Building Cyber Resilience
摘要
Implementing cyber resilience into a system or company requires strategic decisions culminating in a resilience strategy. This strategy sets the direction and ensures that resilience activities are aligned with changes in technology, the business environment, the threat landscape, and the legal environment. It has a significant impact on system engineering, which is the starting topic of this chapter. Furthermore, essential principles for the trustworthy, secure design of systems based on NIST SP800-160 are discussed in the context of applicability and pitfalls. The chapter also provides an overview of resilience design and internal control systems. Finally, the chapter deals with how to gain a company culture, including cyber resilience awareness.