Get 20M+ Full-Text Papers For Less Than $1.50/day. Start a 14-Day Trial for You or Your Team.

Learn More →

Obtaining reasonable assurance on cyber resilience

Obtaining reasonable assurance on cyber resilience The purpose of this paper is to highlight the potential of cyber-testing techniques in assessing the effectiveness of cyber-security controls and obtaining audit evidence.Design/methodology/approachThe paper starts with an identification of the applicable cyber-testing techniques and evaluates their applicability to generally accepted assurance schemes and cyber-security guidelines.FindingsCyber-testing techniques are providing insight in the effectiveness of the actual implementation of cyber-security controls, which may significantly deviate from the conceptual designs of these controls. Furthermore, cyber-testing techniques could provide concise input for cyber-risk management and improvement recommendations.Originality/valueThe presented cyber-testing techniques could complement traditional process-oriented assurance techniques with specialized technical analyses of real-world implementations that focus on the adversaries’ viewpoint. http://www.deepdyve.com/assets/images/DeepDyve-Logo-lg.png Managerial Auditing Journal Emerald Publishing

Obtaining reasonable assurance on cyber resilience

Managerial Auditing Journal , Volume 36 (2): 25 – May 12, 2021

Loading next page...
 
/lp/emerald-publishing/obtaining-reasonable-assurance-on-cyber-resilience-Ca8x1Hjuwm

References (28)

Publisher
Emerald Publishing
Copyright
© Emerald Publishing Limited
ISSN
0268-6902
DOI
10.1108/maj-11-2017-1690
Publisher site
See Article on Publisher Site

Abstract

The purpose of this paper is to highlight the potential of cyber-testing techniques in assessing the effectiveness of cyber-security controls and obtaining audit evidence.Design/methodology/approachThe paper starts with an identification of the applicable cyber-testing techniques and evaluates their applicability to generally accepted assurance schemes and cyber-security guidelines.FindingsCyber-testing techniques are providing insight in the effectiveness of the actual implementation of cyber-security controls, which may significantly deviate from the conceptual designs of these controls. Furthermore, cyber-testing techniques could provide concise input for cyber-risk management and improvement recommendations.Originality/valueThe presented cyber-testing techniques could complement traditional process-oriented assurance techniques with specialized technical analyses of real-world implementations that focus on the adversaries’ viewpoint.

Journal

Managerial Auditing JournalEmerald Publishing

Published: May 12, 2021

Keywords: Cyber risk; Cyber security; IT audit; Cyber assurance; Cyber resilience; Cyber security testing

There are no references for this article.