Applying the Goal, Question, Metric method to derive tailored dynamic cyber risk metrics

Author:

Calvo Miguel,Beltrán Marta

Abstract

Purpose This paper aims to propose a new method to derive custom dynamic cyber risk metrics based on the well-known Goal, Question, Metric (GQM) approach. A framework that complements it and makes it much easier to use has been proposed too. Both, the method and the framework, have been validated within two challenging application domains: continuous risk assessment within a smart farm and risk-based adaptive security to reconfigure a Web application firewall. Design/methodology/approach The authors have identified a problem and provided motivation. They have developed their theory and engineered a new method and a framework to complement it. They have demonstrated the proposed method and framework work, validating them in two real use cases. Findings The GQM method, often applied within the software quality field, is a good basis for proposing a method to define new tailored cyber risk metrics that meet the requirements of current application domains. A comprehensive framework that formalises possible goals and questions translated to potential measurements can greatly facilitate the use of this method. Originality/value The proposed method enables the application of the GQM approach to cyber risk measurement. The proposed framework allows new cyber risk metrics to be inferred by choosing between suggested goals and questions and measuring the relevant elements of probability and impact. The authors’ approach demonstrates to be generic and flexible enough to allow very different organisations with heterogeneous requirements to derive tailored metrics useful for their particular risk management processes.

Publisher

Emerald

Subject

Management of Technology and Innovation,Information Systems and Management,Computer Networks and Communications,Information Systems,Software,Management Information Systems

Reference64 articles.

1. Cyber-risks in the industrial internet of things (IIoT): towards a method for continuous assessment,2018

2. Alberts, C., Behrens, S., Pethia, R. and Wilson, W. (1999), “Operationally critical threat, asset, and vulnerability evaluation (OCTAVE) framework, version 1.0”, available at: http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=13473

3. Security events and vulnerability data for cybersecurity risk estimation;Risk Analysis,2017

4. Assessing cyber risk in cyber-physical systems using the ATT&CK framework;ACM Transactions on Privacy and Security,2023

5. Anne, A.K. (2014), “Predictive key risk indicator identification process using quantitative methods”, available at: https://patents.google.com/patent/US20140019194A1/en US Patent App. 13/547,853.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3