Evaluation of Cybersecurity Management Controls and Metrics of Critical Infrastructures: A Literature Review Considering the NIST Cybersecurity Framework

Barbara Krumay, Edward W.N. Bernroider, Roman Walser

Research output: Chapter in Book/Report/Conference proceedingConference proceedings

Abstract

In recent years, cybersecurity management has gained considerable attention due to a rising number and also increasing severity of cyberattacks in particular targeted at critical infrastructures of countries. Especially rapid digitization holds many vulnerabilities that can be easily exploited if not managed appropriately. Consequently, the European Union (EU) has enacted its first directive on cybersecurity. It is based on the Cybersecurity Framework by the US National Institute of Standards and Technology (NIST) and requires critical infrastructure organizations to regularly monitor and report their cybersecurity efforts. We investigated whether the academic body of knowledge in the area of cybersecurity metrics and controls has covered the constituent NIST functions, and also whether NIST shows any noticeable gaps in relation to literature. Our analysis revealed interesting results in both directions, pointing to imbalances in the academic discourse and underrepresented areas in the NIST framework. In terms of the former, we argue that future research should engage more into detecting, responding and recovering from incidents. Regarding the latter, NIST could also benefit from extending into a number of identified topic areas, for example, natural disasters, monetary aspects, and organizational climate.
Original languageEnglish
Title of host publicationSecure IT Systems. 23rd Nordic Conference, NordSec 2018, Oslo, Norway, November 28-30, 2018, Proceedings
Editors Gruschka N.
PublisherSpringer, Cham
Pages369-384
Number of pages15
Volume11252
ISBN (Print)978-3-030-03638-6
DOIs
Publication statusPublished - 2018

Publication series

NameLecture Notes in Computer Science (LNCS)

Fields of science

  • 303026 Public health
  • 305909 Stress research
  • 102 Computer Sciences
  • 102006 Computer supported cooperative work (CSCW)
  • 102015 Information systems
  • 102016 IT security
  • 502007 E-commerce
  • 502014 Innovation research
  • 502030 Project management
  • 501016 Educational psychology
  • 602036 Neurolinguistics
  • 501030 Cognitive science
  • 502032 Quality management
  • 502043 Business consultancy
  • 502044 Business management
  • 502050 Business informatics
  • 503008 E-learning
  • 509004 Evaluation research
  • 301407 Neurophysiology
  • 301401 Brain research

JKU Focus areas

  • Digital Transformation

Cite this