An Assessment of Capabilities Required for Effective Cybersecurity Incident Management - A Systematic Literature Review
作者:Olufunsho I. Falowo, Kehinde Koshoedo, Murat Ozer · 发表于:2023 International Conference on Data Security and Privacy Protection (DSPP) · 年份:2023 · DOI:10.1109/dspp58763.2023.10404318 · 被引用次数:5
Reports from multiple independent sources reveal that a lack of preparation/readiness for cybersecurity incidents detrimentally affects business continuity and delays the recovery of operations. The current cybersecurity paradigm suggests that any organization can have cyberattacks anytime, regardless of the security principles applied. Therefore, the preparation/readiness phase is vitally essential to respond to these attacks adequately. We first identified a report on major cybersecurity incidents that is compiled by the Center for Strategic & International Studies, from which we examined major cybersecurity incidents, and we then established its credibility, non-partisan, global outreach, and attack coverage by cross-referencing it with Data Breach Investigation Report (DBIR). Given this context, this study conducts a systematic literature review to understand the body of knowledge that highlights administrative and technical capabilities of organizations to respond to a likely cybersecurity attack. Study findings show that about 72 percent of surveyed papers suggest that more organizations embrace administrative capabilities, especially compared to technical skills. More organizations also recognize the importance of having Cybersecurity Incident Response Team (CSIRT) abilities to enhance readiness to combat potential cybersecurity incidents - this is validated by the 88.89 percent score identified in this study. We emphasize the significance of organizations’ readiness t...