A methodology for ontology-based interoperability of dynamic risk assessment frameworks in IoT environments

被引:3
作者
Sanchez-Zas, Carmen [1 ]
Larriva-Novo, Xavier [1 ]
Villagra, Victor A. [1 ]
Rivera, Diego [1 ]
Marin-Lopez, Andres [1 ]
机构
[1] Univ Politecn Madrid UPM, ETSI Telecomunicac, Ave Complutense 30, Madrid 28040, Spain
关键词
Methodology; Risk assessment; Ontology; Internet of Things; Cybersecurity; Support to decision making; MANAGEMENT;
D O I
10.1016/j.iot.2024.101267
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Proper cyber risk management is essential for organizations to make informed decisions and avoid potential financial losses, reputational damage, operational disruptions and other negative impacts. To this end, different institutions have defined risk analysis and risk management methodologies to address the problem and monitor cyber security in organizations. In this aspect, ontologies provide a very powerful tool for interoperability in risk management, given the heterogeneity of input information considered in the different steps of each framework and the ability they provide to perform logical reasoning in order to infer new knowledge. Throughout this study we analyze the different properties of some of the methodologies with the highest adoption rate, proposing an interoperable framework based on an ontology that allows compatibility between different systems, with a dynamic, flexible and efficient operation.
引用
收藏
页数:20
相关论文
共 45 条
[1]   Toward ontology-based risk management framework for software projects: An empirical study [J].
Abioye, Temitope Elizabeth ;
Arogundade, Oluwasefunmi Tale ;
Misra, Sanjay ;
Akinwale, Adio T. ;
Adeniran, Olusola John .
JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2020, 32 (12)
[2]  
Agrawal V., 2016, P INT S HUM ASP INF, P101
[3]   Design of capability maturity model integration with cybersecurity risk severity complex prediction using bayesian-based machine learning models [J].
Alshammari, Fahad H. .
SERVICE ORIENTED COMPUTING AND APPLICATIONS, 2023, 17 (01) :59-72
[4]  
[Anonymous], 2023, EBIOS-risk manager
[5]  
[Anonymous], 2024, OWL web ontology language - overview
[6]  
[Anonymous], 2023, SPIN - overview and motivation
[7]  
[Anonymous], 2023, Gestion de riesgos - una guia de aproximacion para el empresario
[8]  
[Anonymous], 2023, Interoperable EU risk management toolbox - ENISA
[9]  
[Anonymous], 2023, EBIOS-generic approach
[10]  
[Anonymous], 2023, What is monarc? - MONARC