Risk Analysis and Assessment Framework for Cyber Security in Management Systems

Emin Tarakçi, Anıl Mustafa Gönül
{"title":"Risk Analysis and Assessment Framework for Cyber Security in Management Systems","authors":"Emin Tarakçi, Anıl Mustafa Gönül","doi":"10.38213/ohsacademy.1402624","DOIUrl":null,"url":null,"abstract":"Organizations are depending more and more on interconnected digital ecosystems, therefore strengthening cyber security measures is essential. This paper offers a thorough framework for risk assessment and management that fits into the larger category of cyber security-focused management systems. The framework that has been suggest-ed combines state-of-the-art techniques from the fields of risk management and cyber security to build a resilient system that can deal with modern cyber threats. The framework begins with a methodical inventory of resources—such as data centers, vital infrastructure, and network elements—that are necessary for the operation of the corporate cyber environment. A comprehensive risk assessment is then carried out, taking into account the possibility and consequences of any cyber attacks to the assets that have been identified. Predictive modeling and scenario analysis are integrated into the framework to enable a proactive approach to risk mitigation. Consistent with well-known management system standards like ISO 27001 and DDO, the framework emphasizes an iterative and cyclical process. Regular risk reviews, performance reviews, and strategy updates for risk management lead to continuous progress. The synchronization of cyber security measures with changing organ-izational structures and developing threats is ensured by this adaptive approach. In addition to strengthening an organization's cyber resilience, putting the suggested framework into practice ad-vances the more general objective of developing a strong and effective cyber security management system. This methodology offers a scalable and sustainable way to protect digital assets from the ever-changing pool of cyberat-tacks by smoothly integrating risk analysis and management into current organizational procedures. This study offers a methodical and comprehensive approach to risk analysis and management, which adds to the continuing conversation on cyber security. The framework that is provided here acts as a useful manual for com-panies that want to strengthen their cybersecurity while adhering to accepted management system standards.","PeriodicalId":259095,"journal":{"name":"OHS ACADEMY","volume":" 80","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2023-12-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"OHS ACADEMY","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.38213/ohsacademy.1402624","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Organizations are depending more and more on interconnected digital ecosystems, therefore strengthening cyber security measures is essential. This paper offers a thorough framework for risk assessment and management that fits into the larger category of cyber security-focused management systems. The framework that has been suggest-ed combines state-of-the-art techniques from the fields of risk management and cyber security to build a resilient system that can deal with modern cyber threats. The framework begins with a methodical inventory of resources—such as data centers, vital infrastructure, and network elements—that are necessary for the operation of the corporate cyber environment. A comprehensive risk assessment is then carried out, taking into account the possibility and consequences of any cyber attacks to the assets that have been identified. Predictive modeling and scenario analysis are integrated into the framework to enable a proactive approach to risk mitigation. Consistent with well-known management system standards like ISO 27001 and DDO, the framework emphasizes an iterative and cyclical process. Regular risk reviews, performance reviews, and strategy updates for risk management lead to continuous progress. The synchronization of cyber security measures with changing organ-izational structures and developing threats is ensured by this adaptive approach. In addition to strengthening an organization's cyber resilience, putting the suggested framework into practice ad-vances the more general objective of developing a strong and effective cyber security management system. This methodology offers a scalable and sustainable way to protect digital assets from the ever-changing pool of cyberat-tacks by smoothly integrating risk analysis and management into current organizational procedures. This study offers a methodical and comprehensive approach to risk analysis and management, which adds to the continuing conversation on cyber security. The framework that is provided here acts as a useful manual for com-panies that want to strengthen their cybersecurity while adhering to accepted management system standards.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
管理系统网络安全风险分析和评估框架
组织越来越依赖于相互关联的数字生态系统,因此加强网络安全措施至关重要。本文为风险评估和管理提供了一个全面的框架,符合以网络安全为重点的管理系统这一更大的范畴。本文所建议的框架结合了风险管理和网络安全领域的最新技术,以建立一个能够应对现代网络威胁的弹性系统。 该框架首先有条不紊地清点企业网络环境运行所需的资源,如数据中心、重要基础设施和网络元素。然后进行全面的风险评估,考虑到对已确定资产的任何网络攻击的可能性和后果。 预测建模和情景分析被集成到框架中,以实现主动的风险缓解方法。与 ISO 27001 和 DDO 等知名管理系统标准一致,该框架强调迭代和循环过程。定期进行风险审查、绩效审查和风险管理战略更新,从而不断取得进展。这种适应性方法可确保网络安全措施与不断变化的组织结构和发展中的威胁保持同步。 除了加强组织的网络复原力,将建议的框架付诸实践还能实现开发强大有效的网络安全管理系统这一更普遍的目标。通过将风险分析和管理顺利融入当前的组织程序,该方法提供了一种可扩展、可持续的方式,以保护数字资产免受不断变化的网络攻击。 本研究为风险分析和管理提供了一种有条不紊的综合方法,为有关网络安全的持续对话添砖加瓦。对于希望在遵守公认的管理系统标准的同时加强网络安全的企业来说,这里提供的框架是一本有用的手册。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Polyester Reçine Üretim Tesisinde Fonksiyonel Rezonans Analiz Yöntemi (FRAM) ile Risk Analizi Risk Analysis and Assessment Framework for Cyber Security in Management Systems Well-being and Psychosocial Risks in the Workplace: Strategies for Navigating Changing Dynamics PSİKOSOSYAL RİSK DEĞERLENDİRME ÖLÇEĞİ: NHUMAN PSR-Q ÖLÇEK GELİŞTİRME, GÜVENİRLİK VE GEÇERLİK ÇALIŞMASI Türkiye Nükleer Afet Yönetimi için Kritik Başarı Faktörlerinin Analizi
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1