Developing a Unified Cyber Risk Management Framework Using Semantic Technologies and Structured Modeling Approaches
Résumé
Cybersecurity knowledge is often fragmented across heterogeneous ontologies and standards, limiting consistent and interoperable risk management. This study proposes a unified hybrid ontology by integrating ISO/IEC 27005 and the National Institute of Standards and Technology Special Publication 800-30 (NIST SP 800-30), selected for their complementary approaches to risk identification, assessment, and treatment. A Unified Modeling Language (UML) metamodel was designed, translated into the Resource Description Framework (RDF), enriched with Web Ontology Language (OWL) rules, and validated using the World Wide Web Consortium (W3C) RDF Validator. The resulting ontology (~200 RDF triples) achieved full syntactic conformity after resolving seven detected inconsistencies. Unlike previous static models, the framework reacts dynamically to real-time security events: when a vulnerability is reported, it is linked to affected assets and threats, triggering automatic risk recalculation and activation of treatment plans (avoidance, transfer, mitigation, or acceptance). Monitored by Key Performance Indicators (KPIs), the system ensures proactive, adaptive, and continuously aligned risk management, while remaining extensible to additional frameworks such as the Center for Internet Security (CIS) Controls and Control Objectives for Information and Related Technologies (COBIT).
Citer ce document
Accès au document
Texte intégral en lecture en ligne, réservé aux abonnés SPHAERO et aux membres de l'institution. Se connecter
Voir l'article sur le site de la revueStatistiques
Consultations : 1
Téléchargements : 0