Mission assurance policy and risk management in cybersecurity
Hasan Cam () and
Pierre Mouallem ()
Additional contact information
Hasan Cam: U.S. Army Research Laboratory
Pierre Mouallem: U.S. Army Research Laboratory
Environment Systems and Decisions, 2013, vol. 33, issue 4, 500-507
Abstract:
Abstract Mission assurance policy and risk management are essential in enabling decision makers to ensure successful completion of missions by addressing the security status of cyber assets. This paper presents a novel mission assurance policy that adapts to the dynamic security status of all mission assets to quickly and automatically determine mission assurance level and to decide what changes are needed accordingly. The novelty of this mission assurance policy stems from using a time Petri net model for determining the security status of cyber assets, and then employing binary or multi-valued logic decision diagrams to assess the mission assurance level. The ability of a mission assurance policy to successfully complete its objectives depends mainly on whether a risk management scheme is provided to reduce risk to an acceptable level. To that end, this paper also describes a risk management scheme to systematically deal with the main factors of risk management such as the temporal interdependencies of cyber assets, impact of attacks, and risk mitigation. Given that the status of cyber assets changes due to the dynamic cybersecurity environment of asset vulnerabilities, threats, and recovery, the proposed mission assurance policy and risk management scheme enable decision makers to cope with the real-time assessment of mission assurance level.
Keywords: Cyber assets; Policy; Mission assurance; Risk management; Resilience; Decision diagrams; Time Petri net (search for similar items in EconPapers)
Date: 2013
References: View complete reference list from CitEc
Citations: View citations in EconPapers (1)
Downloads: (external link)
http://link.springer.com/10.1007/s10669-013-9468-z Abstract (text/html)
Access to the full text of the articles in this series is restricted.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:envsyd:v:33:y:2013:i:4:d:10.1007_s10669-013-9468-z
Ordering information: This journal article can be ordered from
https://www.springer.com/journal/10669
DOI: 10.1007/s10669-013-9468-z
Access Statistics for this article
More articles in Environment Systems and Decisions from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().