错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Cybersecurity Needs and Benefits: The Four Rings Model

  • Dietmar P. F. Möller,
  • Roland E. Haas

摘要

The old form securing organizational data and business assets mostly depend on the background of fear, to become compromised or blackmailed. Today’s rapid advancements in technologies, and increasingly connected digital systems, resources, and environments have dramatically increased cybersecurity incidents. Therefore, cybersecurity is not just to avoid cybersecurity risk, it’s a new paradigm to rethink beyond threat events with a focus on how an organization can increase cybersecurity to keep its sensitive data and business assets secure. This requires knowledge in four distinct areas: deep cybersecurity awareness, cybersecurity vulnerability analysis, cybersecurity framework, and cybersecurity maturity model. All areas focus on gaining knowledge and pose significant research questions and methods of the interconnected chain of areas, called rings. However, the possibility of cyber-attacks is more likely obtaining access to internal digital systems performing malicious threat event attacks. Therefore, cybersecurity awareness becomes an integral part of connected digital systems and digital infrastructure resources, expressed by cybersecurity risk assessment and management. To perform a cybersecurity risk assessment, identification, analysis, and evaluation of vulnerabilities is required. Fundamental cybersecurity framework approaches, such as NIST cybersecurity framework and MITRE cybersecurity criteria, are security measures used to detect and prevent cybersecurity risk. Together with the essential concept of cybersecurity maturity levels, an approach is developed that helps to defend against sophisticated cybercriminal attacks. Finally, a practical example illustrates the effectiveness in the context of needs and benefits of the four rings model.