Table 2

Summary of framework application

Framework stepApplication in this studySource
ObjectiveRisk Identification/DeterrenceNIST Cyber Framework, Core Function 1 (National Institute of Standards and Technology, 2018)
Security Action Cycle (Straub and Welke, 1998)
CriteriaCause of Breach
Locus of Breach
Impact of Breach
Integrated Risk Model (Khan et al., 2021)
IndicatorsCause
Hacking/IT Incident
Improper Disposal
Loss
Theft
Unauthorized Access/Disclosure
Locus:
Locations
Impact
PHI Stolen
Individuals Affected
U.S. Department of Health and Human Services Office for Civil Rights (2023) 
Indicator Weight DeterminationExperts’ OpinionBest-Worst Method (BWM)
Rezaei (2015) 
PrioritizationPrimary Analysis: Grey Analysis method
Robustness Checks: MABAC, MAIRCA, CoCoSo
Pamučar and Ćirović (2015), Pamučar et al. (2018), Wu (2009), Yazdani et al. (2019), Zhang et al. (2005) 
ApplicationRecognition of Security Problem or Need
Risk Analysis
Risk Planning Model (Goodhue and Straub, 1991)

Source(s): Table by authors

or Create an Account

Close Modal
Close Modal