Information security risk assessment using situational awareness frameworks and application tools

This paper describes the development of situational awareness models and applications to assess cybersecurity risks based on Annex ISO 27001:2013. The risk assessment method used is the direct testing method, namely audit, exercise and penetration testing. The risk assessment of this study is classi...

Full description

Saved in:
Bibliographic Details
Main Authors: Chandra, Nungky Awang, Ramli, Kalamullah, Ratna, Anak Agung Putri, Gunawan, Teddy Surya
Format: Article
Language:English
English
Published: Multidisciplinary Digital Publishing Institute (MDPI) 2022
Subjects:
Online Access:http://irep.iium.edu.my/100338/7/100338_Information%20security%20risk%20assessment%20using%20situational%20awareness_SCOPUS.pdf
http://irep.iium.edu.my/100338/8/100338_Information%20security%20risk%20assessment%20using%20situational%20awareness.pdf
http://irep.iium.edu.my/100338/
https://www.mdpi.com/journal/risks
https://doi.org/10.3390/risks10080165
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Universiti Islam Antarabangsa Malaysia
Language: English
English
Description
Summary:This paper describes the development of situational awareness models and applications to assess cybersecurity risks based on Annex ISO 27001:2013. The risk assessment method used is the direct testing method, namely audit, exercise and penetration testing. The risk assessment of this study is classified into three levels, namely high, medium and low. A high-risk value is an unacceptable risk value. Meanwhile, low and medium risk values can be categorized as acceptable risk values. The results of a network security case study with security performance index indicators based on the percentage of compliance with ISO 27001:2013 annex controls and the value of the risk level of the findings of the three test methods showed that testing with the audit method was 38.29% with a moderate and high-risk level. While the test results with the tabletop exercise method are 75% with low and moderate risk levels. On the other hand, the results with the penetration test method are 16.66%, with moderate and high-risk levels. Test results with unacceptable risk values or high-risk corrective actions are taken through an application. Finally, corrective actions have been verified to prove there is an increase in cyber resilience and security.