Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review
Traditional information security risk assessment (RA) methodologies and standards, adopted by information security management systems and frameworks as a foundation stone towards robust environments, face many difficulties in modern environments where the threat landscape changes rapidly and new vul...
Main Authors: | , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2023-09-01
|
Series: | Future Internet |
Subjects: | |
Online Access: | https://www.mdpi.com/1999-5903/15/10/324 |
_version_ | 1827761556773928960 |
---|---|
author | Pavlos Cheimonidis Konstantinos Rantos |
author_facet | Pavlos Cheimonidis Konstantinos Rantos |
author_sort | Pavlos Cheimonidis |
collection | DOAJ |
description | Traditional information security risk assessment (RA) methodologies and standards, adopted by information security management systems and frameworks as a foundation stone towards robust environments, face many difficulties in modern environments where the threat landscape changes rapidly and new vulnerabilities are being discovered. In order to overcome this problem, dynamic risk assessment (DRA) models have been proposed to continuously and dynamically assess risks to organisational operations in (near) real time. The aim of this work is to analyse the current state of DRA models that have been proposed for cybersecurity, through a systematic literature review. The screening process led us to study 50 DRA models, categorised based on the respective primary analysis methods they used. The study provides insights into the key characteristics of these models, including the maturity level of the examined models, the domain or application area in which these models flourish, and the information they utilise in order to produce results. The aim of this work is to answer critical research questions regarding the development of dynamic risk assessment methodologies and provide insights on the already developed methods as well as future research directions. |
first_indexed | 2024-03-11T10:14:36Z |
format | Article |
id | doaj.art-41b4dd1ff01e443d9d54e055bac2ae22 |
institution | Directory Open Access Journal |
issn | 1999-5903 |
language | English |
last_indexed | 2024-03-11T10:14:36Z |
publishDate | 2023-09-01 |
publisher | MDPI AG |
record_format | Article |
series | Future Internet |
spelling | doaj.art-41b4dd1ff01e443d9d54e055bac2ae222023-11-16T10:28:25ZengMDPI AGFuture Internet1999-59032023-09-01151032410.3390/fi15100324Dynamic Risk Assessment in Cybersecurity: A Systematic Literature ReviewPavlos Cheimonidis0Konstantinos Rantos1Department of Computer Science, International Hellenic University, 654 04 Kavala, GreeceDepartment of Computer Science, International Hellenic University, 654 04 Kavala, GreeceTraditional information security risk assessment (RA) methodologies and standards, adopted by information security management systems and frameworks as a foundation stone towards robust environments, face many difficulties in modern environments where the threat landscape changes rapidly and new vulnerabilities are being discovered. In order to overcome this problem, dynamic risk assessment (DRA) models have been proposed to continuously and dynamically assess risks to organisational operations in (near) real time. The aim of this work is to analyse the current state of DRA models that have been proposed for cybersecurity, through a systematic literature review. The screening process led us to study 50 DRA models, categorised based on the respective primary analysis methods they used. The study provides insights into the key characteristics of these models, including the maturity level of the examined models, the domain or application area in which these models flourish, and the information they utilise in order to produce results. The aim of this work is to answer critical research questions regarding the development of dynamic risk assessment methodologies and provide insights on the already developed methods as well as future research directions.https://www.mdpi.com/1999-5903/15/10/324cybersecuritydynamic risk assessmentmachine-learningquantitative risk assessment |
spellingShingle | Pavlos Cheimonidis Konstantinos Rantos Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review Future Internet cybersecurity dynamic risk assessment machine-learning quantitative risk assessment |
title | Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review |
title_full | Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review |
title_fullStr | Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review |
title_full_unstemmed | Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review |
title_short | Dynamic Risk Assessment in Cybersecurity: A Systematic Literature Review |
title_sort | dynamic risk assessment in cybersecurity a systematic literature review |
topic | cybersecurity dynamic risk assessment machine-learning quantitative risk assessment |
url | https://www.mdpi.com/1999-5903/15/10/324 |
work_keys_str_mv | AT pavloscheimonidis dynamicriskassessmentincybersecurityasystematicliteraturereview AT konstantinosrantos dynamicriskassessmentincybersecurityasystematicliteraturereview |