Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains

Much of the confusion about the effectiveness of information security programs concerns not only how to measure, but also what to measure — an issue of equivocality. Thus, to lower uncertainty for improved decision-making, it is first essential to reduce equivocality by defining, expanding, and clar...

Full description

Bibliographic Details
Main Author: Baker, Wade Henderson
Other Authors: Business Information Technology
Format: Others
Published: Virginia Tech 2018
Subjects:
Online Access:http://hdl.handle.net/10919/85128
id ndltd-VTETD-oai-vtechworks.lib.vt.edu-10919-85128
record_format oai_dc
spelling ndltd-VTETD-oai-vtechworks.lib.vt.edu-10919-851282021-11-02T05:34:58Z Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains Baker, Wade Henderson Business Information Technology Rees, Loren P. Cook, Deborah F. Matheson, Lance A. Wallace, Linda G. Ragsdale, Cliff T. cybersecurity cyber security information security cyber risk information risk risk modeling risk management security metrics decision support systems supply chain management supply chain risk supply chain information sharing Much of the confusion about the effectiveness of information security programs concerns not only how to measure, but also what to measure — an issue of equivocality. Thus, to lower uncertainty for improved decision-making, it is first essential to reduce equivocality by defining, expanding, and clarifying risk factors so that metrics, the "necessary measures," can be unambiguously applied. We formulate a system that (1) allows threats to be accurately measured and tracked, (2) enables the impacts and costs of successful threats to be determined, and (3) aids in evaluating the effectiveness and return on investment of countermeasures. We then examine the quality of controls implemented to mitigate cyber risk and study how effectively they reduce the likelihood of security incidents. Improved control quality was shown to reduce the likelihood of security incidents, yet the results indicate that investing in maximum quality is not necessarily the most efficient use of resources. The next manuscript expands the discussion of cyber risk management beyond single organizations by surveying perceptions and experiences of risk factors related to 3rd parties. To validate and these findings, we undertake in an in-depth investigation of nearly 1000 real-world data breaches occurring over a ten-year period. It provides a robust data model and rich database required by a decision support system for cyber risk in the extended enterprise. To our knowledge, it is the most comprehensive field study ever conducted on the subject. Finally, we incorporate these insights, data, and factors into a simulation model that enables us study the transfer of cyber risk across different supply chain configurations and draw important managerial implications. Ph. D. 2018-09-26T06:00:41Z 2018-09-26T06:00:41Z 2017-04-03 Dissertation vt_gsexam:9779 http://hdl.handle.net/10919/85128 In Copyright http://rightsstatements.org/vocab/InC/1.0/ ETD application/pdf Virginia Tech
collection NDLTD
format Others
sources NDLTD
topic cybersecurity
cyber security
information security
cyber risk
information risk
risk modeling
risk management
security metrics
decision support systems
supply chain management
supply chain risk
supply chain information sharing
spellingShingle cybersecurity
cyber security
information security
cyber risk
information risk
risk modeling
risk management
security metrics
decision support systems
supply chain management
supply chain risk
supply chain information sharing
Baker, Wade Henderson
Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains
description Much of the confusion about the effectiveness of information security programs concerns not only how to measure, but also what to measure — an issue of equivocality. Thus, to lower uncertainty for improved decision-making, it is first essential to reduce equivocality by defining, expanding, and clarifying risk factors so that metrics, the "necessary measures," can be unambiguously applied. We formulate a system that (1) allows threats to be accurately measured and tracked, (2) enables the impacts and costs of successful threats to be determined, and (3) aids in evaluating the effectiveness and return on investment of countermeasures. We then examine the quality of controls implemented to mitigate cyber risk and study how effectively they reduce the likelihood of security incidents. Improved control quality was shown to reduce the likelihood of security incidents, yet the results indicate that investing in maximum quality is not necessarily the most efficient use of resources. The next manuscript expands the discussion of cyber risk management beyond single organizations by surveying perceptions and experiences of risk factors related to 3rd parties. To validate and these findings, we undertake in an in-depth investigation of nearly 1000 real-world data breaches occurring over a ten-year period. It provides a robust data model and rich database required by a decision support system for cyber risk in the extended enterprise. To our knowledge, it is the most comprehensive field study ever conducted on the subject. Finally, we incorporate these insights, data, and factors into a simulation model that enables us study the transfer of cyber risk across different supply chain configurations and draw important managerial implications. === Ph. D.
author2 Business Information Technology
author_facet Business Information Technology
Baker, Wade Henderson
author Baker, Wade Henderson
author_sort Baker, Wade Henderson
title Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains
title_short Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains
title_full Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains
title_fullStr Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains
title_full_unstemmed Toward a Decision Support System for Measuring and Managing Cybersecurity Risk in Supply Chains
title_sort toward a decision support system for measuring and managing cybersecurity risk in supply chains
publisher Virginia Tech
publishDate 2018
url http://hdl.handle.net/10919/85128
work_keys_str_mv AT bakerwadehenderson towardadecisionsupportsystemformeasuringandmanagingcybersecurityriskinsupplychains
_version_ 1719492110369947648