In the last years the use of information and communication technology in organizations has become vital to the point that each menace to its continuous functioning is considered a noteworthy danger for each organization. Cybersecurity has the aim of protecting the organization from these events called cyber-attacks. The emergent cyber resilience management integrates cyber risk management (which is based on identifying, analyzing and mitigating risk of cyber-attacks) with the ability to front them, recover from them and adapt the organization to the new situation when unpredictable attacks occur, without regressing. Several guidelines have been developed to guide organizations in managing cyber resilience, the NIST framework suggested and organized IT and managerial practices among different reference cyber security standards offering a practical overview followed by companies all over the world. Practices and guidelines must be general and consequently they need to be adapted to the specific context in which the company is embedded. In order to identify the effectiveness of the suggested managerial practices and the way they are implemented in the Italian context, we conducted a multiple case study analysis interviewing 20 cybersecurity experts included in the official list realised by the Italian Ministry of Economic Development in 2019. Interesting insights emerged including the lack of disciplinary measures in case of any misconduct, the importance of investing in building a comprehensive awareness of people about cyber threats, the importance of log information for multiple reasons and the urgency for each organization of developing its own tailored policies.

Effectiveness and Adoption of NIST Managerial Practices for Cyber Resilience in Italy / Annarelli, Alessandro; Clemente, Serena; Nonino, Fabio; Palombi, Giulia. - 285:(2021), pp. 818-832. (Intervento presentato al convegno Computing Conference 2021 tenutosi a Virtual) [10.1007/978-3-030-80129-8_55].

Effectiveness and Adoption of NIST Managerial Practices for Cyber Resilience in Italy

Annarelli, Alessandro;Nonino, Fabio;Palombi, Giulia
2021

Abstract

In the last years the use of information and communication technology in organizations has become vital to the point that each menace to its continuous functioning is considered a noteworthy danger for each organization. Cybersecurity has the aim of protecting the organization from these events called cyber-attacks. The emergent cyber resilience management integrates cyber risk management (which is based on identifying, analyzing and mitigating risk of cyber-attacks) with the ability to front them, recover from them and adapt the organization to the new situation when unpredictable attacks occur, without regressing. Several guidelines have been developed to guide organizations in managing cyber resilience, the NIST framework suggested and organized IT and managerial practices among different reference cyber security standards offering a practical overview followed by companies all over the world. Practices and guidelines must be general and consequently they need to be adapted to the specific context in which the company is embedded. In order to identify the effectiveness of the suggested managerial practices and the way they are implemented in the Italian context, we conducted a multiple case study analysis interviewing 20 cybersecurity experts included in the official list realised by the Italian Ministry of Economic Development in 2019. Interesting insights emerged including the lack of disciplinary measures in case of any misconduct, the importance of investing in building a comprehensive awareness of people about cyber threats, the importance of log information for multiple reasons and the urgency for each organization of developing its own tailored policies.
2021
Computing Conference 2021
Cyber resilience; Managerial practices; Cybersecurity experts; Multiple case studies analysis
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
Effectiveness and Adoption of NIST Managerial Practices for Cyber Resilience in Italy / Annarelli, Alessandro; Clemente, Serena; Nonino, Fabio; Palombi, Giulia. - 285:(2021), pp. 818-832. (Intervento presentato al convegno Computing Conference 2021 tenutosi a Virtual) [10.1007/978-3-030-80129-8_55].
File allegati a questo prodotto
File Dimensione Formato  
Annarelli_Effectiveness_2021.pdf

solo gestori archivio

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 4.07 MB
Formato Adobe PDF
4.07 MB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/1560243
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 8
  • ???jsp.display-item.citation.isi??? ND
social impact