How Do We Optimize Risk in Enterprise Architecture when Deploying Emerging Technologies?

C. Griffy-Brown, M. Chun, Howard Miller, Demetrios Lazarikos
{"title":"How Do We Optimize Risk in Enterprise Architecture when Deploying Emerging Technologies?","authors":"C. Griffy-Brown, M. Chun, Howard Miller, Demetrios Lazarikos","doi":"10.33847/2686-8296.3.1_1","DOIUrl":null,"url":null,"abstract":"Emerging Technologies which merge cyber-physical systems continue to transform businesses and digital agility in transformative ways. Importantly, most investigations around focus on either cyber risk or the risk around physical systems but it does not encompass both. However, the immediate challenge is new opportunities occurring with emerging technologies. Examples include automobiles, the Internet of Things (IoT), medical devices, and building controls. In this study we will focus identifying risk as an optimization not a minimization problem and how to develop a practical approach for executives and boards to use in the oversight of cyber physical systems. Based on interviews with executive leadership teams and boards of directors we explored the over-arching research question: How can we apply a risk-based approach to cyber-physical security and what questions should business leaders be asking? The research methodology used a survey instrument and multiple qualitative methods involving business leaders from 60 companies and 80 business leaders from September 2018 – September 2019. Based on this analysis, we developed an extended framework for executives, as well as questions and process for boards to consider as part of their oversight. The Extended Risk-Based Approach equips boards and executives as they begin to develop their thinking around enterprise cyber physical risk.","PeriodicalId":235278,"journal":{"name":"Journal of Digital Science","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-06-29","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Digital Science","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.33847/2686-8296.3.1_1","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

Emerging Technologies which merge cyber-physical systems continue to transform businesses and digital agility in transformative ways. Importantly, most investigations around focus on either cyber risk or the risk around physical systems but it does not encompass both. However, the immediate challenge is new opportunities occurring with emerging technologies. Examples include automobiles, the Internet of Things (IoT), medical devices, and building controls. In this study we will focus identifying risk as an optimization not a minimization problem and how to develop a practical approach for executives and boards to use in the oversight of cyber physical systems. Based on interviews with executive leadership teams and boards of directors we explored the over-arching research question: How can we apply a risk-based approach to cyber-physical security and what questions should business leaders be asking? The research methodology used a survey instrument and multiple qualitative methods involving business leaders from 60 companies and 80 business leaders from September 2018 – September 2019. Based on this analysis, we developed an extended framework for executives, as well as questions and process for boards to consider as part of their oversight. The Extended Risk-Based Approach equips boards and executives as they begin to develop their thinking around enterprise cyber physical risk.
在部署新兴技术时,我们如何优化企业架构中的风险?
融合网络物理系统的新兴技术继续以变革性的方式改变业务和数字敏捷性。重要的是,大多数调查关注的要么是网络风险,要么是物理系统风险,但它并没有涵盖两者。然而,当前的挑战是新兴技术带来的新机遇。例子包括汽车、物联网(IoT)、医疗设备和建筑控制。在本研究中,我们将重点关注将风险识别为优化问题,而不是最小化问题,以及如何开发一种实用的方法,供高管和董事会用于监督网络物理系统。基于对执行领导团队和董事会的采访,我们探讨了一个首要的研究问题:我们如何将基于风险的方法应用于网络物理安全,商业领袖应该问什么问题?研究方法采用了调查工具和多种定性方法,涉及60家公司的商业领袖和80名商业领袖,时间为2018年9月至2019年9月。基于这一分析,我们为高管开发了一个扩展框架,以及供董事会考虑的问题和流程,作为其监督的一部分。当董事会和高管们开始围绕企业网络物理风险展开思考时,“基于风险的扩展方法”为他们提供了装备。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信