Show simple item record

 
dc.contributorHospital General de Granollers
dc.contributor.authorGonzalez Granadillo, Gustavo
dc.contributor.authorMenesidou, Sofia Anna
dc.contributor.authorPapamartzivanos, Dimitrios
dc.contributor.authorRomeu, Ramon
dc.contributor.authorOkoh, Caxton
dc.contributor.authorXenakis, Christos
dc.contributor.authorPanaousis, Emmanouil
dc.contributor.authorNavarro Llobet, Diana
dc.contributor.authorNifakos, Sokratis
dc.date.accessioned2021-10-22T14:35:18Z
dc.date.available2021-10-22T14:35:18Z
dc.date.issued2021-08-15
dc.identifier.citationGonzalez-Granadillo G, Menesidou SA, Papamartzivanos D, Romeu R, Navarro-Llobet D, Okoh C, et al. Automated Cyber and Privacy Risk Management Toolkit. Sensors (Basel). 2021 Aug 15;21(16):5493.
dc.identifier.urihttps://hdl.handle.net/11351/6455
dc.descriptionToolkit; Cybersecurity; Privacy
dc.description.abstractAddressing cyber and privacy risks has never been more critical for organisations. While a number of risk assessment methodologies and software tools are available, it is most often the case that one must, at least, integrate them into a holistic approach that combines several appropriate risk sources as input to risk mitigation tools. In addition, cyber risk assessment primarily investigates cyber risks as the consequence of vulnerabilities and threats that threaten assets of the investigated infrastructure. In fact, cyber risk assessment is decoupled from privacy impact assessment, which aims to detect privacy-specific threats and assess the degree of compliance with data protection legislation. Furthermore, a Privacy Impact Assessment (PIA) is conducted in a proactive manner during the design phase of a system, combining processing activities and their inter-dependencies with assets, vulnerabilities, real-time threats and Personally Identifiable Information (PII) that may occur during the dynamic life-cycle of systems. In this paper, we propose a cyber and privacy risk management toolkit, called AMBIENT (Automated Cyber and Privacy Risk Management Toolkit) that addresses the above challenges by implementing and integrating three distinct software tools. AMBIENT not only assesses cyber and privacy risks in a thorough and automated manner but it also offers decision-support capabilities, to recommend optimal safeguards using the well-known repository of the Center for Internet Security (CIS) Controls. To the best of our knowledge, AMBIENT is the first toolkit in the academic literature that brings together the aforementioned capabilities. To demonstrate its use, we have created a case scenario based on information about cyber attacks we have received from a healthcare organisation, as a reference sector that faces critical cyber and privacy threats.
dc.language.isoeng
dc.publisherMDPI
dc.relation.ispartofseriesSensors (Basel);21(16)
dc.rightsAttribution 4.0 International
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/
dc.sourceScientia
dc.subjectSeguretat informàtica
dc.subjectProtecció de dades
dc.subjectProgramari
dc.subject.meshComputer Security
dc.subject.meshRisk Management
dc.subject.meshEquipment and Supplies
dc.titleAutomated Cyber and Privacy Risk Management Toolkit
dc.typeinfo:eu-repo/semantics/article
dc.identifier.doi10.3390/s21165493
dc.subject.decsseguridad informática
dc.subject.decsgestión de la seguridad
dc.subject.decsequipos y suministros
dc.relation.publishversionhttps://doi.org/10.3390/s21165493
dc.type.versioninfo:eu-repo/semantics/publishedVersion
dc.audienceProfessionals
dc.contributor.authoraffiliation[Gonzalez-Granadillo G] Atos Research and Innovation, Cybersecurity Unit, Barcelona, Spain. [Menesidou SA, Papamartzivanos D] UBITECH, Chalandri, Greece. [Romeu R, Navarro-Llobet D] Hospital General de Granollers, Granollers, Spain. [Okoh C, Panaousis E] School of Computing and Mathematical Sciences, University of Greenwich, London, UK. [Nifakos S] Karolinska Institutet Department of Learning, Informatics, Management and Ethics, Solna, Sweden. [Xenakis C] Department of Digital Systems, University of Piraeus, Pireas, Greece
dc.identifier.pmid34450935
dc.rights.accessrightsinfo:eu-repo/semantics/openAccess


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record