首页> 外文期刊>Business Horizons. >Calculated risk? A cybersecurity evaluation tool for SMEs
【24h】

Calculated risk? A cybersecurity evaluation tool for SMEs

机译:计算风险?中小企业的网络安全评估工具

获取原文
获取原文并翻译 | 示例
       

摘要

Small and medium-sized enterprises (SMEs) are among the least mature and most vulnerable in terms of their cybersecurity risk and resilience. In this article, we describe a methodology developed using the National Institute of Standards and Technology's (NIST) Cybersecurity Framework (CSF) as a starting point. The NIST CSF does not meet all the needs of the SME IT leader, but it offers a solid foundation for a useful evaluation and recommendation methodology. We propose an SME cybersecurity evaluation tool (CET) that consists of a 35-question online survey to be completed by IT leaders to self-rate their maturity within the five NIST framework categories: identify, protect, detect, respond, and recover. We outline this approach to cybersecurity risk management before discussing its effectiveness and implications for practitioners. (C) 2020 Kelley School of Business, Indiana University. Published by Elsevier Inc. All rights reserved.
机译:中小型企业(中小企业)在其网络安全风险和恢复力方面是最不重要的,最脆弱的。在本文中,我们描述了使用国家标准和技术(NIST)网络安全框架(CSF)作为起点的方法。 NIST CSF不符合中小企业IT领导者的所有需求,但它为有用的评估和推荐方法提供了坚实的基础。我们提出了一个中小企业网络安全评估工具(CET),由IT领导人完成35题的在线调查,以在五个NIST框架类别中自筹资费:识别,保护,检测,响应和恢复。在讨论其对从业者的有效性和影响之前,我们概述了这种对网络安全风险管理的方法。 (c)印第安纳大学凯利商学院。由elsevier Inc.出版的所有权利保留。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号