An Integrated Cybersecurity Risk Management (I-CSRM) Framework for Critical Infrastructure Protection

Authors
TypePhD Thesis
Abstract

Risk management plays a vital role in tackling cyber threats within the Cyber-Physical System (CPS) for overall system resilience. It enables identifying critical assets, vulnerabilities, and threats and determining suitable proactive control measures to tackle the risks. However, due to the increased complexity of the CPS, cyber-attacks nowadays are more sophisticated and less predictable, which makes risk management task more challenging. This research aims for an effective Cyber Security Risk Management (CSRM) practice using assets criticality, predication of risk types and evaluating the effectiveness of existing controls. We follow a number of techniques for the proposed unified approach including fuzzy set theory for the asset criticality, machine learning classifiers for the risk predication and Comprehensive Assessment Model (CAM) for evaluating the effectiveness of the existing controls.
The proposed approach considers relevant CSRM concepts such as threat actor attack pattern, Tactic, Technique and Procedure (TTP), controls and assets and maps these concepts with the VERIS community dataset (VCDB) features for the purpose of risk predication. Also, the tool serves as an additional component of the proposed framework that enables asset criticality, risk and control effectiveness calculation for a continuous risk assessment. Lastly, the thesis employs a case study to validate the proposed i-CSRM framework and i-CSRMT in terms of applicability. Stakeholder feedback is collected and evaluated using critical criteria such as ease of use, relevance, and usability. The analysis results illustrate the validity and acceptability of both the framework and tool for an effective risk management practice within a real-world environment.
The experimental results reveal that using the fuzzy set theory in assessing assets' criticality, supports stakeholder for an effective risk management practice. Furthermore, the results have demonstrated the machine learning classifiers’ have shown exemplary performance in predicting different risk types including denial of service, cyber espionage, and Crimeware. An accurate prediction can help organisations model uncertainty with machine learning classifiers, detect frequent cyber-attacks, affected assets, risk types, and employ the necessary corrective actions for its mitigations.
Lastly, to evaluate the effectiveness of the existing controls, the CAM approach is used, and the result shows that some controls such as network intrusion, authentication, and anti-virus show high efficacy in controlling or reducing risks. Evaluating control effectiveness helps organisations to know how effective the controls are in reducing or preventing any form of risk before an attack occurs. Also, organisations can implement new controls earlier. The main advantage of using the CAM approach is that the parameters used are objective, consistent and applicable to CPS.

Year2021
PublisherUniversity of East London
Digital Object Identifier (DOI)
File 2021_PhD_Kure.pdf
Publication dates
05 Oct 2021
Publication process dates
01 Mar 2021
05 Oct 2021

https://repository.uel.ac.uk/item/89ww3

Log in to edit

Download files

2021_PhD_Kure.pdf
License: CC BY-NC-ND 4.0
File access level: Anyone

Related outputs

risk management framework thesis

Asset Criticality and Risk Prediction for an Effective Cyber Security Risk Management of Cyber Physical System

risk management framework thesis

Assets focus risk management framework for critical infrastructure cybersecurity risk management

risk management framework thesis

Cyber Threat Intelligence for Improving Cybersecurity and Risk Management in Critical Infrastructure

Bond University Research Portal Logo

  • Help & FAQ

Data-driven operational risk management: an improved understanding of the effect of causal factors

  • Nikki Cornwell
  • Bond Business School

Student thesis : Doctoral Thesis

Date of Award5 Oct 2023
Original languageEnglish
SponsorsKPMG
Supervisor (Supervisor), (Supervisor), (Supervisor) & Bruce Vanstone (Supervisor)

File : application/pdf, 5.76 MB

Type : Thesis

Embargo End Date : 2 Sept 2024

  • Bibliography
  • More Referencing guides Blog Automated transliteration Relevant bibliographies by topics
  • Automated transliteration
  • Relevant bibliographies by topics
  • Referencing guides

Risk management in banks: determination of practices and relationship with performance

Thumbnail

Description

Collections.

The following license files are associated with this item:

entitlement

Export search results

The export option will allow you to export the current search results of the entered query to a file. Different formats are available for download. To export the items, click on the button corresponding with the preferred download format.

By default, clicking on the export buttons will result in a download of the allowed maximum amount of items.

To select a subset of the search results, click "Selective Export" button and make a selection of the items you want to export. The amount of items that can be exported at once is similarly restricted as the full export.

After making a selection, click one of the export format buttons. The amount of items that will be exported is indicated in the bubble next to export format.

IMAGES

  1. Risk Management Framework

    risk management framework thesis

  2. The Risk Management Framework

    risk management framework thesis

  3. (3) Risk Management Framework Explained with Example visit for Complete

    risk management framework thesis

  4. (PDF) Risk Management Framework (Chapter-4) 2022 COSO, ISO 31000, RISK

    risk management framework thesis

  5. Risk Management Thesis

    risk management framework thesis

  6. Risk Management Framework

    risk management framework thesis

VIDEO

  1. RSA Conference 2011

  2. Master's in Systemic Risk

  3. Scaling B2C Lending

  4. Project Risk Analysis: Introduction to Project Risk Mitigation and Risk Response Planning

  5. Introduction to Risk Management Framework

  6. Introduction to Risk Management

COMMENTS

  1. PDF Master Thesis Enterprise Risk Management: the effect on internal ...

    tle attention has been devoted to the effects of ERM on internal control quality. ERM and internal control are inherently connected, as ERM is comm. nly built upon and strengthens the internal control framework (COSO, 1992, 2004). Risk management, in general, involves identifying a firm's threats and opportunities and.

  2. A Risk Management Framework Using Digital Transformation for the

    A Risk Management Framework Using Digital Transformation for the ...

  3. Enterprise Risk Management Strategies for Organizational Sustainability

    This Dissertation is brought to you for free and open access by the Walden Dissertations and Doctoral Studies Collection at ScholarWorks. It has been accepted for inclusion in Walden Dissertations and Doctoral Studies by an ... enterprise risk management framework (COSO, 2017). Published in 2004, and updated in . 2017): and. risk. the ,

  4. PDF Framework for Risk Management in Project Management

    tute 2023.)2.1.3 PRINCE2 Risk Management FrameworkPRINCE2, an acronym for Projects IN Controlled Environments, is a widely recognized project manage. ent framework known for its structured methodology. PRINCE2's holistic approach to project management has a comprehensive risk manage.

  5. PDF Risk Management Practices in a Construction Project a case study

    Department of Civil and Environmental Engineering Division of Construction Management. Chalmers University of Technology SE-412 96 Göteborg Sweden Telephone: + 46 (0)31-772 1000. Sweden 2011. Risk Management Practices in a Construction Project - a case study. Master of Science Thesis in the Master's Programme. EWELINA GAJEWSKA MIKAELA ROPEL.

  6. PDF Enterprise Risk Management: Development of Strategic Erm Alignment

    A Thesis submitted for the degree of Doctor of Philosophy By Mishal Alajmi Brunel University London 2018. 2 ... Accordingly, this research aims into developing an Enterprise Risk Management (ERM) framework aligned with organizational strategies and objectives that is

  7. PDF Applying effective risk management into project management

    The scope of this thesis was applying ISO31000 risk management standard and COSO ERM based risk management framework into project management at the case organization. Exclusions in this thesis were risk analysis (risk assessment tools & techniques, risk criteria) and reporting principles. These will be defined by the case organization.

  8. An Integrated Cybersecurity Risk Management (I-CSRM) Framework for

    Also, the tool serves as an additional component of the proposed framework that enables asset criticality, risk and control effectiveness calculation for a continuous risk assessment. Lastly, the thesis employs a case study to validate the proposed i-CSRM framework and i-CSRMT in terms of applicability.

  9. (PDF) Enterprise Risk Management: A Literature Review and Agenda for

    The purpose of. the paper is to perform a literature review of the empirical evidence on ERM and to propose futur e. research directions. In line with Tranfield et al.2003) and Prasad et al.2018 ...

  10. Data-driven operational risk management: an improved understanding of

    This thesis makes four main contributions in this regard. First, the field of research applying data analytics to ORM across various industries is systematically reviewed. ... With causal factors analysis (CFA) emerging as a key area within the literature, as well as foundational to risk management theory, the focus of the thesis shifts toward ...

  11. The performativity of risk management frameworks and technologies: The

    This article examines the long-term dynamics among a best-practice risk management framework, risk management technologies and the translation of uncertainties into risks by using a longitudinal case study of a large mega-project. ... Our study is informed by Michel Callon's performativity thesis (Callon, 1998c, Callon, 2007, Callon et al ...

  12. Dissertations / Theses on the topic 'Enterprise Risk Management'

    The main contribution of this thesis is to assess airline risk management systems, identify core drivers of effective risk management practice, and provide a framework with the aim of guiding airlines in the development of enterprise-wide risk management approaches aligned with the requirements of their institutional and technical contexts.

  13. Effective Risk Management Strategies for Information Technology Project

    more than 8 years of IT project management experience with a risk management success rate of 70%. Data were analyzed using thematic analysis through 4 steps including data transcription, data organization, data coding, and data validation. The data analysis revealed 4 major themes: risk management culture, risk management framework, risk ...

  14. PDF MASTER'S THESIS

    2.1.3 NIST SP 800-39 And the Multi-Tiered Risk Management NIST 800-39 suggest a Multi-Tiered risk management model. 800-39 covers almost all three tiers but it is more focused on Tier 1 and Tier 2. NIST SP 800-37 will focus more on Risk management framework at the system level (Tier 3).

  15. PDF Approaches to risk management in international projects: A ...

    The system evolves based on experiences and best practice, as well as developments in the field of risk and project management. This comparative case study seeks to discern differences and similarities in approaches to risk management in two of Multiconsult's projects abroad.

  16. PDF Enterprise Risk Management in the Airline Industry

    Enterprise Risk Management in the Airline Industry

  17. PDF MASTER'S THESIS

    Risk Management / Offshore Technical Safety Spring/ Autumn semester, 2020 Open / Confidential Author: Leandro José Gutierrez Useche Program coordinator: Roger Flage Supervisor(s): Roger Flage Title of master's thesis: An empirical evaluation of risk assessment practices from a risk consistency perspective Credits: 30 SP Keywords: Risk ...

  18. PDF Risk Mitigation in Project Management: Case Horizon 2020

    research first overviews literature on risks and risk management in general and introduces the methods used in risk management activities. The aim is to get an overall view of possible risk areas, risk management processes and risk mitiga-tion actions. The definition of a Horizon 2020 project is also presented.

  19. (PDF) Risk assessment and risk management: Review of ...

    Risk assessment and management was established as a scientific field some 30-40 years ago. Principles. and methods were developed for how to conceptualise, assess and manage risk. These ...

  20. Dissertations / Theses on the topic 'Risk management'

    The goal of this Thesis is to create a framework for review of risk management process and to practically apply it in a case study. Objectives of the theoretical parts are: stating the reasons for risk management in non-financial companies, addressing the main parts of risk management and providing guidance for review of risk management process ...

  21. PDF Entreprise risk management and firm performance: the case of Casablanca

    The criteria for measuring firm performance were based essentially on Florio & Leoni's article: Enterprise risk management and firm performance: The Italian Case (Florio & Leoni, 2017). The Moroccan stock exchange, like the Italian one, failed in becoming a steady source of generating profit for the country.

  22. PDF SUPPLY CHAIN RISK MANAGEMENT

    use of risk management is still far from the ideal. That happens for several reasons, as will be detailed later in this paper. Supply chain risk management (SCRM) involves risk identification, risk assessment, risk mitigation, and risk control. This thesis will explain each of these steps and why they are so important on the decision-making ...

  23. Dissertations / Theses: 'Operational risk management'

    Thesis (Ph.D. (Risk management))--North-West University, Potchefstroom Campus, 2012. ... In addition, a separate head office operational risk function has emerged, responsible for developing the operational risk management framework, consolidating information, consulting with the business units, and monitoring the enterprise-wide effectiveness ...

  24. Risk management in banks: determination of practices and ...

    The issue of risk management in banks has become the centre of debate after the recent financial crises. Several efforts have been made to improve the risk management and performance of banks including introducing the Basel Accords as well as risk management guidelines by central banks. Consequently, the State Bank of Pakistan has issued risk ...