Operational cyber incident coordination revisited: providing cyber situational awareness across organizations and countries

被引:0
作者
Leitner, Maria [1 ,2 ]
Skopik, Florian [2 ]
Pahi, Timea [2 ]
机构
[1] Univ Vienna, Fac Comp Sci, Waehringerstr 29, A-1090 Vienna, Austria
[2] AIT Austrian Inst Technol, Ctr Digital Safety & Secur, Vienna, Austria
来源
INFORMATION SECURITY JOURNAL | 2024年 / 33卷 / 05期
关键词
Coordination and cooperation platform; cyber situational awareness; incident coordination; cyber security;
D O I
10.1080/19393555.2024.2334787
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber situational awareness (CSA) is a prerequisite for justified decision-making and to maintain cyber security. This becomes particularly complex when establishing inter-organizational awareness across sectors. For example, computer security incident response teams (CSIRTs) and national cyber security centers need to establish CSA among countries when coordinating regional cyber incident response. Today's state of the art of information sharing across larger numbers of organizations is often still the least common denominator in the shape of web-based forms and email reports. These are easily applicable by almost everyone who wants to report findings even in stressful situations. However, these do not prove to be efficient for the coordinator that aggregates and merges the data. Therefore, a cyber coordination platform using online surveys is proposed. This approach uses surveys to collect, aggregate and visualize data in a dashboard to support cyber coordination and knowledge management. Furthermore, the online surveys are easy to use and respond to and therefore simplify the participation of stakeholders. We propose an architecture and implement a prototype using popular web application frameworks. The evaluation in a user study revealed promising results with respect to increased efficiency and decreased resource requirements for establishing situational awareness.
引用
收藏
页码:486 / 507
页数:22
相关论文
共 37 条
[1]   How can organizations develop situation awareness for incident response: A case study of management practice [J].
Ahmad, Atif ;
Maynard, Sean B. ;
Desouza, Kevin C. ;
Kotsias, James ;
Whitty, Monica T. ;
Baskerville, Richard L. .
COMPUTERS & SECURITY, 2021, 101
[2]   Incident response teams - Challenges in supporting the organisational security function [J].
Ahmad, Atif ;
Hadgkiss, Justin ;
Ruighaver, A. B. .
COMPUTERS & SECURITY, 2012, 31 (05) :643-652
[3]  
Bronk H., 2006, CSIRT SETTING GUIDE
[4]   An Empirical Analysis of the Docker Container Ecosystem on GitHub [J].
Cito, Jurgen ;
Schermann, Gerald ;
Witternt, John Erik ;
Leitner, Philipp ;
Zumberi, Sali ;
Gall, Harald C. .
2017 IEEE/ACM 14TH INTERNATIONAL CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2017), 2017, :323-333
[5]  
Conti G, 2013, 5 INT C CYBER CONFLI
[6]   TOWARD A THEORY OF SITUATION AWARENESS IN DYNAMIC-SYSTEMS [J].
ENDSLEY, MR .
HUMAN FACTORS, 1995, 37 (01) :32-64
[7]  
ENISA, 2012, NAT CYB SEC STRAT PR
[8]  
ENISA, 2017, ENISA Overview of Cybersecurity and Related Terminology Version 1
[9]  
European Commission, 2016, DIRECTIVE SECURITY N
[10]  
European Parliament Council of the European Union, 2022, DIRECTIVE EU 2022255, V12