Brazilian Integrated Cross-platform Security Assessment Framework: Context of Cybersecurity Methodology
摘要
Context is the circumstances set surrounding an event and encompasses all information about the analysis target, being a prerequisite for any assessment. The existing security assessment methodologies reinforce the importance of a context survey with quality. Its incorrect mapping can lead to false security feelings, and there is a lack of detailed methods for a proper context survey available in the market and the literature. In order to fill this gap, this paper presents the context of cybersecurity methodology (CoCs), which maps as much information as possible concerning the object under evaluation. This methodology will contribute to systems, products, services, processes, and organizations’ cyber protection improvement, circumventing attempted attacks, and ensuring business continuity. The future work is CoCs validation in case studies and the addition of a computational tool to support the methodology application, facilitating the execution by the security specialist and reducing the chance of errors. This method is part of the integrated cross-platform security assessment framework (ICpSAF), within the scope of the Brazilian TecSEG project.