It has never been more important to cybersecure the organization's information systems as it is today. This paper develops a cybersecurity metamodel that maps to NIST SP 800-53 Revision 5, with the aim of integrating its security and privacy controls into a risk management framework. The metamodel shows how to add technical controls from NIST SP 800-53 to risk management processes that are already in place. This will make the process of protecting against cyber threats and holes more effective. This study also emphasizes the use of UML diagrams to create a conceptual model that supports the structure and relationships between controls and risk management components, aiming to encourage a more flexible and proactive approach to implementing security measures. We apply this model to the RDF/XML or Turtle format to validate its semantics and ensure compliance with RDF standards.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Comprehensive Metamodel for Cybersecurity: Based on NIST SP 800-53 Revision 5 Security and Privacy Controls

  • Youssef El Marzak,
  • Khalifa Mansouri,
  • Sophia Faris

摘要

It has never been more important to cybersecure the organization's information systems as it is today. This paper develops a cybersecurity metamodel that maps to NIST SP 800-53 Revision 5, with the aim of integrating its security and privacy controls into a risk management framework. The metamodel shows how to add technical controls from NIST SP 800-53 to risk management processes that are already in place. This will make the process of protecting against cyber threats and holes more effective. This study also emphasizes the use of UML diagrams to create a conceptual model that supports the structure and relationships between controls and risk management components, aiming to encourage a more flexible and proactive approach to implementing security measures. We apply this model to the RDF/XML or Turtle format to validate its semantics and ensure compliance with RDF standards.