inklap

QUANTITATIVE METHODOLOGY FOR ASSESSING CYBERSECURITY RISKS IN THE ABSENCE OF FINANCIAL DATA ON LOSSES

Oleksii Baidur · Cybersecurity: Education, Science, Technique · 2024

The article addresses the pressing issue of cybersecurity risk assessment in military information and communication systems (ICS) during aggressive warfare, where it is impossible to assess potential losses in monetary terms, and considering the specifics of hybrid threats. The introduction discusses the relevance of the problem and emphasizes the need for a proactive cyber defense strategy and timely risk assessment, especially in the context of the active use of cyberweapons by the adversary. Particular attention is given to the impossibility of assessing potential losses from cyberattacks in monetary terms, which necessitates new approaches to risk assessment. The section “Specifics of Cybersecurity Risk Assessment in the ICS of the Armed Forces of Ukraine” analyzes existing standards and methodologies, such as the standards of the DSTU ISO/IEC 27000 group, as well as current cybersecurity risk assessment methodologies, and reveals the limitations of their application in wartime conditions. The section emphasizes the importance of automating the risk assessment process to ensure a rapid response to cyber threats. The advantages of quantitative risk assessment models over qualita

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً