Analysis of Cyber Dependencies for Assessment of Cyber Resilience
摘要
Organizations depend on cyber systems and assets to deliver critical services and business functions. Moreover, modern cyber networks often rely on multiple computing assets or systems working together to meet organizational needs. While such cyber dependencies are critical to day-to-day functioning, they also introduce new attack vectors and avenues for cyber risks to propagate throughout a system. Given these complexities, it is critical for organizations to understand their cyber risks in the context of complex dependencies in order to better protect their cyber systems. Therefore, this chapter delineates different types of cyber dependencies and their associated risks, offering perspectives on best practices for assessing and managing these risks. Once cyber dependencies are identified, assessing their risk requires an understanding of four main components: (1) potential threats, (2) vulnerability to these threats, (3) system resilience to such threats, and (4) the consequences of system disruption. These conceptual needs are considered in differing degrees across a range of cyber risk assessment approaches such as pathway analysis and model checking. Such approaches are compared here with the goal of presenting decision-makers with a standardized approach of assessing cyber resilience in the presence of complex dependencies.