Article

 

A methodology for cyberthreat ranking Open Access Deposited

Article thumbnail: A methodology for cyberthreat ranking
Date Uploaded: 05/15/2020
Date Modified: 05/15/2020

National Institute of Standards and Technology (NIST) recommends that organizations perform cyber risk assessments regularly to identify security vulnerabilities and to control levels of exposure to threats. We discuss a method to customize the ranking of cyber threats based on the organization’s maturity level of implementing NIST controls and we use FAIR model’s LEF component as a measure of the severity of cyber threats. The methodology integrates NIST maturity levels to calculate the resistance strength factor and produce the LEF values for each threat. The LEF value is then used to represent the severity level of the threat to the specific organization. This hybrid risk assessment approach will help stakeholders make data-informed decisions on improving security measures and provide accurate values that represent the current security state of their organization.

Creator
License
Subject
Submitter
College
Department
Date Created
Journal Title
  • IT Research Symposium’20
Language
Related URL

Relationships

In Collection:

Items

Permanent link to this page: https://scholar.uc.edu/show/xd07gt933