Manufacturing is one of the 16 critical infrastructure sectors designated by the United States government. Manufacturing is known for complex integrated Information Systems (ISs) deeply embedded into production operations, such that disruptions to manufacturing companies can result in substantial financial losses and impacts across both economic and safety domains in society. Interconnectedness among companies within the manufacturing sector often leads to inherited cybersecurity vulnerabilities, in which exploits on an entity can cascade to others. Many of these ISs are procured and maintained by third-party entities, often called interconnected entities within the supply chain. Notable data breaches have originated from cyber-attacks on these third parties, causing significant business impacts by misusing sensitive company information. Consequently, the Theory of Cybersecurity Footprint formulates the core of this study, highlighting the relationship among interconnected entities and the potential ripple effects one organization can have on another, irrespective of size. To mitigate these risks, it is imperative to enhance cybersecurity practices to assess supply chain cybersecurity posture and manage the risks from lower-tier interconnected entities to the originating organization. The overarching aim of this study is to devise an index to measure the cyber posture of manufacturing organizations based on their interconnected entities. In this paper, we outline the results of the first phase with 30 Subject Matter Experts (SMEs) participated in a survey intended to determine the number of tiers to assess in the supply chain and establish the importance of the tiers, domains, and elements in evaluating an organization’s cyber posture. This research outlines measures aligned with the CMMC 2.0 Level 1 standards, presented within a hierarchical index structure and the resulting SME weights calculated for the domains and associated elements.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Subject Matter Experts’ Feedback on Cybersecurity Footprint Index Measures to Assess Organizational Cyber Posture of Manufacturing Companies

  • John Del Vecchio,
  • Yair Levy,
  • Ling Wang,
  • Ajoy Kumar

摘要

Manufacturing is one of the 16 critical infrastructure sectors designated by the United States government. Manufacturing is known for complex integrated Information Systems (ISs) deeply embedded into production operations, such that disruptions to manufacturing companies can result in substantial financial losses and impacts across both economic and safety domains in society. Interconnectedness among companies within the manufacturing sector often leads to inherited cybersecurity vulnerabilities, in which exploits on an entity can cascade to others. Many of these ISs are procured and maintained by third-party entities, often called interconnected entities within the supply chain. Notable data breaches have originated from cyber-attacks on these third parties, causing significant business impacts by misusing sensitive company information. Consequently, the Theory of Cybersecurity Footprint formulates the core of this study, highlighting the relationship among interconnected entities and the potential ripple effects one organization can have on another, irrespective of size. To mitigate these risks, it is imperative to enhance cybersecurity practices to assess supply chain cybersecurity posture and manage the risks from lower-tier interconnected entities to the originating organization. The overarching aim of this study is to devise an index to measure the cyber posture of manufacturing organizations based on their interconnected entities. In this paper, we outline the results of the first phase with 30 Subject Matter Experts (SMEs) participated in a survey intended to determine the number of tiers to assess in the supply chain and establish the importance of the tiers, domains, and elements in evaluating an organization’s cyber posture. This research outlines measures aligned with the CMMC 2.0 Level 1 standards, presented within a hierarchical index structure and the resulting SME weights calculated for the domains and associated elements.