Structuring the Chaos: Enabling Small Business Cyber-Security Risks & Assets Modelling with a UML Class Model
摘要
Small businesses around the world are increasingly adopting IT, thus increasing their exposure to malicious cyber activity. Small businesses struggle with implementing cyber-security, even when they are aware of the cyber-security risks around their business. Almost all modern cyber-security solutions are created and widely deployed in large enterprises. However there are fundamental differences between the characteristics of small businesses versus large ones. Small businesses often do not have the technical expertise or the time to implement currently available cyber-security tools and standards. At the same time, cyber-security competes with other roles that small business owners take on, e.g. cleaning, sales etc. Hence, cyber security tools specific to small businesses are needed. The most important task in cyber-security is knowing the assets that need protection, and their context. To support this information gathering phase of a small business’ cyber-security journey, we propose a new UML class (Small IT Data (SITD)) model. The SITD model is designed in the UML format to ensure that it is implementable at scale. The model’s structure stays relevant by using generic classes and structures that can evolve with technology and environmental changes. The SITD model keeps security decisions proportionate to the business by highlighting relationships between business strategy tasks and IT infrastructure. The SITD model’s simplified non-specialist terminology and its presentation encourages sustained participation by all stakeholders, not just technical ones. We start by constructing a set of design principles to address small business cyber-security needs. Model components are designed in response to these needs. The uses of the SITD model are then demonstrated and design principles validated by examining a case study of a real small business’s operational and IT information. The SITD model’s ability to illustrate breach information is also demonstrated using the NotPetya incident.