首页> 外文期刊>Decision support systems >A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs
【24h】

A dynamic simulation approach to support the evaluation of cyber risks and security investments in SMEs

机译:一种支持中小企业网络风险评估和安全投资的动态仿真方法

获取原文
获取原文并翻译 | 示例
       

摘要

The growing amount of cyberspace threats highlights the need to evaluate cybersecurity risks and to plan for effective investments. One internationally recognized document for cybersecurity risk management is the framework for Improving Critical Infrastructure Cybersecurity by the US National Institute of Standards and Technology (NIST). It provides guidelines, best practices and standards for cybersecurity risk management. Nevertheless, as other self-assessment frameworks, it produces a static view of an organization's cyber posture and does not capture the dynamics of organizational changes and cyberattacks. Moreover, the current situation sees small and medium enterprises (SMEs) in a critical position since they need to manage their cybersecurity while usually not being skilled or equipped enough to internalize this process. Therefore, there is a need for a practical and easily applicable model able to identify a cybersecurity risk profile and its dynamics. This study proposes a system dynamics methodology and tool (SMECRA - SME Cyber Risk Assessment) for supporting cybersecurity investment decisions for SMEs through the evaluation of cyber risk and previous investments. SMECRA addresses dynamic organizational complexity and can be used to assess cyber risks and related dynamics over time. Three case studies demonstrate its capability to assess a SME's cybersecurity status and to evaluate investments impacts on an organization's risk profile, raising cybersecurity awareness. This study is important for SMEs wishing to manage their own cybersecurity risk and for insurance companies in their economic evaluation of residual risks that SMEs wish to externalize.
机译:越来越多的网络空间威胁突出了评估网络安全风险并计划有效投资的必要性。一个国际公认的网络安全风险管理文件是美国国家标准与技术研究所(NIST)改善关键基础设施网络安全的框架。它为网络安全风险管理提供了指南,最佳实践和标准。然而,作为其他自我评估框架,它产生了组织的网络姿势的静态视图,并不会捕获组织变化和网络攻击的动态。此外,目前的情况将中小型企业(中小企业)视为危重地位,因为他们需要管理他们的网络安全,而通常不熟练或足够才能将此过程内化。因此,需要一种实用且易于适用的模型,能够识别网络安全风险概况及其动态。本研究提出了一种系统动态方法和工具(SMECRA - 中小企业网络风险评估),通过评估网络风险和以前的投资来支持中小企业的网络安全投资决策。 SMECRA解决了动态的组织复杂性,可用于随着时间的推移评估网络风险和相关动态。三个案例研究表明其能够评估中小企业的网络安全地位,并评估投资对组织风险概况的影响,提高网络安全意识。本研究对于希望管理自己的网络安全风险和保险公司的中小企业对中小企业希望外容的剩余风险的经济评估,这项研究很重要。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号