Table 13

Examples of practical applications of the framework

Prioritization questionWhich type of data must be secured first?What types of software threats must be prioritized first?Which types of threat detection must be prioritized firstWhich actions must be prioritized after breach?
Framework steps
Determine the cybersecurity functionProtect/PreventionProtect/PreventionDetectionRecovery
Select the appropriate threat-modeling approachCORAS (Asset-Driven Risk Modeling)STRIDEPASTA (Attack and Threat Modeling)Integrated Data Breach Risk Model
Determine risk indicators and their weightDecided based on the criteria and availability of data (firsthand data collection, secondary public or proprietary data)
Apply MCDM technique(s) and determine rankingsApply choosing technique based on the attributes of indicators. Using additional techniques for robustness checks is highly recommended. See Toloie-Eshlaghy and Homayonfar (2011) for a comprehensive history of the methodology
Integrate findings with security risk planningRisk AnalysisRisk AnalysisAlternative GenerationPlanning Decisions

Source(s): Table by authors

or Create an Account

Close Modal
Close Modal