Cyber defense matrix

Ashutosh Dutta, Ehab S. Al-Shaer · 2019

Most enterprises aiming to deploy cost-effective security configuration follow information security standards and guidelines to adopt cybersecurity controls such as CIS Critical Security Controls (CIS CSC) [2]. With the increased dependency over cyber, the landscape of cyber attacks is escalating quickly, and as a consequence, hundreds of cybersecurity controls have to be delineated to implement NIST Cybersecurity Framework (i.e., identify, protect, detect, respond and recover) [6]. The security configuration comprised of the appropriate set of security controls requires not only to be optimized regarding Return on Investment (RoI) but also to be resilient in order to tackle the failures against diversified cyber attacks. However, the composition of such optimal and resilient cybersecurity portfolio (security configuration) is a highly complex and error-prone task as there are exponential numbers of ways to construct a portfolio due to a large number of security controls, threats, resource, and usability constraints.

Read the paper · More papers on PaperTik