Automated Cyber and Privacy Risk Management Toolkit

被引:15
作者
Gonzalez-Granadillo, Gustavo [1 ]
Menesidou, Sofia Anna [2 ]
Papamartzivanos, Dimitrios [2 ]
Romeu, Ramon [3 ]
Navarro-Llobet, Diana [3 ]
Okoh, Caxton [4 ]
Nifakos, Sokratis [5 ]
Xenakis, Christos [6 ]
Panaousis, Emmanouil [4 ]
机构
[1] ATOS Spain, Atos Res & Innovat, Cybersecur Unit, Barcelona 08020, Spain
[2] UBITECH Ltd, Thessalias 8 & Etolias 10, Chalandri 15231, Greece
[3] Fundacio Privada Hosp Asil Granollers, Granollers 08402, Spain
[4] Univ Greenwich, Sch Comp & Math Sci, London SE10 9LS, England
[5] Karolinska Inst, Dept Learning Informat Management & Eth, Tomtebodavagen 18b, S-17165 Solna, Sweden
[6] Univ Piraeus, Dept Digital Syst, Karaoli Ke Dimitriou 80, Piraeus 18534, Greece
基金
欧盟地平线“2020”;
关键词
toolkit; cybersecurity; privacy; risk assessment; risk control; healthcare; DECISION-SUPPORT; HEALTH-CARE; GAME-THEORY; SECURITY; CYBERSECURITY; ASSESSMENTS; SELECTION;
D O I
10.3390/s21165493
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
Addressing cyber and privacy risks has never been more critical for organisations. While a number of risk assessment methodologies and software tools are available, it is most often the case that one must, at least, integrate them into a holistic approach that combines several appropriate risk sources as input to risk mitigation tools. In addition, cyber risk assessment primarily investigates cyber risks as the consequence of vulnerabilities and threats that threaten assets of the investigated infrastructure. In fact, cyber risk assessment is decoupled from privacy impact assessment, which aims to detect privacy-specific threats and assess the degree of compliance with data protection legislation. Furthermore, a Privacy Impact Assessment (PIA) is conducted in a proactive manner during the design phase of a system, combining processing activities and their inter-dependencies with assets, vulnerabilities, real-time threats and Personally Identifiable Information (PII) that may occur during the dynamic life-cycle of systems. In this paper, we propose a cyber and privacy risk management toolkit, called AMBIENT (Automated Cyber and Privacy Risk Management Toolkit) that addresses the above challenges by implementing and integrating three distinct software tools. AMBIENT not only assesses cyber and privacy risks in a thorough and automated manner but it also offers decision-support capabilities, to recommend optimal safeguards using the well-known repository of the Center for Internet Security (CIS) Controls. To the best of our knowledge, AMBIENT is the first toolkit in the academic literature that brings together the aforementioned capabilities. To demonstrate its use, we have created a case scenario based on information about cyber attacks we have received from a healthcare organisation, as a reference sector that faces critical cyber and privacy threats.
引用
收藏
页数:28
相关论文
共 73 条
  • [1] Supporting Privacy Impact Assessment by Model-Based Privacy Analysis
    Ahmadian, Amir Shayan
    Strueber, Daniel
    Riediger, Volker
    Juerjens, Jan
    [J]. 33RD ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2018, : 1467 - 1474
  • [2] [Anonymous], 2017, ISOIEC291342017
  • [3] [Anonymous], 2020, NIST privacy framework: a tool for improving privacy through enterprise risk management No, DOI DOI 10.6028/NIST.CSWP.01162020
  • [4] [Anonymous], 2014, ISOIEC270182014
  • [5] [Anonymous], 2017, ISOIEC291512017
  • [6] The weakest link revisited
    Arce, Iván
    [J]. IEEE Security and Privacy, 2003, 1 (02) : 72 - 76
  • [7] Arnell S., GDPR DATA PROTECTION
  • [8] Bay Dynamics, CYB VAL RISK QUANT F
  • [9] Bischoff P., 2020, 172 Ransomware attacks on US Healthcare Organizations since 2016
  • [10] A text-mining based cyber-risk assessment and mitigation framework for critical analysis of online hacker forums
    Biswas, Baidyanath
    Mukhopadhyay, Arunabha
    Bhattacharjee, Sudip
    Kumar, Ajay
    Delen, Dursun
    [J]. DECISION SUPPORT SYSTEMS, 2020, 152