Return On Cyber Security Investment (ROCSI)
Return On Cyber Security Investment (ROCSI)
批准号:
ES/W005964/1
负责人:
Ying He
金额:
$30.41万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2022
资助国家:
英国
项目状态:
已结题
起止时间:
2022 至 --
中文摘要
为了实现商业价值,任何投资都必须是有选择性的,并专注于业务的高优先级领域。然而,董事会发现很难证明投资成本的合理性,并制定关于网络安全的投资回报率参数,因为他们无法充分理解和预测网络威胁的直接和间接影响。根本问题在于,缺乏透明的方式将网络威胁纳入董事会关于网络安全投资的决策。在投资决策中,组织需要确定威胁出现时的业务影响,计算直接成本(例如网络威胁缓解,网络保险费用)和间接成本(例如对系统性能的影响,股价下跌),以优化组织的安全防御能力。关键决策者是安全经理(如CISO)和董事会成员。然而,他们发现很难估计投资成本,并将其与获得的潜在利益或减轻的影响进行平衡,因为网络安全投资可以防止潜在损失,但可能不会直接产生收入。缺乏将网络威胁缓解与网络安全ROI联系起来的明确方法。由于不断变化的威胁形势和业务环境(例如,向系统添加设备或更改威胁缓解决策)而产生的不确定性,这一问题更加复杂。拟议的ROCSI旨在通过全面捕获来自多个威胁源的威胁数据并将其整合到网络安全投资决策流程中来应对这些挑战。ROCSI旨在提供威胁信息,用户定制和最新的决策支持,并随着新威胁数据的出现而不断更新。ROCSI将根据决策者对业务流程的排名,输出威胁缓解的ROI分析结果。该项目将通过结合多学科数据和人为因素,为董事会和战略层面的网络安全决策提供新方法的基础,以提高决策的透明度和质量。它将通过研究董事会和战略层面的威胁知情决策,为国家网络安全战略做出贡献,旨在提高组织的网络防御能力,提高组织的应变能力。它通过激励董事会和组织积极投资网络安全并采取积极的安全行为,解决了NCSC研究问题手册的主题“激励和行为”。拟议中的研究位于全球无障碍主题中,网络安全被列为优先事项。这个项目是在一个独特的位置,提供在研究社区和行业的基础上,PI的NCSC,RITICS,RISCS,创新英国,和PI的建立联系,谁将帮助塑造,评估和完善拟议的研究之前的参与的影响。该项目独特地受益于主办机构在人类决策(LUCID研究实验室)和行为科学(ESRC资助的NIBS)研究方面的良好记录,其与NCSC,GCHQ和DSTL以及Horizon DER研究所的合作关系,使研究成果得到最广泛的传播和利用。
英文摘要
To be of business value, any investment must be selective and focus on high priority areas of the business. However, boards find it difficult to justify the cost of investment and formulate ROI arguments on cyber security due to their inability to fully understand and anticipate the direct and indirect impact of cyber threats. The fundamental problem is the absence of transparent ways of integrating cyber threats into the boards' decisions about investment in cyber security. In an investment decision, organisations are required to determine business impact if the threats were to manifest, calculate the direct cost (e.g. cyber threat mitigations, cyber insurance charges) and indirect cost (e.g. impact on system performance, share price drop) to optimise the organisation's security defence capability. The key decision makers are security managers (e.g. CISO) and board members. However, they find it difficult to estimate the costs of investing and balancing these against potential benefits procured or impacts mitigated as the cyber security investments prevent potential losses but may not generate revenue directly. There is a lack of a clear way of linking cyber threat mitigations to the cyber security ROI. This is compounded by the uncertainties resulting from the changing threat landscape and business context (e.g. adding devices to the system or changing of threat mitigation decisions). The proposed ROCSI is designed to address these challenges by comprehensively capturing threat data from multiple threat sources and integrating it into the cyber security investment decision processes. The ROCSI aims to deliver threat-informed, user-tailored and up-to-date decision support which is continuously updated as new threat data becomes available. The ROCSI will output the ROI analysis on threat mitigations in response to the business processes ranked by decision makers.This project will deliver the foundations for a novel approach to cyber security decision making at the board and strategic level through combining multidisciplinary data and human factors to improve the transparency and quality of decision making. It will contribute to the national strategy on cyber security through the research of threat-informed decision making at the board and strategic level, with the aim of enhancing organisations' cyber defence capability and improve organisational resilience. It addresses the theme "Incentives and behaviours" of the NCSC Research Problem Book, through incentivising boards and organisations to proactively invest into cyber security and adopt positive security behaviours. The proposed research sits in the Global Uncertainties theme, where Cyber Security is listed as a priority. This project is in a unique position to deliver impact in both research communities and industries based on the PI's previous engagement with NCSC, RITICS, RISCS, Innovate UK, and the PI's established contacts who will help shape, evaluate and refine the proposed research. this project uniquely benefits from the host organisation's strong track record in human decision making (the LUCID research lab) and behaviour science (the ESRC funded NIBS) research, its partnership with NCSC, GCHQ, and Dstl and the Horizon DER Institute that enables the widest dissemination and exploitation of research outcomes.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
DOI:
10.2196/41748
发表时间:
2023-04-25
期刊:
JOURNAL OF MEDICAL INTERNET RESEARCH
影响因子:
7.4
作者:
[He, Ying, Zamani, Efpraxia, Yevseyeva, Iryna, Luo, Cunjin]
通讯作者:
Luo, Cunjin
Return On Cyber Security Investment (ROCSI)
-
批准号:ES/W005964/2
-
项目类别:Research Grant
-
资助金额:$25.38万
-
财政年份:2023
-
负责人:Ying He
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Cyber体系脆弱性仿真分析方法研究
-
批准号:61403400
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2014
-
负责人:许相莉
-
依托单位:
基于复杂网络理论的Cyber体系效能仿真分析方法研究
-
批准号:61374179
-
项目类别:面上项目
-
资助金额:77.0万元
-
批准年份:2013
-
负责人:胡晓峰
-
依托单位:
面向智能电网基础设施Cyber-Physical安全的自治愈基础理论研究
-
批准号:61300132
-
项目类别:青年科学基金项目
-
资助金额:23.0万元
-
批准年份:2013
-
负责人:王竹晓
-
依托单位:
Cyber攻击对国家关键基础设施级联失效影响建模仿真研究
-
批准号:61174035
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2011
-
负责人:贺筱媛
-
依托单位:
基于Cyber空间的体系脆弱性仿真分析方法研究
-
批准号:61174156
-
项目类别:面上项目
-
资助金额:59.0万元
-
批准年份:2011
-
负责人:胡晓峰
-
依托单位: