<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-20T10:59:52Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/157124" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/157124</identifier><datestamp>2024-10-03T03:47:03Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor">Reynolds, Taylor</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="advisor">Weitzner, Daniel J.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author">Conard, Chelsea Foushee</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department">Massachusetts Institute of Technology. Institute for Data, Systems, and Society</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2024-10-02T17:32:04Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2024-10-02T17:32:04Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued">2024-09</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="submitted">2024-09-16T19:32:15.163Z</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">https://hdl.handle.net/1721.1/157124</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract">In the field of cybersecurity, the lack of standardized data collection and incident reporting&#xd;
methods pose significant challenges to address and respond to incidents affecting critical&#xd;
infrastructure. Various initiatives aim to resolve this issue by mandating the collection of&#xd;
data on cyber incidents; however, there is often a lack of clear guidelines on how the collected&#xd;
data will be utilized effectively.&#xd;
This paper introduces the Cyber Incident Severity Scale (CISS), a framework designed&#xd;
to guide the selection of relevant data for analysis and communicate the severity of a cybersecurity incident. By drawing insights from established scales in other fields, such as&#xd;
natural disasters and public health, this research produces a single score for a reporting&#xd;
entity which can be aggregated to determine the overall severity of an incident. The ability&#xd;
to swiftly assess and score an incident is a critical tool to quantify incident severity and&#xd;
prioritize response, support policy development, and bolster the overall security of critical&#xd;
infrastructure.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree">S.M.</dim:field>
   <dim:field mdschema="dc" element="publisher">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights">Attribution-NonCommercial-NoDerivatives 4.0 International (CC BY-NC-ND 4.0)</dim:field>
   <dim:field mdschema="dc" element="rights">Copyright retained by author(s)</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri">https://creativecommons.org/licenses/by-nc-nd/4.0/</dim:field>
   <dim:field mdschema="dc" element="title">Quantifying the Severity of a Cybersecurity Incident for Incident Reporting</dim:field>
   <dim:field mdschema="dc" element="type">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="degree">Master</dim:field>
   <dim:field mdschema="thesis" element="degree" qualifier="name">Master of Science in Technology and Policy</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="40673638-9613-41a3-9462-cf2562f27b73">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
   	&lt;Title>Quantifying the Severity of a Cybersecurity Incident for Incident Reporting&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2024-09&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Conard, Chelsea Foushee&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>https://creativecommons.org/licenses/by-nc-nd/4.0/&lt;/License>
   	&lt;Abstract>In the field of cybersecurity, the lack of standardized data collection and incident reporting&#xd;
methods pose significant challenges to address and respond to incidents affecting critical&#xd;
infrastructure. Various initiatives aim to resolve this issue by mandating the collection of&#xd;
data on cyber incidents; however, there is often a lack of clear guidelines on how the collected&#xd;
data will be utilized effectively.&#xd;
This paper introduces the Cyber Incident Severity Scale (CISS), a framework designed&#xd;
to guide the selection of relevant data for analysis and communicate the severity of a cybersecurity incident. By drawing insights from established scales in other fields, such as&#xd;
natural disasters and public health, this research produces a single score for a reporting&#xd;
entity which can be aggregated to determine the overall severity of an incident. The ability&#xd;
to swiftly assess and score an incident is a critical tool to quantify incident severity and&#xd;
prioritize response, support policy development, and bolster the overall security of critical&#xd;
infrastructure.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>