Examples of practical applications of the framework
| Prioritization question | Which type of data must be secured first? | What types of software threats must be prioritized first? | Which types of threat detection must be prioritized first | Which actions must be prioritized after breach? |
|---|---|---|---|---|
| Framework steps | ||||
| Determine the cybersecurity function | Protect/Prevention | Protect/Prevention | Detection | Recovery |
| Select the appropriate threat-modeling approach | CORAS (Asset-Driven Risk Modeling) | STRIDE | PASTA (Attack and Threat Modeling) | Integrated Data Breach Risk Model |
| Determine risk indicators and their weight | Decided based on the criteria and availability of data (firsthand data collection, secondary public or proprietary data) | |||
| Apply MCDM technique(s) and determine rankings | Apply choosing technique based on the attributes of indicators. Using additional techniques for robustness checks is highly recommended. See Toloie-Eshlaghy and Homayonfar (2011) for a comprehensive history of the methodology | |||
| Integrate findings with security risk planning | Risk Analysis | Risk Analysis | Alternative Generation | Planning Decisions |
| Prioritization question | Which type of data must be secured first? | What types of software threats must be prioritized first? | Which types of threat detection must be prioritized first | Which actions must be prioritized after breach? |
|---|---|---|---|---|
| Framework steps | ||||
| Determine the cybersecurity function | Protect/Prevention | Protect/Prevention | Detection | Recovery |
| Select the appropriate threat-modeling approach | CORAS (Asset-Driven Risk Modeling) | STRIDE | PASTA (Attack and Threat Modeling) | Integrated Data Breach Risk Model |
| Determine risk indicators and their weight | Decided based on the criteria and availability of data (firsthand data collection, secondary public or proprietary data) | |||
| Apply MCDM technique(s) and determine rankings | Apply choosing technique based on the attributes of indicators. Using additional techniques for robustness checks is highly recommended. See | |||
| Integrate findings with security risk planning | Risk Analysis | Risk Analysis | Alternative Generation | Planning Decisions |
Source(s): Table by authors
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.