Introducing OSSF: A framework for online service cybersecurity risk management

被引:32
作者
Meszaros, Jan [1 ]
Buchalcevova, Alena [1 ]
机构
[1] Univ Econ, Dept Informat Technol, W Churchill Sq 4, Prague 13067 3, Czech Republic
关键词
Security; Cybersecurity; Security risks; Risk management; Online service; Threats; Vulnerabilities; Measures; Risk analysis; Threat analysis;
D O I
10.1016/j.cose.2016.12.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper proposes a new framework for online services security risk management which can be used by both service providers and service consumers. The proposed framework was validated through a case study performed in a large enterprise environment. The key components of the proposed framework are Threat model and Risk model. These models are designed to fit specific features of online services and the surrounding cyberspace environment. A risk.management process is an integral part of the framework. The process is suitable for frequent and recurrent risk assessments. The process execution results in identification and performance of proper tasks which contribute to treatment of identified security risks and deficiencies. Online services risk score could be continuously documented and reported if the process is executed on a regular basis. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:300 / 313
页数:14
相关论文
共 16 条
[1]  
[Anonymous], 2014, Framework for improving critical infrastructure cybersecurity, DOI 10.6028/NIST.CSWP.02122014
[2]  
[Anonymous], 2014, 27000 ISOIEC
[3]  
[Anonymous], 2009, 310002009 ISOIEC
[4]  
[Anonymous], 2011, 270052011 ISOIEC
[5]  
[Anonymous], OV CYB
[6]   Identifying cyber risk hotspots: A framework for measuring temporal variance in computer network risk [J].
Awan, Malik Shahzad Kateem ;
Burnap, Pete ;
Rana, Omer .
COMPUTERS & SECURITY, 2016, 57 :31-46
[7]  
Caralli R.A., 2007, Technical report
[8]  
Government of Canada, 2007, HARM THREAT RISK ASS
[9]  
ISO IEC, 2012, 270322012 ISOIEC
[10]  
Lund MS, 2011, MODEL-DRIVEN RISK ANALYSIS: THE CORAS APPROACH, P3, DOI 10.1007/978-3-642-12323-8