A Systematic Approach for Cybersecurity Risk Management
Name
chen-kristiny-sm-sdm-2021-thesis.pdf
Description
Thesis PDF
Size
5.25 MB
Format
Adobe PDF
Checksum (MD5)
08a6807878d385a192d63c53ffd48b3e
Author(s)
Chen, Kristin YiJie
Advisor(s)
Siegel, Michael D.
Date Issued
September 2021
Publisher
Massachusetts Institute of Technology
Abstract
In the last few years, the concern over cybersecurity has grown dramatically. With all the existing, and sometimes competing, guidelines and frameworks intended to inform cyber risk strategies, organizations face the problem of deciding which is right for them. To resolve the confusion, this research proposes a practical and effective model that can be used by organizations of any size or in any industry for cyber risk management. We propose a Cyber Risk Cube (CRC) tool designed to be practical for all parts of an organization, which examines three fundamental pairings for looking at cyber risk: Internal/External, Measurement/Management, and Qualitative/Quantitative. The CRC tool can be used as a common language for sharing ideas and solutions to cyber risk management. Ultimately, the CRC provides details for implementing solutions to managing cyber risks in a concise and standardized manner.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
System Design and Management Program.
System Design and Management Program.
Terms of Use
In Copyright - Educational Use Permitted
Copyright MIT
Persistent DSpace Link