Premium
Towards the Definition of a Dynamic and Systemic Assessment for Cybersecurity Risks
Author(s) -
Armenia Stefano,
Ferreira Franco Eduardo,
ino Fabio,
Spagnoli Emanuele,
Medaglia Carlo M.
Publication year - 2018
Publication title -
systems research and behavioral science
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.371
H-Index - 45
eISSN - 1099-1743
pISSN - 1092-7026
DOI - 10.1002/sres.2556
Subject(s) - cyberspace , damages , computer security , risk analysis (engineering) , process (computing) , business , work (physics) , risk assessment , knowledge management , computer science , political science , engineering , law , the internet , mechanical engineering , world wide web , operating system
Nowadays, our society is increasingly becoming economically and socially dependent on the cyberspace. However, the cyberspace is exposed to numerous risks, and there is a constant threat of exploitable vulnerabilities, which could cause significant reputational and economic damages. For addressing these threats, the Italian National Cyber Security Framework was developed to offer an approach to assessing cyber risks into organizations, as well as to help improve the related security through focused investments. Still, this evaluation is not a straightforward endeavour. Using the principles of the Systems Thinking paradigm, this work puts into causal relationships the self‐assessment risk‐categories by associating them to the various aspects of an organization structure used as a case study (composed of business areas and process). Finally, it presents a systemic causal‐effect relationship map capable of evidencing how a change in one or more categories could impact other security‐related elements of the company. © 2018 John Wiley & Sons, Ltd.