Summary of framework application
| Framework step | Application in this study | Source |
|---|---|---|
| Objective | Risk Identification/Deterrence | NIST Cyber Framework, Core Function 1 (National Institute of Standards and Technology, 2018) Security Action Cycle (Straub and Welke, 1998) |
| Criteria | Cause of Breach Locus of Breach Impact of Breach | Integrated Risk Model (Khan et al., 2021) |
| Indicators | Cause Hacking/IT Incident Improper Disposal Loss Theft Unauthorized Access/Disclosure Locus: Locations Impact PHI Stolen Individuals Affected | U.S. Department of Health and Human Services Office for Civil Rights (2023) |
| Indicator Weight Determination | Experts’ Opinion | Best-Worst Method (BWM) Rezaei (2015) |
| Prioritization | Primary Analysis: Grey Analysis method Robustness Checks: MABAC, MAIRCA, CoCoSo | Pamučar and Ćirović (2015), Pamučar et al. (2018), Wu (2009), Yazdani et al. (2019), Zhang et al. (2005) |
| Application | Recognition of Security Problem or Need Risk Analysis | Risk Planning Model (Goodhue and Straub, 1991) |
| Framework step | Application in this study | Source |
|---|---|---|
| Objective | Risk Identification/Deterrence | NIST Cyber Framework, Core Function 1 ( |
| Criteria | Cause of Breach | Integrated Risk Model ( |
| Indicators | Cause | |
| Indicator Weight Determination | Experts’ Opinion | Best-Worst Method (BWM) |
| Prioritization | Primary Analysis: Grey Analysis method | |
| Application | Recognition of Security Problem or Need | Risk Planning Model ( |
Source(s): Table by authors
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.