Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports

Cyber Third-Party Risk Management: A Comparison of Non-Intrusive Risk Scoring Reports
复制标题

DOI:
10.3390/electronics10101168
复制
发表时间:
2021-05
期刊:
影响因子:
2.9
通讯作者:
Omer F. Keskin;Kevin Matthe Caramancion;Irem Tatar;Owais Raza;Unal Tatar
Omer F. Keskin;Kevin Matthe Caramancion;Irem Tatar;Owais Raza;Unal Tatar
中科院分区:
工程技术3区
文献类型:
--
作者:
Omer F. Keskin;Kevin Matthe Caramancion;Irem Tatar;Owais Raza;Unal Tatar

文献摘要

被引文献

相似文献

在这个时代,网络安全是组织关注的问题。然而,加强组织内部网络的安全可能是不够的,因为现代组织依赖于第三方,而这些依赖可能会为网络犯罪分子开辟新的攻击路径。网络第三方风险管理(C-TPRM)在企业界是一个比较新的概念。所有供应商或合作伙伴都存在潜在的安全漏洞和威胁。即使组织拥有最佳的网络安全实践,其数据、客户和声誉也可能因为第三方而面临风险。组织寻求有效和高效的方法来评估其合作伙伴的网络安全风险。除了用于评估组织的网络安全风险的侵入性方法(如渗透测试)外,正在出现非侵入性方法,通过综合公开可用的信息来更容易地进行C-TPRM,而不需要被调查组织的任何参与。在本研究中,介绍和比较了不同公司建立的C-TPRM的现有方法,以找出常用的评估指标和标准。此外,还比较了评估特定组织的网络安全风险的不同方法的结果,以检查可靠性和一致性。结果表明,即使结果之间存在相似性,提供的安全分数也不完全收敛。
Cybersecurity is a concern for organizations in this era. However, strengthening the security of an organization’s internal network may not be sufficient since modern organizations depend on third parties, and these dependencies may open new attack paths to cybercriminals. Cyber Third-Party Risk Management (C-TPRM) is a relatively new concept in the business world. All vendors or partners possess a potential security vulnerability and threat. Even if an organization has the best cybersecurity practice, its data, customers, and reputation may be at risk because of a third party. Organizations seek effective and efficient methods to assess their partners’ cybersecurity risks. In addition to intrusive methods to assess an organization’s cybersecurity risks, such as penetration testing, non-intrusive methods are emerging to conduct C-TPRM more easily by synthesizing the publicly available information without requiring any involvement of the subject organization. In this study, the existing methods for C-TPRM built by different companies are presented and compared to discover the commonly used indicators and criteria for the assessments. Additionally, the results of different methods assessing the cybersecurity risks of a specific organization were compared to examine reliability and consistency. The results showed that even if there is a similarity among the results, the provided security scores do not entirely converge.