Abstract
The application of the Wald’s criterion for risk analysis and management within the context of ensuring resilience for mission-critical information systems, operations, and organizations in conditions of uncertainty is considered. The proposed method facilitates addressing risks asso-ciated with stochastic and HILF (high impact, low frequency) threats, the probability of which is challenging to predict. This approach is grounded in assessing potential damages and the cost of countermeasures concerning these types of threats. Notably, the focus is directed towards ex-amining the worst possible outcomes of the evaluated threats, reducing the need for accurate probability forecasting. Utilizing the maximin criterion allows for surpassing the constraints of the standard risk matrix, which is employed to determine the risk level by juxtaposing the threat’s probability category with the severity of its implications. Consequently, information security systems can attain heightened levels of efficiency, which, subsequently, bolsters the re-silience of the organizations they safeguard.
Publisher
National Academy of Sciences of Ukraine (Co. LTD Ukrinformnauka) (Publications)
Reference12 articles.
1. Procedure for the implementation of the information security system in government agencies, enterprises, organizations whose information and communication systems process information, the requirement for protection of which is established by law and does not constitute a state secret (2021) НД ТЗІ 3.6-004-21. Administration of the State Special Communications Service of Ukraine.
2. Masys, A.J., Ray-Bennett, N., Shiroshita, H., & Jackson, P. (2014). High Impact/Low Frequency Extreme Events: Enabling Reflection and Resilience in a Hyper-connected World. Procedia Economics and Finance, 18, 772-779. https://doi.org/10.1016/s2212-5671(14)01001-6.
3. Murray, N.J., Keith, D.A., Bland, L.M., Nicholson, E., Regan, T.J., Rodríguez, J.P., & Bedward, M. (2017). The use of range size to assess risks to biodiversity from stochastic threats. Diversity and Distributions, 23(5), 474-483. https://doi.org/10.1111/ddi.12533.
4. NIST Special Publication 800-160, Volume 2. Developing cyber-resilient systems: A systems security engineering approach. (2021). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1
5. Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1. (2018). National Institute of Standards and Technology. https://doi.org/10.6028/nist.cswp.04162018