Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review

Traditional information security risk assessment (RA) methodologies and standards, adopted by information security management systems and frameworks as a foundation stone towards robust environments, face many difficulties in modern environments where the threat landscape changes rapidly and new vul...

Full description

Bibliographic Details
Main Authors: Pavlos Cheimonidis, Konstantinos Rantos
Format: Article
Language:English
Published: MDPI AG 2023-09-01
Series:Future Internet
Subjects:
Online Access:https://www.mdpi.com/1999-5903/15/10/324
_version_ 1827761556773928960
author Pavlos Cheimonidis
Konstantinos Rantos
author_facet Pavlos Cheimonidis
Konstantinos Rantos
author_sort Pavlos Cheimonidis
collection DOAJ
description Traditional information security risk assessment (RA) methodologies and standards, adopted by information security management systems and frameworks as a foundation stone towards robust environments, face many difficulties in modern environments where the threat landscape changes rapidly and new vulnerabilities are being discovered. In order to overcome this problem, dynamic risk assessment (DRA) models have been proposed to continuously and dynamically assess risks to organisational operations in (near) real time. The aim of this work is to analyse the current state of DRA models that have been proposed for cybersecurity, through a systematic literature review. The screening process led us to study 50 DRA models, categorised based on the respective primary analysis methods they used. The study provides insights into the key characteristics of these models, including the maturity level of the examined models, the domain or application area in which these models flourish, and the information they utilise in order to produce results. The aim of this work is to answer critical research questions regarding the development of dynamic risk assessment methodologies and provide insights on the already developed methods as well as future research directions.
first_indexed 2024-03-11T10:14:36Z
format Article
id doaj.art-41b4dd1ff01e443d9d54e055bac2ae22
institution Directory Open Access Journal
issn 1999-5903
language English
last_indexed 2024-03-11T10:14:36Z
publishDate 2023-09-01
publisher MDPI AG
record_format Article
series Future Internet
spelling doaj.art-41b4dd1ff01e443d9d54e055bac2ae222023-11-16T10:28:25ZengMDPI AGFuture Internet1999-59032023-09-01151032410.3390/fi15100324Dynamic Risk Assessment in Cybersecurity: A Systematic Literature ReviewPavlos Cheimonidis0Konstantinos Rantos1Department of Computer Science, International Hellenic University, 654 04 Kavala, GreeceDepartment of Computer Science, International Hellenic University, 654 04 Kavala, GreeceTraditional information security risk assessment (RA) methodologies and standards, adopted by information security management systems and frameworks as a foundation stone towards robust environments, face many difficulties in modern environments where the threat landscape changes rapidly and new vulnerabilities are being discovered. In order to overcome this problem, dynamic risk assessment (DRA) models have been proposed to continuously and dynamically assess risks to organisational operations in (near) real time. The aim of this work is to analyse the current state of DRA models that have been proposed for cybersecurity, through a systematic literature review. The screening process led us to study 50 DRA models, categorised based on the respective primary analysis methods they used. The study provides insights into the key characteristics of these models, including the maturity level of the examined models, the domain or application area in which these models flourish, and the information they utilise in order to produce results. The aim of this work is to answer critical research questions regarding the development of dynamic risk assessment methodologies and provide insights on the already developed methods as well as future research directions.https://www.mdpi.com/1999-5903/15/10/324cybersecuritydynamic risk assessmentmachine-learningquantitative risk assessment
spellingShingle Pavlos Cheimonidis
Konstantinos Rantos
Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
Future Internet
cybersecurity
dynamic risk assessment
machine-learning
quantitative risk assessment
title Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
title_full Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
title_fullStr Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
title_full_unstemmed Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
title_short Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
title_sort dynamic risk assessment in cybersecurity a systematic literature review
topic cybersecurity
dynamic risk assessment
machine-learning
quantitative risk assessment
url https://www.mdpi.com/1999-5903/15/10/324
work_keys_str_mv AT pavloscheimonidis dynamicriskassessmentincybersecurityasystematicliteraturereview
AT konstantinosrantos dynamicriskassessmentincybersecurityasystematicliteraturereview