Extended IMECA Technique for Assessing Risks of Successful Cyberattacks
Olena Veprytska, Vyacheslav Serhiiovych Kharchenko · 2023
The research focuses on improving the IMECA risk-based method of cyber security analysis by detailing its elements that form “threat-vulnerability-attack-consequences-impact Of other attacks/On other attacks-criticality” and creating dependencies between the impact of attacks on each other, which are used in the risk calculations. The possibility of using quantitative and qualitative indicators to assess the risks of successful attacks is implemented, as well as the implementation of the “questionnaire” methodology for a more reasoned and accurate assessment of criticality and comparison of countermeasures. The proposed version of the extended IMECA reduces the influence of expert opinion in risk analysis.