首页> 外文期刊>Risk analysis >Cyber Risk Management for Critical Infrastructure: A Risk Analysis Model and Three Case Studies
【24h】

Cyber Risk Management for Critical Infrastructure: A Risk Analysis Model and Three Case Studies

机译:关键基础设施的网络风险管理:风险分析模型和三个案例研究

获取原文
获取原文并翻译 | 示例

摘要

Managing cyber security in an organization involves allocating the protection budget across a spectrum of possible options. This requires assessing the benefits and the costs of these options. The risk analyses presented here are statistical when relevant data are available, and system-based for high-consequence events that have not happened yet. This article presents, first, a general probabilistic risk analysis framework for cyber security in an organization to be specified. It then describes three examples of forward-looking analyses motivated by recent cyber attacks. The first one is the statistical analysis of an actual database, extended at the upper end of the loss distribution by a Bayesian analysis of possible, high-consequence attack scenarios that may happen in the future. The second is a systems analysis of cyber risks for a smart, connected electric grid, showing that there is an optimal level of connectivity. The third is an analysis of sequential decisions to upgrade the software of an existing cyber security system or to adopt a new one to stay ahead of adversaries trying to find their way in. The results are distributions of losses to cyber attacks, with and without some considered counter-measures in support of risk management decisions based both on past data and anticipated incidents.
机译:管理组织中的网络安全涉及在各种可能的方案中分配保护预算。这需要评估这些选择的收益和成本。当相关数据可用时,此处介绍的风险分析是统计的,并且针对尚未发生的高后果事件是基于系统的。本文首先介绍了要指定的组织中用于网络安全的一般概率风险分析框架。然后,它描述了由最近的网络攻击引起的前瞻性分析的三个示例。第一个是对实际数据库的统计分析,它通过对将来可能发生的可能发生的高后果攻击场景的贝叶斯分析,在损失分布的上限进行扩展。第二个是对智能互联电网的网络风险进行的系统分析,表明存在最佳连接水平。第三部分是对升级现有网络安全系统软件或采用新系统以领先于试图找到竞争对手的对手的顺序决策的分析。结果是在遭受或不遭受某些攻击的情况下,网络攻击的损失分布考虑了基于过去的数据和预期的事件支持风险管理决策的对策。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号