On the Complexity of Cybersecurity Exercises Proportional to Preparedness

On the Complexity of Cybersecurity Exercises Proportional to Preparedness
复制标题

DOI:
10.20965/jdr.2017.p1081
复制
发表时间:
2017-10-01
影响因子:
0.8
通讯作者:
Watanabe, Kenji
Watanabe, Kenji
中科院分区:
其他
文献类型:
--
作者:
Aoyama, Tomomi;Nakano, Toshihiko;Watanabe, Kenji

文献摘要

被引文献

相似文献

本研究的目的是说明演习如何发挥推动力的作用,以提高组织的网络安全准备。各组织的网络安全准备程度差别很大。这意味着培训和演习必须针对具体能力。在本文中,我们回顾了美国国家标准与技术研究院(NIST)的网络安全框架,该框架正式确定了衡量准备程度的层次概念。随后,我们研究了文献中的演习类型,并提出了指导方针,指定特定的演习类型,目标和参与者的每个级别的准备。拟议的准则应有助于加强网络安全风险管理做法,减少资源滥用,并导致能力的顺利提高。
The purpose of this study is to illustrate how exercises can play the role of a driving power to improve an organization's cyber security preparedness. The degree of cyber security preparedness varies significantly among organizations. This implies that training and exercises must be tailored to specific capabilities. In this paper, we review the National Institute of Standards and Technology (NIST) cybersecurity framework that formalizes the concept of tier, which measures the degree of preparedness. Subsequently, we examine the types of exercises available in the literature and propose guidelines that assign specific exercise types, aims, and participants to each level of preparedness. The proposed guideline should facilitate the reinforcement of cybersecurity risk management practices, reduce resource misuse, and lead to a smooth improvement of capabilities.