Lowering the Boundaries of Information Security Governance: A Multi-Perspective Quantitative Viewpoint
This repository contains pointers to the open-source repositories of the projects performed during Alessandro Palma's Ph.D. period that led to his dissertation. Below you can find the table of contents and you can click on the titles you are redirected to the corresponding repository.
1. Introduction
1.1. Research challenges
1.1.1. Poor quantitative assessment boundary
1.1.2. Lack of multi-perspective assessment boundary
1.1.3. Limited decision support boundary
1.1.4. Challenges in cyber risk assessment with Attack Graphs
1.1.5. Challenges in Incident Management Process assessment
1.2. Contributions and dissertation structure
1.2.1. Publications
2. State of the Art
2.1. ISO/IEC 27001 and 27002
2.2. NIST CSF
2.3. Research on Information Security Governance
2.3.1. Quantitative assessment
2.3.2. Multi-Perspecttive assessment
2.3.3. Decision support
3. Cyber risk assessment with Attack Graph
3.1. Preliminaries on Attack Graphs
3.1.1. Attack Graph generation pillars
3.1.2. Attack Graph analysis and risk model
3.2. Related Work
3.2.1. Attack Graph generation and analysis
3.2.2. Attack Graph scalability analysis
3.3. Attack Graph Scalability Investigation
3.3.1. Vulnerable network generator
3.3.2. Analytical framework
3.3.3. Experimental evaluation of Attack Graph scalability
3.3.4. Informativeness of the experimental evaluation
3.3.5. Empirical evaluation on real networks
3.4. Rethinking the Attack Graph Generation and Analysis Process
3.4.1. Overview of the progressive approach
3.4.1. StatAG: Statistically Significant Generation
3.4.1. SteerAG: Steered Genration and Analysis
3.4.1. Validation
3.4.1. Case study
3.5. Employing Attack Graph in IoT Data Spaces
3.5.1. System sesign and implementation
3.5.2. Security messaging mechanism
3.5.3. Evaluation
3.6. Discussion and remarks
4. Process compliance assessment for Incident Management
4.1. Preliminaries on process compliance assessment
4.1.1. Incident Management Process
4.1.1. Process Mining
4.1.1. Visual Analytics
4.2. Related Work
4.2.1. IMP compliance assessment
4.2.2. Quantitative assessment of security processes
4.2.3. Support to process compliance assessment
4.3. Motivating scenario: ISO/IEC 27035:2023
4.4. Process Compliance Assessment formal model
4.4.1. Deviation Taxonomy
4.4.2. Cost Model
4.4.3. Context-Aware Trace Alignment
4.5. Process Compliance Assessment System for IMP
4.5.1. Inputs
4.5.2. Deviation Identification
4.5.3. Deviation Cost Assignment
4.5.4. Context-Aware Trace Alignment
4.5.5. Output
4.6. Benchmark validation for Process Compliance Assessment
4.6.1. Benchmark design and architecture
4.6.2. BenchIMP system
4.6.3. Evaluation of the compliance assessment model and system
4.7. Case Study Application: ISO/IEC 27035:2023
4.8. Visual Support to IMP Compliance Assessment
4.8.1. Requirement collection
4.8.2. System design
4.8.3. Usage scenario
4.9. Discussion and Remarks
5. Discussion and Research Opportunities
5.1. Toward an integrated model
5.2. Consideration of Information Security Governance processes
5.2.1. Asset and resource management
5.2.2. Training and Awareness
6. Conclusions