<p>The increasing frequency of cyber threats poses substantial challenges for organizations in both the private and public sectors. This systematic literature review evaluates and categorizes current cyber risk assessment methodologies and frameworks, supporting the selection of suitable approaches for practical and academic applications. Utilizing the PRISMA framework, 712 relevant studies were filtered from an initial pool of 1900 academic publications and subsequently analyzed and organized into a structured database, providing an overview of the advantages and limitations of widely cited approaches in this domain. The findings indicate a strong preference for established risk management frameworks, including the ISO 27000 family, OCTAVE, and NIST Special Publications, as well as mathematical approaches such as Bayesian networks, fuzzy logic, and multi-criteria decision-making techniques. The 217 approaches identified were grouped into two primary categories: <i>Standards, Frameworks, and Guidelines</i> and <i>Risk Assessment Methods</i>, with further classification by the application sectors addressed in the literature. Analysis suggests that no single approach offers universal applicability. The choice of methodology should therefore be informed by an organization’s specific resources, size, and sectoral requirements. A cross-analysis of methods and sectors reveals gaps in sector-specific coverage, particularly for healthcare, finance, and small and medium-sized enterprises. The review identifies a trend toward hybrid approaches that combine organizational frameworks with quantitative methods and documents persistent barriers to adoption, including cost, data scarcity, and insufficient management engagement. Based on these findings, a conceptual framework is developed to evaluate approaches across five dimensions and to derive a typology of governance-oriented, quantitative, and hybrid methods. Implications for practitioners, regulators, and researchers are discussed in relation to current regulatory frameworks, including the NIS-2 Directive and the Digital Operational Resilience Act (DORA).</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Bridging the gaps in cyber risk assessment: a comprehensive systematic review of standards, frameworks and quantification methods

  • Phillip Sampson,
  • Barry Sheehan,
  • Darren Shannon,
  • Anna Cartwright,
  • Jacob Seifert,
  • Edward Cartwright,
  • Tom Meurs

摘要

The increasing frequency of cyber threats poses substantial challenges for organizations in both the private and public sectors. This systematic literature review evaluates and categorizes current cyber risk assessment methodologies and frameworks, supporting the selection of suitable approaches for practical and academic applications. Utilizing the PRISMA framework, 712 relevant studies were filtered from an initial pool of 1900 academic publications and subsequently analyzed and organized into a structured database, providing an overview of the advantages and limitations of widely cited approaches in this domain. The findings indicate a strong preference for established risk management frameworks, including the ISO 27000 family, OCTAVE, and NIST Special Publications, as well as mathematical approaches such as Bayesian networks, fuzzy logic, and multi-criteria decision-making techniques. The 217 approaches identified were grouped into two primary categories: Standards, Frameworks, and Guidelines and Risk Assessment Methods, with further classification by the application sectors addressed in the literature. Analysis suggests that no single approach offers universal applicability. The choice of methodology should therefore be informed by an organization’s specific resources, size, and sectoral requirements. A cross-analysis of methods and sectors reveals gaps in sector-specific coverage, particularly for healthcare, finance, and small and medium-sized enterprises. The review identifies a trend toward hybrid approaches that combine organizational frameworks with quantitative methods and documents persistent barriers to adoption, including cost, data scarcity, and insufficient management engagement. Based on these findings, a conceptual framework is developed to evaluate approaches across five dimensions and to derive a typology of governance-oriented, quantitative, and hybrid methods. Implications for practitioners, regulators, and researchers are discussed in relation to current regulatory frameworks, including the NIS-2 Directive and the Digital Operational Resilience Act (DORA).