首页 > 最新文献

Journal of business continuity & emergency planning最新文献

英文 中文
An apolitical risk assessment of the 2024 US elections: The threat of widespread riots and significant business disruption. 对 2024 年美国大选的非政治风险评估:大范围骚乱和重大业务中断的威胁。
Q3 Medicine Pub Date : 2024-01-01
Mike Blyth, Antony Sherlock, Sula Mpande, Daniel Beale

Civil disorder has always plagued humanity, with violence being triggered by real or perceived grievances, rumours and speculation, and internal or external agitators. The risk to people, communities, businesses and the rule of law is not isolated to a particular country or society. The propensity for violence and how it is incited is, however, an evolving threat with the advent of the 'modern riot'. The causes of violence centre on economic and social injustice, sports- and event-related riots, a reaction to police or security forces and political unrest. As the US nears the contentious 2024 elections, the failing trust in the three branches of government combined with external global tensions and conflict, threats from domestic extremist groups, a rising acceptance of violence as a means of settling political disagreements, hostile nation actors and international terror groups that exploit societal instability create fertile conditions for widespread violence. Exacerbating these factors are the risks from artificial intelligence (AI) deepfake, rapid mass communications, the citizen journalist, prominent influencers amplifying grievances and inflammatory media reporting. This convergence of exacerbators and accelerants for political discord offers the potential for serious security risks and significant business disruption.

内乱一直困扰着人类,实际或想象中的不满、谣言和猜测、内部或外部煽动者都会引发暴力。人民、社区、企业和法治所面临的风险并不局限于某个国家或社会。然而,随着 "现代骚乱 "的出现,暴力倾向及其煽动方式是一种不断演变的威胁。暴力事件的起因主要是经济和社会不公、与体育和活动有关的骚乱、对警察或安全部队的反应以及政治动荡。随着美国 2024 年大选的临近,人们对政府三大部门的信任度不断下降,再加上外部的全球紧张局势和冲突、国内极端主义组织的威胁、越来越多的人接受暴力作为解决政治分歧的手段、敌对的国家行为体和利用社会不稳定的国际恐怖组织,这些都为广泛的暴力活动创造了肥沃的土壤。人工智能(AI)深度伪造、快速大众传播、公民记者、扩大不满情绪的知名影响者和煽动性媒体报道等风险加剧了这些因素。政治不和谐的加剧因素和助推因素汇聚在一起,有可能带来严重的安全风险和重大的业务干扰。
{"title":"An apolitical risk assessment of the 2024 US elections: The threat of widespread riots and significant business disruption.","authors":"Mike Blyth, Antony Sherlock, Sula Mpande, Daniel Beale","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>Civil disorder has always plagued humanity, with violence being triggered by real or perceived grievances, rumours and speculation, and internal or external agitators. The risk to people, communities, businesses and the rule of law is not isolated to a particular country or society. The propensity for violence and how it is incited is, however, an evolving threat with the advent of the 'modern riot'. The causes of violence centre on economic and social injustice, sports- and event-related riots, a reaction to police or security forces and political unrest. As the US nears the contentious 2024 elections, the failing trust in the three branches of government combined with external global tensions and conflict, threats from domestic extremist groups, a rising acceptance of violence as a means of settling political disagreements, hostile nation actors and international terror groups that exploit societal instability create fertile conditions for widespread violence. Exacerbating these factors are the risks from artificial intelligence (AI) deepfake, rapid mass communications, the citizen journalist, prominent influencers amplifying grievances and inflammatory media reporting. This convergence of exacerbators and accelerants for political discord offers the potential for serious security risks and significant business disruption.</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"18 1","pages":"6-38"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"142009618","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Redefining cyber resilience : Through the risk register lens. 重新定义网络复原力:通过风险登记透镜。
Q3 Medicine Pub Date : 2024-01-01
Ria Thomas

Resilience is deeper than maintaining a company's operations and services in the face of significant disruptions. It is the ability of a business to withstand, pivot and continue to grow in the face of a significant threat. To achieve resilience, companies must have an integrated, end-to-end understanding of how a specific threat magnifies the risks identified on their risk register, and what measures are needed across the enterprise to address the amplification of those risks. This paper details how the need for a holistic approach is especially important for cyber crises, compared with other types of crises, because they tend to have more broad-ranging impacts and complexities, such as: unclear timelines, lack of public empathy, unpredictable human threat actor(s), as well as a broader set of internal and external stakeholders that need to be engaged. Unlike other crises, cyber crises have the potential to magnify most - if not all - of the risks on the risk register. As such, cyber resilience requires ensuring that key stakeholders, whether shareholders, customers, regulators, business partners, employees, etc, stay resolute in their faith in a company and its leadership's ability to navigate the increasingly complex issues related to cyber risks and how these issues are addressed enterprise-wide, not purely seen through the lens of technical or operational resilience. To achieve cyber resilience, organisations must develop and implement programmes that integrate both the technical and the broader business measures needed to limit fallout, demonstrate leadership through cyber crises, and deepen trust regardless of the potential severity of the impact.

复原力不仅仅是在面临重大干扰时维持公司的运营和服务。它是企业在面对重大威胁时的承受能力、转向能力和继续发展的能力。要实现复原力,企业必须对特定威胁如何放大其风险登记册中确定的风险,以及整个企业需要采取哪些措施来应对这些风险的放大有一个综合的、端到端的了解。与其他类型的危机相比,网络危机往往具有更广泛的影响和复杂性,例如:不明确的时间表、缺乏公众共鸣、不可预测的人类威胁行为者,以及需要参与的更广泛的内部和外部利益相关者,因此,本文详细阐述了对整体方法的需求对于网络危机尤为重要。与其他危机不同,网络危机有可能放大风险登记册上的大部分风险(如果不是全部的话)。因此,网络复原力要求确保主要利益相关者,无论是股东、客户、监管机构、业务伙伴、员工等,都坚定地相信公司及其领导层有能力应对日益复杂的网络风险相关问题,以及如何在整个企业范围内解决这些问题,而不是纯粹从技术或运营复原力的角度来看待这些问题。要实现网络复原力,企业必须制定和实施各种计划,将技术措施和更广泛的业务措施结合起来,以限制影响,在网络危机中展现领导力,并加深信任,而不管潜在影响的严重程度如何。
{"title":"Redefining cyber resilience : Through the risk register lens.","authors":"Ria Thomas","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>Resilience is deeper than maintaining a company's operations and services in the face of significant disruptions. It is the ability of a business to withstand, pivot and continue to grow in the face of a significant threat. To achieve resilience, companies must have an integrated, end-to-end understanding of how a specific threat magnifies the risks identified on their risk register, and what measures are needed across the enterprise to address the amplification of those risks. This paper details how the need for a holistic approach is especially important for cyber crises, compared with other types of crises, because they tend to have more broad-ranging impacts and complexities, such as: unclear timelines, lack of public empathy, unpredictable human threat actor(s), as well as a broader set of internal and external stakeholders that need to be engaged. Unlike other crises, cyber crises have the potential to magnify most - if not all - of the risks on the risk register. As such, cyber resilience requires ensuring that key stakeholders, whether shareholders, customers, regulators, business partners, employees, etc, stay resolute in their faith in a company and its leadership's ability to navigate the increasingly complex issues related to cyber risks and how these issues are addressed enterprise-wide, not purely seen through the lens of technical or operational resilience. To achieve cyber resilience, organisations must develop and implement programmes that integrate both the technical and the broader business measures needed to limit fallout, demonstrate leadership through cyber crises, and deepen trust regardless of the potential severity of the impact.</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"18 1","pages":"75-83"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"142009638","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Continuity of an essential service during the COVID-19 pandemic: A systematic review and meta-analysis of vaccine perceptions and hesitancy in the emergency medical services profession. COVID-19 大流行期间基本服务的连续性:关于紧急医疗服务行业对疫苗的看法和犹豫的系统回顾与荟萃分析。
Q3 Medicine Pub Date : 2024-01-01
Randy D Kearns, Ginny R Kaplan, Michael W Hubble

During and subsequent to a natural disaster, there is an expectation that certain elements of society will continue to operate with a degree of normalcy. For example, it is expected that emergency medical services will continue to function and remain reliable for the community served. Expectations such as these are based on the presumed reliability of government and the assumption that those responsible for the relevant infrastructure will have made plans to ensure it remains functional and taken steps to mitigate known weaknesses. The COVID-19 pandemic provides a case in point. Specifically, data captured during the pandemic are now the subject of ongoing review and analysis, and the findings from such studies are being used to inform planning and preparedness for the next public health disaster. This particular study was conducted in response to circumstantial evidence indicating that frontline workers in the healthcare profession may share some of the same ambivalence towards transmission mitigation as seen in the general population when confronted with new and emerging communicable diseases. This is a concern, as when medical personnel are either unable or unwilling to take reasonable steps to protect themselves and their patients, it undermines the readiness of the essential service. To explore this situation in greater depth, the study examines the real-time responses from a sample of frontline personnel interviewed during the pandemic. The results indicate that there are a number of opportunities to improve workforce readiness to assure reliable continuity during the next outbreak, epidemic or pandemic.

在自然灾害发生期间及之后,人们期望社会的某些要素能够在一定程度上继续正常运行。例如,人们期望紧急医疗服务将继续运作,并对所服务的社区保持可靠。诸如此类的期望都是基于政府的可靠性假设,以及相关基础设施的负责人已制定计划确保其继续运作并采取措施减轻已知弱点的假设。COVID-19 大流行就是一个很好的例子。具体而言,大流行期间获取的数据目前正在进行审查和分析,研究结果将用于为下一次公共卫生灾难的规划和准备工作提供信息。有间接证据表明,医疗保健行业的一线工作者在面对新出现的传染病时,可能会像普通人一样对减少传播抱有矛盾的态度,因此我们开展了这项研究。这是一个令人担忧的问题,因为当医务人员不能或不愿采取合理措施来保护自己和病人时,就会破坏基本服务的准备状态。为了更深入地探讨这种情况,本研究对大流行期间采访的一线人员的实时反应进行了抽样调查。结果表明,有很多机会可以提高工作人员的准备状态,以确保在下一次疫情爆发、流行病或大流行期间保持可靠的连续性。
{"title":"Continuity of an essential service during the COVID-19 pandemic: A systematic review and meta-analysis of vaccine perceptions and hesitancy in the emergency medical services profession.","authors":"Randy D Kearns, Ginny R Kaplan, Michael W Hubble","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>During and subsequent to a natural disaster, there is an expectation that certain elements of society will continue to operate with a degree of normalcy. For example, it is expected that emergency medical services will continue to function and remain reliable for the community served. Expectations such as these are based on the presumed reliability of government and the assumption that those responsible for the relevant infrastructure will have made plans to ensure it remains functional and taken steps to mitigate known weaknesses. The COVID-19 pandemic provides a case in point. Specifically, data captured during the pandemic are now the subject of ongoing review and analysis, and the findings from such studies are being used to inform planning and preparedness for the next public health disaster. This particular study was conducted in response to circumstantial evidence indicating that frontline workers in the healthcare profession may share some of the same ambivalence towards transmission mitigation as seen in the general population when confronted with new and emerging communicable diseases. This is a concern, as when medical personnel are either unable or unwilling to take reasonable steps to protect themselves and their patients, it undermines the readiness of the essential service. To explore this situation in greater depth, the study examines the real-time responses from a sample of frontline personnel interviewed during the pandemic. The results indicate that there are a number of opportunities to improve workforce readiness to assure reliable continuity during the next outbreak, epidemic or pandemic.</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"18 1","pages":"84-96"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"142009620","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Get it together, together: Creating whole community continuity through cross-sector collaboration in Texas. 齐心协力,共同完成:在得克萨斯州,通过跨部门合作创造整个社区的连续性。
Q3 Medicine Pub Date : 2024-01-01
Heather Hernandez, Shelby Hyman, Stephen Vollbrecht

Continuity of operations for government is an evolving philosophy, much like exercises and after-action reports. Continuity continues to identify areas for growth and improvement as more people become involved in the conversation. This paper briefly describes the evolution of continuity in the USA and its application in the State of Texas. Moving forward, it discusses the application of the concept of 'whole community continuity' as the driving force of the Continuity Council in Texas, which focuses on preparedness at all levels, from individuals to private industry, to all levels of government.

政府行动的连续性是一个不断发展的理念,就像演习和行动后报告一样。随着越来越多的人参与到对话中来,连续性不断确定增长和改进的领域。本文简要介绍了连续性在美国的演变及其在得克萨斯州的应用。展望未来,本文讨论了 "整个社区连续性 "概念的应用,它是得克萨斯州连续性委员会的推动力,重点关注从个人到私营企业,再到各级政府等各个层面的准备工作。
{"title":"Get it together, together: Creating whole community continuity through cross-sector collaboration in Texas.","authors":"Heather Hernandez, Shelby Hyman, Stephen Vollbrecht","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>Continuity of operations for government is an evolving philosophy, much like exercises and after-action reports. Continuity continues to identify areas for growth and improvement as more people become involved in the conversation. This paper briefly describes the evolution of continuity in the USA and its application in the State of Texas. Moving forward, it discusses the application of the concept of 'whole community continuity' as the driving force of the Continuity Council in Texas, which focuses on preparedness at all levels, from individuals to private industry, to all levels of government.</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"17 3","pages":"235-247"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"139997733","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Building resilience: The role of enterprise security risk management in developing a resilient organisation. 建设复原力:企业安全风险管理在发展弹性组织中的作用。
Q3 Medicine Pub Date : 2024-01-01
Tim McCreight

Enterprise security risk management (ESRM) has continued to gain global acceptance as a management philosophy for the development and implementation of an enterprise-wide corporate security programme. As organisations continue to rebuild and recover from COVID-19, the value of assessing the resilience of an organisation through regular testing of its response to events has gained prominence. There are opportunities to link the development and implementation of a risk-based approach for designing a security programme, to assessing an organisation's resilience to future events. Organisations can benefit from the complementary approaches of ESRM and organisational resilience once the commonalities are identified and embraced. This paper expands upon the ESRM management approach, linking the concepts of ESRM to the design of a resilient enterprise.

企业安全风险管理(ESRM)作为制定和实施全企业范围企业安全计划的管理理念,在全球范围内不断得到认可。随着各组织继续从 COVID-19 事件中重建和恢复,通过定期测试其对事件的响应来评估组织复原力的价值已变得越来越突出。我们有机会将制定和实施基于风险的方法来设计安全计划与评估组织对未来事件的应变能力联系起来。一旦发现并接受了这两种方法的共同点,各组织就能从 ESRM 和组织复原力的互补方法中获益。本文扩展了环境、社会和风险管理的管理方法,将环境、社会和风险管理的概念与复原力企业的设计联系起来。
{"title":"Building resilience: The role of enterprise security risk management in developing a resilient organisation.","authors":"Tim McCreight","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>Enterprise security risk management (ESRM) has continued to gain global acceptance as a management philosophy for the development and implementation of an enterprise-wide corporate security programme. As organisations continue to rebuild and recover from COVID-19, the value of assessing the resilience of an organisation through regular testing of its response to events has gained prominence. There are opportunities to link the development and implementation of a risk-based approach for designing a security programme, to assessing an organisation's resilience to future events. Organisations can benefit from the complementary approaches of ESRM and organisational resilience once the commonalities are identified and embraced. This paper expands upon the ESRM management approach, linking the concepts of ESRM to the design of a resilient enterprise.</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"17 4","pages":"363-374"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"140913236","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Operational resilience towards a global alignment. 实现全球统一的业务复原力。
Q3 Medicine Pub Date : 2024-01-01
Alda Bida, Rupesh Nathoo

Operational resilience lies between operational risk and business continuity. This paper provides a view on the implementation of the operational resilience framework, and its relationship with operational risk and business continuity. It analyses the similarities and differences between these exercises and how management information from these exercises can be leveraged and aligned. The paper also provides answers to three important questions: (1) What pushed the international regulators to add additional oversight? (2) What benefits and challenges are brought by operational resilience? (3) Why is it important to harmonise operational resilience within the international regulatory landscape?

业务复原力介于业务风险和业务连续性之间。本文就运营复原力框架的实施及其与运营风险和业务连续性的关系提出了看法。它分析了这些工作之间的异同,以及如何利用和调整这些工作中的管理信息。本文还回答了三个重要问题:(1) 是什么促使国际监管机构增加额外的监督?(2) 业务复原力带来了哪些益处和挑战?(3) 为什么在国际监管范围内协调运营弹性非常重要?
{"title":"Operational resilience towards a global alignment.","authors":"Alda Bida, Rupesh Nathoo","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>Operational resilience lies between operational risk and business continuity. This paper provides a view on the implementation of the operational resilience framework, and its relationship with operational risk and business continuity. It analyses the similarities and differences between these exercises and how management information from these exercises can be leveraged and aligned. The paper also provides answers to three important questions: (1) What pushed the international regulators to add additional oversight? (2) What benefits and challenges are brought by operational resilience? (3) Why is it important to harmonise operational resilience within the international regulatory landscape?</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"17 4","pages":"306-322"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"140913283","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Mine the past: How to make better risk-based decisions and improve outcomes with historical threat data. 挖掘过去:如何利用历史威胁数据更好地做出基于风险的决策并改进结果。
Q3 Medicine Pub Date : 2024-01-01
Ann Pickren

The impact of every crisis has the potential to cascade throughout an organisation's operations, supply chain and market ecosystem. To properly understand and mitigate this ripple of dynamic risk, business continuity, security and risk management leaders need to know where to focus their attention. Looking at historical threat data provides a clearer picture of the risk landscape, helping leaders better anticipate and plan for the future. To date, however, there have been challenges in this process. As the volume of data about critical events continues to grow at an alarming rate, sifting manually through data puts organisations - and business continuity - in jeopardy. This paper discusses the value of historical threat data and innovations in data-mining technology that can unlock the true power of historical data for informed, strategic decision-making and better outcomes during a crisis.

每次危机的影响都有可能波及整个组织的运营、供应链和市场生态系统。为了正确理解和缓解这种动态风险涟漪,业务连续性、安全和风险管理领导者需要知道他们的关注点在哪里。查看历史威胁数据可以更清晰地了解风险状况,帮助领导者更好地预测和规划未来。然而,迄今为止,这一过程一直面临挑战。随着关键事件数据量以惊人的速度持续增长,人工筛选数据会危及组织和业务连续性。本文讨论了历史威胁数据的价值以及数据挖掘技术的创新,这些技术可以释放历史数据的真正力量,从而在危机期间做出明智的战略决策并取得更好的结果。
{"title":"Mine the past: How to make better risk-based decisions and improve outcomes with historical threat data.","authors":"Ann Pickren","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>The impact of every crisis has the potential to cascade throughout an organisation's operations, supply chain and market ecosystem. To properly understand and mitigate this ripple of dynamic risk, business continuity, security and risk management leaders need to know where to focus their attention. Looking at historical threat data provides a clearer picture of the risk landscape, helping leaders better anticipate and plan for the future. To date, however, there have been challenges in this process. As the volume of data about critical events continues to grow at an alarming rate, sifting manually through data puts organisations - and business continuity - in jeopardy. This paper discusses the value of historical threat data and innovations in data-mining technology that can unlock the true power of historical data for informed, strategic decision-making and better outcomes during a crisis.</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"17 4","pages":"351-362"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"140913281","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Editorial. 社论
Q3 Medicine Pub Date : 2024-01-01
Lyndon Bird
{"title":"Editorial.","authors":"Lyndon Bird","doi":"","DOIUrl":"","url":null,"abstract":"","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"17 4","pages":"304-305"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"140913238","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Editorial. 社论
Q3 Medicine Pub Date : 2024-01-01
Lyndon Bird
{"title":"Editorial.","authors":"Lyndon Bird","doi":"","DOIUrl":"","url":null,"abstract":"","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"17 3","pages":"204-205"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"139997732","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
Building capability and community through cyber-incident response exercises. 通过网络事件应对演习建设能力和社区。
Q3 Medicine Pub Date : 2024-01-01
Matthew Ricks

While a natural disaster or related threat may impact an organisation at some point, it is more likely (even inevitable) that it will be the victim of a cyber attack. The solution to being better prepared for these imminent attacks is to undertake more lightweight and frequent incident response (IR) exercises to help build capabilities and community through a tighter, recurring cycle of planning, conducting and assessing. To boost the facilitation of IR exercises, organisations must leverage the established relationships between business continuity management (BCM) or resilience staff (both of which are familiar with business continuity and disaster recovery exercises), and their information security office. As BCM will ultimately be involved in response and recovery after a cyber attack, it is intuitively more effective to collaborate with BCM in advance. Indeed, it has been substantiated that BCM engagement improves incident response time and reduces incident response costs. This paper concludes that involving BCM or resilience departments in IR exercises contributes to more effective responses to actual incidents.

虽然自然灾害或相关威胁可能会在某些时候对组织造成影响,但组织更有可能(甚至不可避免)成为网络攻击的受害者。为更好地应对这些迫在眉睫的攻击,解决方案是开展更轻量级、更频繁的事件响应(IR)演习,通过计划、实施和评估的紧密循环,帮助建立能力和社区。为了促进事件响应演习,组织必须利用业务连续性管理(BCM)或恢复力员工(两者都熟悉业务连续性和灾难恢复演习)与其信息安全办公室之间的既定关系。由于业务连续性管理部门最终将参与网络攻击后的响应和恢复工作,因此直观地说,提前与业务连续性管理部门合作更为有效。事实证明,业连管的参与能缩短事件响应时间,降低事件响应成本。本文的结论是,让业连管或复原部门参与 IR 演习有助于更有效地应对实际事件。
{"title":"Building capability and community through cyber-incident response exercises.","authors":"Matthew Ricks","doi":"","DOIUrl":"","url":null,"abstract":"<p><p>While a natural disaster or related threat may impact an organisation at some point, it is more likely (even inevitable) that it will be the victim of a cyber attack. The solution to being better prepared for these imminent attacks is to undertake more lightweight and frequent incident response (IR) exercises to help build capabilities and community through a tighter, recurring cycle of planning, conducting and assessing. To boost the facilitation of IR exercises, organisations must leverage the established relationships between business continuity management (BCM) or resilience staff (both of which are familiar with business continuity and disaster recovery exercises), and their information security office. As BCM will ultimately be involved in response and recovery after a cyber attack, it is intuitively more effective to collaborate with BCM in advance. Indeed, it has been substantiated that BCM engagement improves incident response time and reduces incident response costs. This paper concludes that involving BCM or resilience departments in IR exercises contributes to more effective responses to actual incidents.</p>","PeriodicalId":39080,"journal":{"name":"Journal of business continuity & emergency planning","volume":"18 1","pages":"49-58"},"PeriodicalIF":0.0,"publicationDate":"2024-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"142009619","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
引用次数: 0
期刊
Journal of business continuity & emergency planning
全部 Acc. Chem. Res. ACS Applied Bio Materials ACS Appl. Electron. Mater. ACS Appl. Energy Mater. ACS Appl. Mater. Interfaces ACS Appl. Nano Mater. ACS Appl. Polym. Mater. ACS BIOMATER-SCI ENG ACS Catal. ACS Cent. Sci. ACS Chem. Biol. ACS Chemical Health & Safety ACS Chem. Neurosci. ACS Comb. Sci. ACS Earth Space Chem. ACS Energy Lett. ACS Infect. Dis. ACS Macro Lett. ACS Mater. Lett. ACS Med. Chem. Lett. ACS Nano ACS Omega ACS Photonics ACS Sens. ACS Sustainable Chem. Eng. ACS Synth. Biol. Anal. Chem. BIOCHEMISTRY-US Bioconjugate Chem. BIOMACROMOLECULES Chem. Res. Toxicol. Chem. Rev. Chem. Mater. CRYST GROWTH DES ENERG FUEL Environ. Sci. Technol. Environ. Sci. Technol. Lett. Eur. J. Inorg. Chem. IND ENG CHEM RES Inorg. Chem. J. Agric. Food. Chem. J. Chem. Eng. Data J. Chem. Educ. J. Chem. Inf. Model. J. Chem. Theory Comput. J. Med. Chem. J. Nat. Prod. J PROTEOME RES J. Am. Chem. Soc. LANGMUIR MACROMOLECULES Mol. Pharmaceutics Nano Lett. Org. Lett. ORG PROCESS RES DEV ORGANOMETALLICS J. Org. Chem. J. Phys. Chem. J. Phys. Chem. A J. Phys. Chem. B J. Phys. Chem. C J. Phys. Chem. Lett. Analyst Anal. Methods Biomater. Sci. Catal. Sci. Technol. Chem. Commun. Chem. Soc. Rev. CHEM EDUC RES PRACT CRYSTENGCOMM Dalton Trans. Energy Environ. Sci. ENVIRON SCI-NANO ENVIRON SCI-PROC IMP ENVIRON SCI-WAT RES Faraday Discuss. Food Funct. Green Chem. Inorg. Chem. Front. Integr. Biol. J. Anal. At. Spectrom. J. Mater. Chem. A J. Mater. Chem. B J. Mater. Chem. C Lab Chip Mater. Chem. Front. Mater. Horiz. MEDCHEMCOMM Metallomics Mol. Biosyst. Mol. Syst. Des. Eng. Nanoscale Nanoscale Horiz. Nat. Prod. Rep. New J. Chem. Org. Biomol. Chem. Org. Chem. Front. PHOTOCH PHOTOBIO SCI PCCP Polym. Chem.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1