Automated Cyber and Privacy Risk Management Toolkit

Author:

Gonzalez-Granadillo GustavoORCID,Menesidou Sofia AnnaORCID,Papamartzivanos DimitriosORCID,Romeu Ramon,Navarro-Llobet DianaORCID,Okoh Caxton,Nifakos Sokratis,Xenakis ChristosORCID,Panaousis EmmanouilORCID

Abstract

Addressing cyber and privacy risks has never been more critical for organisations. While a number of risk assessment methodologies and software tools are available, it is most often the case that one must, at least, integrate them into a holistic approach that combines several appropriate risk sources as input to risk mitigation tools. In addition, cyber risk assessment primarily investigates cyber risks as the consequence of vulnerabilities and threats that threaten assets of the investigated infrastructure. In fact, cyber risk assessment is decoupled from privacy impact assessment, which aims to detect privacy-specific threats and assess the degree of compliance with data protection legislation. Furthermore, a Privacy Impact Assessment (PIA) is conducted in a proactive manner during the design phase of a system, combining processing activities and their inter-dependencies with assets, vulnerabilities, real-time threats and Personally Identifiable Information (PII) that may occur during the dynamic life-cycle of systems. In this paper, we propose a cyber and privacy risk management toolkit, called AMBIENT (Automated Cyber and Privacy Risk Management Toolkit) that addresses the above challenges by implementing and integrating three distinct software tools. AMBIENT not only assesses cyber and privacy risks in a thorough and automated manner but it also offers decision-support capabilities, to recommend optimal safeguards using the well-known repository of the Center for Internet Security (CIS) Controls. To the best of our knowledge, AMBIENT is the first toolkit in the academic literature that brings together the aforementioned capabilities. To demonstrate its use, we have created a case scenario based on information about cyber attacks we have received from a healthcare organisation, as a reference sector that faces critical cyber and privacy threats.

Funder

Seventh Framework Programme

Publisher

MDPI AG

Subject

Electrical and Electronic Engineering,Biochemistry,Instrumentation,Atomic and Molecular Physics, and Optics,Analytical Chemistry

Reference73 articles.

1. Principles of Information Security;Whitman,2011

2. CIS Controls v7.1https://www.cisecurity.org/controls/

3. Cybersecurity in healthcare: A systematic review of modern threats and trends

4. 2020 Data Breach Investigations Reporthttps://enterprise.verizon.com/resources/reports/2020-data-breach-investigations-report.pdf

5. 172 Ransomware Attacks on US Healthcare Organizations Since 2016 (Costing Over $157 Million)https://www.comparitech.com/blog/information-security/ransomware-attacks-hospitals-data/

Cited by 20 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Modelling user notification scenarios in privacy policies;Cybersecurity;2024-09-04

2. Local Government Cybersecurity Landscape: A Systematic Review and Conceptual Framework;Applied Sciences;2024-06-25

3. Automated Knowledge-Based Cybersecurity Risk Assessment of Cyber-Physical Systems;IEEE Access;2024

4. Towards Cybersecurity Risk Assessment Automation: an Ontological Approach;2023 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC/PiCom/CBDCom/CyberSciTech);2023-11-14

5. Adaptive vulnerability-based risk identification software with virtualization functions for dynamic management;Journal of Network and Computer Applications;2023-10

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3