Advancing cybersecurity capabilities for South African organisations through R&D

被引:0
作者
Khan, Zubeida Casmod [1 ]
Mkuzangwe, Nenekazi Nokuthala Penelope [1 ]
机构
[1] CSIR, Pretoria, South Africa
来源
PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2022) | 2022年
关键词
cybersecurity; cyber threat; cybersecurity capability; cyber-attack; research and development;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There is a growth of cyber-attacks in South Africa. Seeing that there are over 38 million Internet users in South Africa, this is no surprise. The South African government has published the National Cybersecurity Policy Framework (NCPF) and Protection of Personal Information Act (POPIA) to move towards mitigating cyber threats due to the increase of the presence of South African organisations and citizens in cyber space. This demonstrates that there is a need for organisations to have a clear roadmap to implement and improve on their own cybersecurity capabilities. South African organisations need to take a proactive stance in cybersecurity because businesses rely heavily on technology for day-to-day operations. Currently cyber-attacks cost South African organisations over R2 billion, and the current work-from- home arrangement that most organisations have implemented will only worsen the situation. While a cybersecurity roadmap will differ in every organisation based on the organisation's vision, goals, and objectives, along with their information technology (IT) and operations technology (OT), a starting point is perhaps the identification of key research and development (R&D) areas together with key activities that organisations can focus on in order to improve their cybersecurity capabilities. Cybersecurity capabilities are tools that organisations use to strengthen their organisation and protect themselves from potential cyber threats. The purpose of this study was to investigate R&D areas that organisations should invest in for the purpose of improving their cybersecurity capabilities. There are various subfields in cybersecurity that can be explored for organisations to advance their cybersecurity capabilities. Five integral R&D dimensions were identified together with key activities and are presented and discussed. A conceptual framework is also presented which maps the R&D dimensions and activities to the main pillars of cybersecurity, i.e., People, Processes, and Technology. South African organisations could reference the framework and adapt it for their business needs to protect themselves against potential cyber threats.
引用
收藏
页码:102 / 110
页数:9
相关论文
共 18 条
  • [1] ATLA, 2020, RD VIS REAL MULT DEF
  • [2] Business Tech (2021), 2021, BUSUNESS TECH AUG
  • [3] Chou T, 2019, P 2019 C IND ED COLL
  • [4] Cummings M L., 2018, Artificial Intelligence and International Affairs s, P7
  • [5] Deloitte, 2019, FUT RISK DIG ERA
  • [6] DRS, 2018, IMP DIG FOR CYB SEC
  • [7] Franco F. Di, 2018, ANAL EUROPEAN RD PRI
  • [8] Institute for Information Infrastructure Protection, 2003, CYB SEC RES DEV AG
  • [9] Johnson C., 2017, ITL B MAY 2017 CYBER
  • [10] Johnson C., 2016, NATL I STANDARDS TEC, DOI [10.6028/NIST.SP.800-150, DOI 10.6028/NIST.SP.800-150]