错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

CCAF, Continuous Cyber Assurance Framework

  • Mohammad Tahir Chowdhory,
  • Hamid Jahankhani

摘要

This research proposes the Continuous Cyber Assurance Framework (CCAF) as a comprehensive and effective approach to continuously manage cyber security practices of third-party suppliers. Through an extensive literature review, case studies, and consultations with industry professionals, the CCAF has been developed and consists of six key phases. These phases include a total of 16 steps that are designed to ensure continuous cybersecurity assurance for third-party suppliers throughout their engagement. The framework highlights the importance of contract management, risk assessment and management, security controls and guidelines, incident management and response, compliance monitoring, and continuous improvement. In addition, a table-based step-by-step guide has been developed by the researcher, this is a practical tool for security professionals to apply the CCAF when working with third-party suppliers. CCAF’s effectiveness has been demonstrated through its application to a hypothetical scenario where Client G engages with Supplier Z for a project that includes cloud migration using AWS. The framework's application provides an effective means of managing third-party supplier cybersecurity by identifying potential risks, implementing appropriate security controls and guidelines, and monitoring compliance. The Continuous Cyber Assurance Framework has the potential to enhance third-party supplier cybersecurity by ensuring continuous cybersecurity assurance throughout the engagement period. Future work may involve exploring the use of smart contracts and blockchain technology in the framework to enhance security and efficiency.