Related Experiment Videos
Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management
Alexander A Ganin1, Phuoc Quach2, Mahesh Panwar2
1University of Virginia, Department of Systems and Information Engineering, Charlottesville, VA, USA.
Risk Analysis : an Official Publication of the Society for Risk Analysis
|September 6, 2017
Summary
Cyber risk assessment faces challenges with evolving systems. A new decision-analysis approach quantifies threat, vulnerability, and consequences for better cybersecurity management.
Area of Science:
- Cybersecurity
- Risk Management
- Decision Analysis
Background:
- Novel cyber systems present complex challenges for risk assessment and management due to their dynamic nature, multi-domain distribution (physical, information, sociocognitive), and intricate network structures.
- Existing risk-based decision-making techniques often fail to address the complete risk assessment triplet (threat, vulnerability, consequence) and struggle to integrate across different domains for effective cybersecurity guidance.
Purpose of the Study:
- To present a novel decision-analysis-based framework for quantifying threat, vulnerability, and consequences in cyber systems.
- To bridge the gap between risk assessment and risk management by providing a structured and transparent process for selecting cybersecurity management alternatives.
Main Methods:
- Review of existing probabilistic and risk-based decision-making techniques for cyber systems.
- Development and application of a decision-analysis approach to quantify threat, vulnerability, and consequences using a defined set of criteria.
- Evaluation of the framework using a hypothetical case study to rank cybersecurity enhancement strategies.
Main Results:
- The proposed framework quantifies threat, vulnerability, and consequences, enabling a structured assessment of cybersecurity management alternatives.
- The approach facilitates a transparent process for selecting risk management actions, integrating stakeholder values and technical data.
- A case study demonstrated the framework's utility in evaluating and ranking five distinct cybersecurity enhancement strategies.
Conclusions:
- The presented decision-analysis framework offers a justifiable method for selecting risk management actions in complex cyber systems.
- This approach enhances cybersecurity by providing a structured way to evaluate and choose among different management alternatives.
- While acknowledging the inherent subjectivity in countermeasure selection, the framework promotes justifiable and value-aligned decision-making.