Urgency in Cybersecurity Risk Management: Toward a Solid Theory

Open Access
Authors
Publication date 2024
Book title 2024 IEEE 37th Computer Security Foundations Symposium
Book subtitle proceedings : 8-12 July 2024, Enschede, The Netherlands
ISBN
  • 9798350362046
ISBN (electronic)
  • 9798350362039
Series CSF
Event 2024 IEEE 37th Computer Security Foundations Symposium
Pages (from-to) 651-664
Number of pages 14
Publisher Los Alamitos, California: IEEE Computer Society
Organisations
  • Faculty of Science (FNWI) - Informatics Institute (IVI)
Abstract
IT systems are exposed to a rapidly changing landscape of serious security risks. Given the limited resources available to an organization, it is becoming more and more important to properly prioritize security risks, so that the organization can focus its efforts on the most critical risks. Traditionally, risks are assessed in terms of two aspects: occurrence probability and caused damage. However, for real-time risk prioritization, a third aspect is also of critical importance: urgency. Urgency stems from time-related considerations, such as the time needed by adversaries to exploit a vulnerability or the time needed for system administrators to put a countermeasure in place. These time-related considerations are orthogonal to the traditional aspects of occurrence probability and caused damage, and are largely ignored by existing risk management approaches. This paper proposes a way for introducing the notion of urgency into risk assessment. Our aim is to devise an intuitive approach for assessing risks, taking urgency into account, based on a solid theoretical underpinning. We establish a mathematical model using probability theory, and derive formulas for time-aware risk assessment in different settings.
Document type Conference contribution
Language English
Published at https://doi.org/10.1109/CSF61375.2024.00051
Downloads
Permalink to this page
Back