Author:
Calvo Miguel,Beltrán Marta
Abstract
Purpose
This paper aims to propose a new method to derive custom dynamic cyber risk metrics based on the well-known Goal, Question, Metric (GQM) approach. A framework that complements it and makes it much easier to use has been proposed too. Both, the method and the framework, have been validated within two challenging application domains: continuous risk assessment within a smart farm and risk-based adaptive security to reconfigure a Web application firewall.
Design/methodology/approach
The authors have identified a problem and provided motivation. They have developed their theory and engineered a new method and a framework to complement it. They have demonstrated the proposed method and framework work, validating them in two real use cases.
Findings
The GQM method, often applied within the software quality field, is a good basis for proposing a method to define new tailored cyber risk metrics that meet the requirements of current application domains. A comprehensive framework that formalises possible goals and questions translated to potential measurements can greatly facilitate the use of this method.
Originality/value
The proposed method enables the application of the GQM approach to cyber risk measurement. The proposed framework allows new cyber risk metrics to be inferred by choosing between suggested goals and questions and measuring the relevant elements of probability and impact. The authors’ approach demonstrates to be generic and flexible enough to allow very different organisations with heterogeneous requirements to derive tailored metrics useful for their particular risk management processes.
Subject
Management of Technology and Innovation,Information Systems and Management,Computer Networks and Communications,Information Systems,Software,Management Information Systems
Reference64 articles.
1. Cyber-risks in the industrial internet of things (IIoT): towards a method for continuous assessment,2018
2. Alberts, C., Behrens, S., Pethia, R. and Wilson, W. (1999), “Operationally critical threat, asset, and vulnerability evaluation (OCTAVE) framework, version 1.0”, available at: http://resources.sei.cmu.edu/library/asset-view.cfm?AssetID=13473
3. Security events and vulnerability data for cybersecurity risk estimation;Risk Analysis,2017
4. Assessing cyber risk in cyber-physical systems using the ATT&CK framework;ACM Transactions on Privacy and Security,2023
5. Anne, A.K. (2014), “Predictive key risk indicator identification process using quantitative methods”, available at: https://patents.google.com/patent/US20140019194A1/en US Patent App. 13/547,853.