Vendor Cybersecurity Risk Assessment in an Autonomous Mobility Ecosystem

Albena Tzoneva, G. Momcheva, B. Stoyanov
{"title":"Vendor Cybersecurity Risk Assessment in an Autonomous Mobility Ecosystem","authors":"Albena Tzoneva, G. Momcheva, B. Stoyanov","doi":"10.1109/COMSCI55378.2022.9912588","DOIUrl":null,"url":null,"abstract":"Vendor cybersecurity risk assessment is of critical importance to smart city infrastructure and sustainability of the autonomous mobility ecosystem. Lack of engagement in cybersecurity policies and process implementation by the tier companies providing hardware or services to OEMs within this ecosystem poses a significant risk to not only the individual companies but to the ecosystem overall. The proposed quantitative method of estimating cybersecurity risk allows vendors to have visibility to the financial risk associated with potential threats and to consequently allocate adequate resources to cybersecurity. It facilitates faster implementation of defense measures and provides a useful tool in the vendor selection process. The paper focuses on cybersecurity risk assessment as a critical part of the overall company mission to create a sustainable structure for maintaining cybersecurity health. Compound cybersecurity risk and impact on company operations as outputs of this quantitative analysis present a unique opportunity to strategically plan and make informed decisions towards acquiring a reputable position in a sustainable ecosystem. This method provides attack trees and assigns a risk factor to each vendor thus offering a competitive advantage and an insight into the supply chain risk map. This is an innovative way to look at vendor cybersecurity posture. Through a selection of unique industry specific parameters and a modular approach, this risk assessment model can be employed as a tool to navigate the supply base and prevent significant financial cost. It generates synergies within the connected vehicle ecosystem leading to a safe and sustainable economy.","PeriodicalId":399680,"journal":{"name":"2022 10th International Scientific Conference on Computer Science (COMSCI)","volume":"54 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 10th International Scientific Conference on Computer Science (COMSCI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/COMSCI55378.2022.9912588","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Vendor cybersecurity risk assessment is of critical importance to smart city infrastructure and sustainability of the autonomous mobility ecosystem. Lack of engagement in cybersecurity policies and process implementation by the tier companies providing hardware or services to OEMs within this ecosystem poses a significant risk to not only the individual companies but to the ecosystem overall. The proposed quantitative method of estimating cybersecurity risk allows vendors to have visibility to the financial risk associated with potential threats and to consequently allocate adequate resources to cybersecurity. It facilitates faster implementation of defense measures and provides a useful tool in the vendor selection process. The paper focuses on cybersecurity risk assessment as a critical part of the overall company mission to create a sustainable structure for maintaining cybersecurity health. Compound cybersecurity risk and impact on company operations as outputs of this quantitative analysis present a unique opportunity to strategically plan and make informed decisions towards acquiring a reputable position in a sustainable ecosystem. This method provides attack trees and assigns a risk factor to each vendor thus offering a competitive advantage and an insight into the supply chain risk map. This is an innovative way to look at vendor cybersecurity posture. Through a selection of unique industry specific parameters and a modular approach, this risk assessment model can be employed as a tool to navigate the supply base and prevent significant financial cost. It generates synergies within the connected vehicle ecosystem leading to a safe and sustainable economy.
自主移动生态系统中的供应商网络安全风险评估
供应商网络安全风险评估对智慧城市基础设施和自主移动生态系统的可持续性至关重要。在这个生态系统中,为oem提供硬件或服务的公司缺乏对网络安全政策和流程实施的参与,不仅会给个别公司带来重大风险,也会给整个生态系统带来重大风险。所提出的定量评估网络安全风险的方法使供应商能够了解与潜在威胁相关的财务风险,从而为网络安全分配足够的资源。它有助于更快地实现防御措施,并在供应商选择过程中提供有用的工具。本文重点关注网络安全风险评估,将其作为公司整体使命的关键部分,以创建一个可持续的结构来维护网络安全健康。作为定量分析的输出,复合网络安全风险和对公司运营的影响为战略规划和做出明智决策提供了独特的机会,从而在可持续生态系统中获得良好的地位。该方法提供了攻击树,并为每个供应商分配了风险因素,从而提供了竞争优势和对供应链风险图的洞察。这是一种看待供应商网络安全态势的创新方式。通过选择独特的行业特定参数和模块化方法,该风险评估模型可以作为导航供应基础的工具,并防止重大的财务成本。它在互联汽车生态系统中产生协同效应,从而实现安全和可持续的经济。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信