IDEAS home Printed from https://ideas.repec.org/a/spr/envsyd/v33y2013i4d10.1007_s10669-013-9485-y.html
   My bibliography  Save this article

Resilience metrics for cyber systems

Author

Listed:
  • Igor Linkov

    (US Army Engineer Research and Development Center)

  • Daniel A. Eisenberg

    (US Army Engineer Research and Development Center
    Arizona State University)

  • Kenton Plourde

    (US Army Engineer Research and Development Center)

  • Thomas P. Seager

    (Arizona State University)

  • Julia Allen

    (Carnegie Mellon Software Engineering Institute)

  • Alex Kott

    (Army Research Laboratory)

Abstract

As federal agencies and businesses rely more on cyber infrastructure, they are increasingly vulnerable to cyber attacks that can cause damages disproportionate to the sophistication and cost to launch the attack. In response, regulatory authorities call for focusing attention on enhancing infrastructure resilience. For example, in the USA, President Obama issued an Executive Order and policy directives focusing on improving the resilience and security of cyber infrastructure to a wide range of cyber threats. Despite the national and international importance, resilience metrics to inform management decisions are still in the early stages of development. We apply the resilience matrix framework developed by Linkov et al. (Environ Sci Technol 47:10108–10110, 2013) to develop and organize effective resilience metrics for cyber systems. These metrics link national policy goals to specific system measures, such that resource allocation decisions can be translated into actionable interventions and investments. In this paper, a number of metrics have been identified and assessed using quantitative and qualitative measures found in the literature. We have proposed a generic approach and could integrate actual data, technical judgment, and literature-based measures to assess system resilience across physical, information, cognitive, and social domains.

Suggested Citation

  • Igor Linkov & Daniel A. Eisenberg & Kenton Plourde & Thomas P. Seager & Julia Allen & Alex Kott, 2013. "Resilience metrics for cyber systems," Environment Systems and Decisions, Springer, vol. 33(4), pages 471-476, December.
  • Handle: RePEc:spr:envsyd:v:33:y:2013:i:4:d:10.1007_s10669-013-9485-y
    DOI: 10.1007/s10669-013-9485-y
    as

    Download full text from publisher

    File URL: http://link.springer.com/10.1007/s10669-013-9485-y
    File Function: Abstract
    Download Restriction: Access to the full text of the articles in this series is restricted.

    File URL: https://libkey.io/10.1007/s10669-013-9485-y?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    As the access to this document is restricted, you may want to search for a different version of it.

    References listed on IDEAS

    as
    1. Stanley Kaplan & B. John Garrick, 1981. "On The Quantitative Definition of Risk," Risk Analysis, John Wiley & Sons, vol. 1(1), pages 11-27, March.
    Full references (including those not matched with items on IDEAS)

    Citations

    Citations are extracted by the CitEc Project, subscribe to its RSS feed for this item.
    as


    Cited by:

    1. R. Cantelmi & G. Di Gravio & R. Patriarca, 2021. "Reviewing qualitative research approaches in the context of critical infrastructure resilience," Environment Systems and Decisions, Springer, vol. 41(3), pages 341-376, September.
    2. Laura A. Bakkensen & Cate Fox‐Lent & Laura K. Read & Igor Linkov, 2017. "Validating Resilience and Vulnerability Indices in the Context of Natural Disasters," Risk Analysis, John Wiley & Sons, vol. 37(5), pages 982-1004, May.
    3. Bo Zou & Pooria Choobchian & Julie Rozenberg, 2021. "Cyber resilience of autonomous mobility systems: cyber-attacks and resilience-enhancing strategies," Journal of Transportation Security, Springer, vol. 14(3), pages 137-155, December.
    4. Ivo Häring & Mirjam Fehling-Kaschek & Natalie Miller & Katja Faist & Sebastian Ganter & Kushal Srivastava & Aishvarya Kumar Jain & Georg Fischer & Kai Fischer & Jörg Finger & Alexander Stolz & Tobias , 2021. "A performance-based tabular approach for joint systematic improvement of risk control and resilience applied to telecommunication grid, gas network, and ultrasound localization system," Environment Systems and Decisions, Springer, vol. 41(2), pages 286-329, June.
    5. Zou,Bo & Choobchian,Pooria & Rozenberg,Julie, 2020. "Cyber Resilience of Autonomous Mobility Systems : Cyber Attacks and Resilience-Enhancing Strategies," Policy Research Working Paper Series 9135, The World Bank.
    6. Sedigheh Meimandi Parizi & Mohammad Taleai & Ayyoob Sharifi, 2021. "Integrated methods to determine urban physical resilience characteristics and their interactions," Natural Hazards: Journal of the International Society for the Prevention and Mitigation of Natural Hazards, Springer;International Society for the Prevention and Mitigation of Natural Hazards, vol. 109(1), pages 725-754, October.
    7. Claudia R. Binder & Susan Mühlemeier & Romano Wyss, 2017. "An Indicator-Based Approach for Analyzing the Resilience of Transitions for Energy Regions. Part I: Theoretical and Conceptual Considerations," Energies, MDPI, vol. 10(1), pages 1-18, January.
    8. Wood, Matthew D. & Wells, Emily M. & Rice, Glenn & Linkov, Igor, 2019. "Quantifying and mapping resilience within large organizations," Omega, Elsevier, vol. 87(C), pages 117-126.
    9. Alexander A. Ganin & Phuoc Quach & Mahesh Panwar & Zachary A. Collier & Jeffrey M. Keisler & Dayton Marchese & Igor Linkov, 2020. "Multicriteria Decision Framework for Cybersecurity Risk Assessment and Management," Risk Analysis, John Wiley & Sons, vol. 40(1), pages 183-199, January.
    10. Sharifi, Ayyoob & Yamagata, Yoshiki, 2016. "Principles and criteria for assessing urban energy resilience: A literature review," Renewable and Sustainable Energy Reviews, Elsevier, vol. 60(C), pages 1654-1677.
    11. Mujjuni, F. & Betts, T. & To, L.S. & Blanchard, R.E., 2021. "Resilience a means to development: A resilience assessment framework and a catalogue of indicators," Renewable and Sustainable Energy Reviews, Elsevier, vol. 152(C).
    12. Christopher M. Smith & William T. Scherer & Stephen Carr, 2016. "Value of intelligence applied to networks," Environment Systems and Decisions, Springer, vol. 36(1), pages 85-91, March.
    13. Kong, Jingjing & Zhang, Chao & Simonovic, Slobodan P., 2021. "Optimizing the resilience of interdependent infrastructures to regional natural hazards with combined improvement measures," Reliability Engineering and System Safety, Elsevier, vol. 210(C).
    14. Roege, Paul E. & Collier, Zachary A. & Mancillas, James & McDonagh, John A. & Linkov, Igor, 2014. "Metrics for energy resilience," Energy Policy, Elsevier, vol. 72(C), pages 249-256.
    15. Alessandro Annarelli & Giulia Palombi, 2021. "Digitalization Capabilities for Sustainable Cyber Resilience: A Conceptual Framework," Sustainability, MDPI, vol. 13(23), pages 1-9, November.
    16. Zachary A. Collier & Igor Linkov & James H. Lambert, 2013. "Four domains of cybersecurity: a risk-based systems approach to cyber decisions," Environment Systems and Decisions, Springer, vol. 33(4), pages 469-470, December.
    17. Claudio M. Rocco & Kash Barker & Jose Moronta, 2022. "Determining the best algorithm to detect community structures in networks: application to power systems," Environment Systems and Decisions, Springer, vol. 42(2), pages 251-264, June.
    18. Ziyi Wang & Zengqiao Chen & Cuiping Ma & Ronald Wennersten & Qie Sun, 2022. "Nationwide Evaluation of Urban Energy System Resilience in China Using a Comprehensive Index Method," Sustainability, MDPI, vol. 14(4), pages 1-36, February.
    19. Bhandari, Pratik & Creighton, Douglas & Gong, Jinzhe & Boyle, Carol & Law, Kris M.Y., 2023. "Evolution of cyber-physical-human water systems: Challenges and gaps," Technological Forecasting and Social Change, Elsevier, vol. 191(C).
    20. Kirsty Perrett & Ian David Wilson, 2023. "A cyber resilience analysis case study of an industrial operational technology environment," Environment Systems and Decisions, Springer, vol. 43(2), pages 178-190, June.
    21. Nicole R. Sikula & James W. Mancillas & Igor Linkov & John A. McDonagh, 2015. "Risk management is not enough: a conceptual model for resilience and adaptation-based vulnerability assessments," Environment Systems and Decisions, Springer, vol. 35(2), pages 219-228, June.
    22. Patriarca, Riccardo & Simone, Francesco & Di Gravio, Giulio, 2022. "Modelling cyber resilience in a water treatment and distribution system," Reliability Engineering and System Safety, Elsevier, vol. 226(C).

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Gundula Glowka & Andreas Kallmünzer & Anita Zehrer, 2021. "Enterprise risk management in small and medium family enterprises: the role of family involvement and CEO tenure," International Entrepreneurship and Management Journal, Springer, vol. 17(3), pages 1213-1231, September.
    2. Benischke, Mirko H. & Guldiken, Orhun & Doh, Jonathan P. & Martin, Geoffrey & Zhang, Yanze, 2022. "Towards a behavioral theory of MNC response to political risk and uncertainty: The role of CEO wealth at risk," Journal of World Business, Elsevier, vol. 57(1).
    3. S. Cucurachi & E. Borgonovo & R. Heijungs, 2016. "A Protocol for the Global Sensitivity Analysis of Impact Assessment Models in Life Cycle Assessment," Risk Analysis, John Wiley & Sons, vol. 36(2), pages 357-377, February.
    4. K. Karthikeyan & S. Bharath & K. Ranjith Kumar, 2012. "An Empirical Study on Investors’ Perception towards Mutual Fund Products through Banks with Reference to Tiruchirapalli City, Tamil Nadu," Vision, , vol. 16(2), pages 101-108, June.
    5. Nicola Paltrinieri & Nicolas Dechy & Ernesto Salzano & Mike Wardman & Valerio Cozzani, 2012. "Lessons Learned from Toulouse and Buncefield Disasters: From Risk Analysis Failures to the Identification of Atypical Scenarios Through a Better Knowledge Management," Risk Analysis, John Wiley & Sons, vol. 32(8), pages 1404-1419, August.
    6. Louis Anthony (Tony) Cox, Jr., 2012. "Community Resilience and Decision Theory Challenges for Catastrophic Events," Risk Analysis, John Wiley & Sons, vol. 32(11), pages 1919-1934, November.
    7. Chen, Fuzhong & Hsu, Chien-Lung & Lin, Arthur J. & Li, Haifeng, 2020. "Holding risky financial assets and subjective wellbeing: Empirical evidence from China," The North American Journal of Economics and Finance, Elsevier, vol. 54(C).
    8. Niël Almero Krüger & Natanya Meyer, 2021. "The Development of a Small and Medium-Sized Business Risk Management Intervention Tool," JRFM, MDPI, vol. 14(7), pages 1-14, July.
    9. James H. Lambert & Rachel K. Jennings & Nilesh N. Joshi, 2006. "Integration of risk identification with business process models," Systems Engineering, John Wiley & Sons, vol. 9(3), pages 187-198, September.
    10. Johnson, Caroline A. & Flage, Roger & Guikema, Seth D., 2021. "Feasibility study of PRA for critical infrastructure risk analysis," Reliability Engineering and System Safety, Elsevier, vol. 212(C).
    11. Kasai, Naoya & Matsuhashi, Shigemi & Sekine, Kazuyoshi, 2013. "Accident occurrence model for the risk analysis of industrialfacilities," Reliability Engineering and System Safety, Elsevier, vol. 114(C), pages 71-74.
    12. J. C. Helton & F. J. Davis, 2002. "Illustration of Sampling‐Based Methods for Uncertainty and Sensitivity Analysis," Risk Analysis, John Wiley & Sons, vol. 22(3), pages 591-622, June.
    13. Michael Greenberg & Paul Lioy & Birnur Ozbas & Nancy Mantell & Sastry Isukapalli & Michael Lahr & Tayfur Altiok & Joseph Bober & Clifton Lacy & Karen Lowrie & Henry Mayer & Jennifer Rovito, 2013. "Passenger Rail Security, Planning, and Resilience: Application of Network, Plume, and Economic Simulation Models as Decision Support Tools," Risk Analysis, John Wiley & Sons, vol. 33(11), pages 1969-1986, November.
    14. Felipe Aguirre & Mohamed Sallak & Walter Schön & Fabien Belmonte, 2013. "Application of evidential networks in quantitative analysis of railway accidents," Journal of Risk and Reliability, , vol. 227(4), pages 368-384, August.
    15. Naomi Aoki, 2018. "Who Would Be Willing to Accept Disaster Debris in Their Backyard? Investigating the Determinants of Public Attitudes in Post‐Fukushima Japan," Risk Analysis, John Wiley & Sons, vol. 38(3), pages 535-547, March.
    16. Yacov Y. Haimes, 2012. "Systems‐Based Guiding Principles for Risk Modeling, Planning, Assessment, Management, and Communication," Risk Analysis, John Wiley & Sons, vol. 32(9), pages 1451-1467, September.
    17. Matthew H. Henry & Yacov Y. Haimes, 2009. "A Comprehensive Network Security Risk Model for Process Control Networks," Risk Analysis, John Wiley & Sons, vol. 29(2), pages 223-248, February.
    18. Amro Nasr & Oskar Larsson Ivanov & Ivar Björnsson & Jonas Johansson & Dániel Honfi, 2021. "Towards a Conceptual Framework for Built Infrastructure Design in an Uncertain Climate: Challenges and Research Needs," Sustainability, MDPI, vol. 13(21), pages 1-19, October.
    19. James H. Lambert & Benjamin L. Schulte & Priya Sarda, 2005. "Tracking the complexity of interactions between risk incidents and engineering systems," Systems Engineering, John Wiley & Sons, vol. 8(3), pages 262-277, September.
    20. Zio, E., 2018. "The future of risk assessment," Reliability Engineering and System Safety, Elsevier, vol. 177(C), pages 176-190.

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:spr:envsyd:v:33:y:2013:i:4:d:10.1007_s10669-013-9485-y. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Sonal Shukla or Springer Nature Abstracting and Indexing (email available below). General contact details of provider: http://www.springer.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.