Developing cyber-resistivity maturity and scoring framework (CRMSF) for any size of organization
摘要
Cybersecurity is essential for organizations of all sizes, as cyber threats can jeopardize their data, operations, reputation, and competitiveness. Consequently, a one-size-fits-all cybersecurity framework, especially one based solely on maturity levels, is neither practical nor effective, as acknowledged in recent literature critiquing universal maturity models (Liyanage et al. in Sok: identifying limitations and bridging gaps of cybersecurity capability maturity models (ccmms). arXiv preprint arXiv:240816140, https://arxiv.org/abs/2408.16140, 2024). Instead, organizations require a scalable and adaptive framework that allows them to assess their current cybersecurity posture, identify gaps and risks, and implement targeted measures to enhance their cybersecurity maturity in a timely and practical manner. Maintaining continuous awareness of their cybersecurity status and understanding the degree of necessary improvement is critical. In response to these challenges and to address the limitations of existing capability models and frameworks, this paper proposes a novel framework, the Cyber-Resistivity Maturity and Scoring Framework (CRMSF). It emphasizes distinct capability evaluation attributes, including the use of weight factors, criticality and complexity analysis, benchmarking, and maturity levels.