论文标题

支持自动网络风险评估审查的方法

A Methodology to Support Automatic Cyber Risk Assessment Review

论文作者

Angelini, Marco, Bonomi, Silvia, Palma, Alessandro

论文摘要

网络风险评估是增强组织保护,识别和评估网络威胁的基本活动。目前,这项活动主要是手动进行的,并且深其中的风险识别和正确量化取决于人类评估者的经验和信心。结果,该过程不是完全客观的,对同一情况的两个平行评估可能会导致不同的结果。本文通过提出一种支持风险评估者的方法来自动审查生产评估的方法,从而朝着降低主观性程度的方向迈出了一步。我们的方法从使用众所周知的网络安全框架(例如ISO 27001,NIST)进行的基于对照的评估开始,并对可以自动评估的基础结构方面的安全控制(例如,ICT设备,组织策略)进行了映射安全控制。利用此映射,该方法建议如何识别需要修订的控件。通过医疗领域的案例研究和一组统计分析,该方法已得到验证。

Cyber risk assessment is a fundamental activity for enhancing the protection of an organization, identifying and evaluating the exposure to cyber threats. Currently, this activity is carried out mainly manually and the identification and correct quantification of risks deeply depend on the experience and confidence of the human assessor. As a consequence, the process is not completely objective and two parallel assessments of the same situation may lead to different results. This paper takes a step in the direction of reducing the degree of subjectivity by proposing a methodology to support risk assessors with an automatic review of the produced assessment. Our methodology starts from a controls-based assessment performed using well-known cybersecurity frameworks (e.g., ISO 27001, NIST) and maps security controls over infrastructural aspects that can be assessed automatically (e.g., ICT devices, organization policies). Exploiting this mapping, the methodology suggests how to identify controls needing revision. The approach has been validated through a case study from the healthcare domain and a set of statistical analyses.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源