Title
Method for Designing Countermeasures for Crypto-Ransomware Based on the NIST CSF
Date Issued
01 January 2022
Access level
metadata only access
Resource Type
conference paper
Publisher(s)
Springer Science and Business Media Deutschland GmbH
Abstract
Crypto-ransomware are malicious programs that encrypt the data of an infected machine, making it a hostage until the owner of the device decides to pay the fee to recover their information. This has become a complex cybersecurity problem causing more and more economic damage. Crypto-ransomware has rendered cybersecurity models not adequate since they do not establish specific guidelines for the design of countermeasures. This paper proposes a method for the design of countermeasures related to crypto-ransomware attacks based on the NIST 800–53 revision 4 standard and the Information Security Maturity Model published by ISACA in the COBIT Focus magazine. The model consists of five phases: identify vulnerabilities, assess vulnerabilities, propose countermeasures, implement countermeasures, and evaluate countermeasures. This allows an organization to measure its current cybersecurity state, know cybersecurity measures oriented to crypto-ransomware and its prioritization through criticality indexes in a simple, adaptive and easy to implement way. A case study in a Peruvian company shows the simplicity and ease of use of the method, which allows the design of countermeasures with which the level of cybersecurity can be improved by 55.6%.
Start page
365
End page
380
Volume
237
Language
English
OCDE Knowledge area
Ingeniería de sistemas y comunicaciones
Scopus EID
2-s2.0-85116922763
Source
Smart Innovation, Systems and Technologies
Resource of which it is part
Smart Innovation, Systems and Technologies
ISSN of the container
21903018
ISBN of the container
978-981163636-3
Conference
4th International Conference on Networking, Intelligent Systems and Security, NISS 2021
Sources of information: Directorio de Producción Científica Scopus