Quantifying Risk from Non-Compliant Configurations: A Framework for Decision-Making
Authors: Santosh Kumar Kande
DOI: https://doi.org/10.5281/zenodo.14523134
Short DOI: https://doi.org/g8wdv6
Country: United States
Full-text Research PDF File:
View |
Download
Abstract: A direct correlation with a higher risk of a breach, decreased operational effectiveness, and likely punitive fines make configuration non-compliance a major challenge in cybersecurity. Current methods for handling non-compliance usually emphasize detection rather than actionable risk prioritization. In this paper we present a novel framework to quantify the risk posed by non-compliant configurations. The results of this analysis are combined with dynamic risk assessment metrics and contextual asset valuation to develop an approach for quantifying financial losses that complement current static risk measurements to provide organizations with a decision-making tool to assist in determining how to allocate resources, vulnerable system remediation, etc.
Keywords: Risk quantification, non-compliance, configuration management, cybersecurity, financial impact, decision-making framework
Paper Id: 231834
Published On: 2024-01-04
Published In: Volume 12, Issue 1, January-February 2024
Cite This: Quantifying Risk from Non-Compliant Configurations: A Framework for Decision-Making - Santosh Kumar Kande - IJIRMPS Volume 12, Issue 1, January-February 2024. DOI 10.5281/zenodo.14523134