Categorizing Anomalies for Cybersecurity Risk
摘要
This study explores the categorization of anomalies within cybersecurity risk management, beginning with a foundational identification of anomaly types. This categorization is expanded through context enrichment and the inclusion of extreme but rare events, leading to a novel taxonomy for cybersecurity anomalies as per design science research artifact. A case study of the Target data breach from 2014 is provided to highlight these ideas and show how the refined anomaly taxonomy is applicable in real-world scenarios. Through this analysis, the study highlights the importance of contextual analysis and comprehensive data enrichment in identifying and managing cybersecurity anomalies.