全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

A Web Platform Based on the NIST CSF for Assessing and Monitoring the Cybersecurity of SMEs and Critical Infrastructures

DOI: 10.4236/ojapps.2025.151018, PP. 274-284

Keywords: Cybersecurity, NIST CSF Framework, Cybersecurity Assessment Tool, Cybersecurity Mitigation, Small and Medium-Sized Enterprises, Critical Infrastructure

Full-Text   Cite this paper   Add to My Lib

Abstract:

The NIST Cybersecurity Framework (NIST CSF) serves as a voluntary guideline aimed at helping organizations, tiny and medium-sized enterprises (SMEs), and critical infrastructure operators, effectively manage cyber risks. Although comprehensive, the complexity of the NIST CSF can be overwhelming, especially for those lacking extensive cybersecurity resources. Current implementation tools often cater to larger companies, neglecting the specific needs of SMEs, which can be vulnerable to cyber threats. To address this gap, our research proposes a user-friendly, open-source web platform designed to simplify the implementation of the NIST CSF. This platform enables organizations to assess their risk exposure and continuously monitor their cybersecurity maturity through tailored recommendations based on their unique profiles. Our methodology includes a literature review of existing tools and standards, followed by a description of the platform’s design and architecture. Initial tests with SMEs in Burkina Faso reveal a concerning cybersecurity maturity level, indicating the urgent need for improved strategies based on our findings. By offering an intuitive interface and cross-platform accessibility, this solution aims to empower organizations to enhance their cybersecurity resilience in an evolving threat landscape. The article concludes with discussions on the practical implications and future enhancements of the tool.

References

[1]  Wrenn, G. (2017) CSO Online.
https://www.csoonline.com/article/3239968/how-can-my-cyber-program-benefit-from-a-standards-based-approach.html
[2]  Johnson, L. (2020) Cybersecurity Framework. In: Security Controls Evaluation, Testing, and Assessment Handbook, Elsevier, 537-548.
https://doi.org/10.1016/b978-0-12-818427-1.00012-4
[3]  Federal Office for Economic Approvals (2018) Minimum Standard for IT Resilience. Bern (Switzerland).
[4]  NIST (2018) Framework for Improving Critical Infrastructure Cybersecurity. National Institute of Standards and Technology.
[5]  Benz, M. and Chatterjee, D. (2020) Calculated Risk? A Cybersecurity Evaluation Tool for SMEs. Business Horizons, 63, 531-540.
[6]  Antunes, M., Maximiano, M. and Gomes, R. (2022) A Customizable Web Platform to Manage Standards Compliance of Information Security and Cybersecurity Auditing. Procedia Computer Science, 196, 36-43.
https://doi.org/10.1016/j.procs.2021.11.070

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133