性,其中数字领袖往往有冒险精神和实验,以确定未来的关键机会,更高的耐受性和食欲。现在,企业需要重新思考他们的网络安全管理方法,并认识到,传统的访问控制和边界防御独自不再足够。 ,不断发展并适应反新出现的威胁,并尽量减少暴露的潜在的负面影响,而全面和主动的方法是必需的。了解组织如何有效地在其网络安全工作是确保控制仍然并驾齐驱,和适当的,不断变化的IT威胁环境的先决条件。本文提出了可以通过组织使用的网络安全的方法,以提供一个全面的分析网络安全的概念框架。它详细介绍了托换网络安全有效性的关键因素或管理主题,以及如何通过评估针对这些因素或管理主题的表现获得的认识实际上可以用于提高网络安全有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号