A Socio-Technical Approach to Cyber Risk Assessment
Authors/Creators
- 1. City, University of London, Department of Computer Science, United Kingdom, EC1V 0HB and Gruppo Maggioli, Research & Development Lab, A. Papandreou 19, 151 24, Marousi, Greece
- 2. University of Piraeus, Department of Informatics, Karaoli and Dimitriou 80, Piraeus, 185 34 and FORTH external expert, Athens, Greece
Description
Evaluating the levels of cyber-security risks within an enterprise is most important in protecting its information system, services and all its digital assets against security incidents (e.g. accidents, malicious acts, massive cyber-attacks). The existing risk assessment methodologies (e.g. eBIOS, OCTAVE, CRAMM, NIST-800) adopt a technical approach considering as attack factors only the capability, intention and target of the attacker, and not paying attention to the attacker’s psychological profile and personality traits. In this paper, a socio-technical approach is proposed in cyber risk assessment, in order to achieve more realistic risk estimates by considering the personality traits of the attackers. In particular, based upon principles from investigative psychology and behavioural science, a multi-dimensional, extended, quantifiable model for an attacker’s profile is developed, which becomes an additional factor in the cyber risk level calculation.
Files
a-socio-technical-approach-to-cyber-risk-assessment.pdf
Files
(211.2 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:8a968fea343392784e492c76c5dfca0b
|
211.2 kB | Preview Download |