Article

 

Integrating NIST Framework into FAIR model for Quantitative Risk Assessment of Cyber Threats 开放存取 Deposited

可下载的内容

File thumbnail: Submission_17_Bakare.pdf 下载PDF文件
下载 Adobe Acrobat Reader
Date Uploaded: 05/15/2020
Date Modified: 05/15/2020

As incessant cyber-attacks on organizations increase in complexity and destructiveness with the aim
to disrupt services and steal information, proactive measures are critically needed to mitigate these
attacks, cyber security risk assessment tops the list of measures. This study provides an overview of
cybersecurity risk assessment, various types of frameworks, and the difference between qualitative
and quantitative cybersecurity risk assessments. The aim of this early research is the creation of a
hybrid system which integrates an existing cybersecurity risk assessment system based on the NIST framework into the Factor Analysis of Information Risk (FAIR) model, an analytic risk assessment model that enables true quantitative measurement. In this study, we propose a hybrid-assessment tool which will be used to describe and compare the impact of using NIST driven values
as inputs for the resistance strength to determine the Loss Event Frequent (LEF) and Annual Loss
Expectancy (ALE) of a risk scenario as opposed to using experts’ opinion as user inputs for determination of the LEF and ALE values.

创建者
证书
学科
提交
部门
创建日期
出版者
期刊名称
  • IT Research Symposium’19
语言

Digital Object Identifier (DOI)

识别码: doi:10.7945/r35x-0f80
链接: https://doi.org/10.7945/r35x-0f80

这个DOI链接是其他人引用您工作的最佳方式。

关系

在收集:

单件

永久链接到此页面: https://scholar.uc.edu/show/b5644s84b