Sažetak
Cybersecurity planning within a complex system and applying its principles and procedures aims to achieve system resilience in cyberspace, i.e. cyber resilience. The purpose of a complex system is to carry out a mission (task, mission) as a set of abilities and preferences concerning the internal and external circumstances of the system. Cyber resistance requires organizational, human, material, and financial resources to implement measures, activities, and procedures to reduce residual (remaining) security risk. This is part of the security risk that must be accepted within the system since risk assessment of internal and external circumstances is an opportunity to develop capabilities, and achieving its further reduction is impossible. The conceptual research presented in this paper analyzes ways and means to achieve cyber resistance in today's growing security risks. This research aims to create a new cyber resistance model, including cyber and information security. The context of the model consists of unrecognized security risks in cyberspace, and the conceptual modelling method is used to design the model. The model implies and encompasses the awareness of the existence of unknown system vulnerabilities and, at the same time, unknown cyber threats and attacks as possible consequences of the existence of unrecognizable vulnerabilities. This
also considers that the methods of separating previously unseen threats and attacks of the past day are unknown today in many business cases, as well as the methods of defence and possible responses to the same - unknown unknowns. To confront the challenges above, there is a need to create "knowledge about ignorance" of a complex system, i.e. for the development of cyber capabilities and their realization, based on the principles of cyber security and cyber defence.
Ključne riječi
attribution; cyber defense; cyber resilience; cyber security; conceptual model