Article

 

Integrating NIST Framework into FAIR model for Quantitative Risk Assessment of Cyber Threats Acceso Abierto Deposited

Contenido Descargable

File thumbnail: Submission_17_Bakare.pdf Descargar PDF
Descargar Adobe Acrobat Reader
Date Uploaded: 05/15/2020
Date Modified: 05/15/2020

As incessant cyber-attacks on organizations increase in complexity and destructiveness with the aim
to disrupt services and steal information, proactive measures are critically needed to mitigate these
attacks, cyber security risk assessment tops the list of measures. This study provides an overview of
cybersecurity risk assessment, various types of frameworks, and the difference between qualitative
and quantitative cybersecurity risk assessments. The aim of this early research is the creation of a
hybrid system which integrates an existing cybersecurity risk assessment system based on the NIST framework into the Factor Analysis of Information Risk (FAIR) model, an analytic risk assessment model that enables true quantitative measurement. In this study, we propose a hybrid-assessment tool which will be used to describe and compare the impact of using NIST driven values
as inputs for the resistance strength to determine the Loss Event Frequent (LEF) and Annual Loss
Expectancy (ALE) of a risk scenario as opposed to using experts’ opinion as user inputs for determination of the LEF and ALE values.

Creador
Licencia
Tema
Presentador
Colegio
Departamento
Fecha de creacion
Editor
Título de la revista
  • IT Research Symposium’19
Idioma

Digital Object Identifier (DOI)

Identificador: doi:10.7945/r35x-0f80
Enlazar: https://doi.org/10.7945/r35x-0f80

Este enlace DOI es la mejor manera para que otros citen su trabajo.

Relaciones

En Colección:

Elementos

Enlace permanente a esta página: https://scholar.uc.edu/show/b5644s84b