Tehničko veleučilište u Zagrebu · Zagreb

Cybersecurity and Cyber Defense Insights: The Complementary Conceptual Model of Cyber Resilience

sažetak izlaganja sa skupa

sažetak izlaganja sa skupa

Cybersecurity and Cyber Defense Insights: The Complementary Conceptual Model of Cyber Resilience

Vrsta prilog sa skupa (u zborniku)
Tip sažetak izlaganja sa skupa
Godina 2023
Nadređena publikacija Book of abstracts of the ENTRENOVA – Enterprise Research Innovation Conference 2023
Stranice str. 31-31
DOI https://doi.org/10.54820/entrenova-2023-0001
ISSN 2806-612X
Status objavljeno

Sažetak

Cybersecurity planning within a complex system and applying its principles and procedures aims to achieve system resilience in cyberspace, i.e. cyber resilience. The purpose of a complex system is to carry out a mission (task, mission) as a set of abilities and preferences concerning the internal and external circumstances of the system. Cyber resistance requires organizational, human, material, and financial resources to implement measures, activities, and procedures to reduce residual (remaining) security risk. This is part of the security risk that must be accepted within the system since risk assessment of internal and external circumstances is an opportunity to develop capabilities, and achieving its further reduction is impossible. The conceptual research presented in this paper analyzes ways and means to achieve cyber resistance in today's growing security risks. This research aims to create a new cyber resistance model, including cyber and information security. The context of the model consists of unrecognized security risks in cyberspace, and the conceptual modelling method is used to design the model. The model implies and encompasses the awareness of the existence of unknown system vulnerabilities and, at the same time, unknown cyber threats and attacks as possible consequences of the existence of unrecognizable vulnerabilities. This
also considers that the methods of separating previously unseen threats and attacks of the past day are unknown today in many business cases, as well as the methods of defence and possible responses to the same - unknown unknowns. To confront the challenges above, there is a need to create "knowledge about ignorance" of a complex system, i.e. for the development of cyber capabilities and their realization, based on the principles of cyber security and cyber defence.

Ključne riječi

attribution; cyber defense; cyber resilience; cyber security; conceptual model