Supply Chain Cybersecurity: Security Controls with Maximum Cybersecurity Value
Tadeusz Sawik
Chapter Chapter 10 in Stochastic Programming in Supply Chain Risk Management, 2024, pp 323-346 from Springer
Abstract:
Abstract This chapter deals with optimization of cybersecurity investment in supply chains using stochastic programming approach. A classical exponential function of breach probability and the intuitive idea of the expected net benefits were applied to introduce the concept of cybersecurity value. The cybersecurity value of a security control is defined as the value gained by implementing a single control to secure a subset of components. The cybersecurity value of a control can be seen as a measure of its efficiency in reducing vulnerability of a secured system or component. A mixed binary optimization problem, next transformed into an unconstrained binary program, is developed to maximize total cybersecurity value of security control portfolio. The optimal solution to the binary program provides a simple formula to immediately obtain the portfolio of security controls with maximum total cybersecurity value and determine a rough-cut cybersecurity investment. This study also shows that portfolio of security controls with maximum total cybersecurity value reduces the losses from security breaches and mitigates the impact of cyber risk. The major decision-making insights are summarized at the end of this chapter.
Keywords: Supply chain cybersecurity; Rough-cut cybersecurity investment; Expected net benefits; Total cybersecurity value; Portfolio of security controls (search for similar items in EconPapers)
Date: 2024
References: Add references at CitEc
Citations:
There are no downloads for this item, see the EconPapers FAQ for hints about obtaining it.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:isochp:978-3-031-57927-1_10
Ordering information: This item can be ordered from
http://www.springer.com/9783031579271
DOI: 10.1007/978-3-031-57927-1_10
Access Statistics for this chapter
More chapters in International Series in Operations Research & Management Science from Springer
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().