A CIS Controls V8.0 Scoring System using Combined Ranking-Weight Methods

Hayat Abdulla Asad Cue, Thirimachos Bourlai, Mark Lupo · 2024

Cybersecurity compliance assessments are crucial for many organizations’ cybersecurity risk management and cyber resilience development. While qualitative compliance aspects are always present in the assessment process, quantitative ones are not primarily being used. In addition, multiple studies have proposed methods for quantifying these assessments. Still, most of them are not directly applicable to target-rich, resource-poor organizations like public school systems, hospitals, small businesses, and government offices. On limited occasions, Rank-Weight methods have been applied to solve the cybersecurity criteria weighting problem, with limitations in terms of having to decide between the variants of those methods, along with criteria prioritization issues. To bridge this gap, we introduce a novel scoring system focusing on the latest version of the Center for Internet Security Critical Security Controls (CIS Controls). Our work integrates the Harmonic mean combination of Rank-Weight methods and a six-base safeguard implementation levels. The combination of methods presented in this paper and the proposed scoring system solution provides a quantitative-based approach to assess the cybersecurity posture in practical scenarios. The quantitative aspect of our proposed work contributes to stakeholders’ more accurate understanding of their security posture and the security criteria that must be prioritized for efficiently addressing cyber threat challenges. Moreover, because we are focusing on the CIS controls, which have been mapped to mitigation techniques that prevent the most common types of attacks, our approach is expected to be more realistic than the adaptation of other qualitative frameworks not directly linked to cyber threat empirical evidence.

Read the paper · More papers on PaperTik