Assessing prescriptive improvements to a system's cyber security and resilience

Scott Musman · 2016

In the process of creating new capabilities, and improving the efficiency of existing operational processes, as a society, we have become dependent on information and communications technology (ICT). ICT is now integral to almost every aspect of our daily activities. The detrimental impact of these ICT dependencies, however, is that business operations become susceptible to possible impacts from cyber incidents. Protecting ICT from cyber incident effects or reducing their impacts on operational activities has become a problem of national importance. Concomitantly, there is an escalating imperative to identify and minimize operational cyber risk. In almost all circumstances, we are interested in achieving operational resilience: the ability for systems to continue to fulfil their intended purpose in the face of actual or potential cyber incidents. Achieving such resilience almost always must be pursued in a resource limited environment, where there is a need to justify the costs and resources needed. Unfortunately most current definitions of resilience are qualitative ones. If resilience is defined in a qualitative rather than quantitative way there is little in the way of prescriptive advice that can be offered to increase resilience. To address this deficiency we use a quantitative definition of resilience and apply it in a game theory inspired approach that considers multiple cyber attacker moves ahead. This allows us to assess defender actions as a portfolio analysis to identify a prescriptive selection of the best employment of security and resilience methods to use.

Read the paper · More papers on PaperTik