Full Text

Turn on search term navigation

© 2021 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.

Abstract

Addressing cyber and privacy risks has never been more critical for organisations. While a number of risk assessment methodologies and software tools are available, it is most often the case that one must, at least, integrate them into a holistic approach that combines several appropriate risk sources as input to risk mitigation tools. In addition, cyber risk assessment primarily investigates cyber risks as the consequence of vulnerabilities and threats that threaten assets of the investigated infrastructure. In fact, cyber risk assessment is decoupled from privacy impact assessment, which aims to detect privacy-specific threats and assess the degree of compliance with data protection legislation. Furthermore, a Privacy Impact Assessment (PIA) is conducted in a proactive manner during the design phase of a system, combining processing activities and their inter-dependencies with assets, vulnerabilities, real-time threats and Personally Identifiable Information (PII) that may occur during the dynamic life-cycle of systems. In this paper, we propose a cyber and privacy risk management toolkit, called AMBIENT (Automated Cyber and Privacy Risk Management Toolkit) that addresses the above challenges by implementing and integrating three distinct software tools. AMBIENT not only assesses cyber and privacy risks in a thorough and automated manner but it also offers decision-support capabilities, to recommend optimal safeguards using the well-known repository of the Center for Internet Security (CIS) Controls. To the best of our knowledge, AMBIENT is the first toolkit in the academic literature that brings together the aforementioned capabilities. To demonstrate its use, we have created a case scenario based on information about cyber attacks we have received from a healthcare organisation, as a reference sector that faces critical cyber and privacy threats.

Details

Title
Automated Cyber and Privacy Risk Management Toolkit
Author
Gonzalez-Granadillo, Gustavo 1   VIAFID ORCID Logo  ; Menesidou, Sofia Anna 2   VIAFID ORCID Logo  ; Papamartzivanos, Dimitrios 2   VIAFID ORCID Logo  ; Romeu, Ramon 3 ; Navarro-Llobet, Diana 3   VIAFID ORCID Logo  ; Okoh, Caxton 4 ; Nifakos, Sokratis 5 ; Xenakis, Christos 6   VIAFID ORCID Logo  ; Panaousis, Emmanouil 4   VIAFID ORCID Logo 

 ATOS Spain, Atos Research & Innovation, Cybersecurity Unit, 08020 Barcelona, Spain 
 UBITECH Ltd., Thessalias 8 & Etolias 10, 152 31 Chalandri, Greece; [email protected] (S.A.M.); [email protected] (D.P.) 
 Fundació Privada Hospital Asil de Granollers, 08402 Granollers, Spain; [email protected] (R.R.); [email protected] (D.N.-L.) 
 School of Computing and Mathematical Sciences, University of Greenwich, London SE10 9LS, UK; [email protected] (C.O.); [email protected] (E.P.) 
 Karolinska Institutet Department of Learning, Informatics, Management and Ethics, Tomtebodavägen 18b, 171 77 Solna, Sweden; [email protected] 
 Department of Digital Systems, University of Piraeus, Karaoli ke Dimitriou 80, 185 34 Pireas, Greece; [email protected] 
First page
5493
Publication year
2021
Publication date
2021
Publisher
MDPI AG
e-ISSN
14248220
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
2565708103
Copyright
© 2021 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.