论文标题

组织如何寻求网络保证?关于采用共同标准及以后的调查

How Do Organizations Seek Cyber Assurance? Investigations on the Adoption of the Common Criteria and Beyond

论文作者

Sun, Nan, Li, Chang-Tsun, Chan, Hin, Islam, Md Zahidul, Islam, Md Rafiqul, Armstrong, Warren

论文摘要

网络保证是在网络攻击和其他意外事件袭击下运作的能力,对于每天面临淹没安全威胁的组织至关重要。组织通常采用多种策略来进行风险管理以实现网络保证。利用网络安全标准和认证可以为供应商提供指导,以设计和制造安全的信息和通信技术(ICT)产品,并为消费者提供对产品安全功能的保证。因此,采用安全标准和认证是风险管理和网络保证的有效策略。在这项工作中,我们首先通过调查来自各个国家和部门的组织的258名参与者来调查通过网络安全标准和认证的采用。具体来说,我们通过设计的问卷确定了常见标准的采用障碍。考虑到确定的七个采用障碍,我们展示了促进网络安全标准和认证的建议。此外,除了网络安全标准和认证之外,我们还阐明了参与者设计的其他风险管理策略,该策略提供了有关增强组织中网络保证的网络安全方法的指示。

Cyber assurance, which is the ability to operate under the onslaught of cyber attacks and other unexpected events, is essential for organizations facing inundating security threats on a daily basis. Organizations usually employ multiple strategies to conduct risk management to achieve cyber assurance. Utilizing cybersecurity standards and certifications can provide guidance for vendors to design and manufacture secure Information and Communication Technology (ICT) products as well as provide a level of assurance of the security functionality of the products for consumers. Hence, employing security standards and certifications is an effective strategy for risk management and cyber assurance. In this work, we begin with investigating the adoption of cybersecurity standards and certifications by surveying 258 participants from organizations across various countries and sectors. Specifically, we identify adoption barriers of the Common Criteria through the designed questionnaire. Taking into account the seven identified adoption barriers, we show the recommendations for promoting cybersecurity standards and certifications. Moreover, beyond cybersecurity standards and certifications, we shed light on other risk management strategies devised by our participants, which provides directions on cybersecurity approaches for enhancing cyber assurance in organizations.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源