• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Requirements for Playbook-Assisted Cyber Incident Response, Reporting and Automation
 
  • Details
  • Full
Options
September 30, 2024
Journal Article
Title

Requirements for Playbook-Assisted Cyber Incident Response, Reporting and Automation

Abstract
Cybersecurity playbooks assume an increasingly important role as threat-specific documents for guiding operators in the context of cyber incident response. However, these playbooks are mostly unstructured or semi-structured, which significantly limits their utility when it comes to automating response and reporting steps, complying with cybersecurity directives, or sharing best practices for incident response across organisations. We thus argue that cybersecurity playbooks must transition to interoperable and machine-readable formats from generation, via management and utilisation to cross-organisational sharing. In this work, we identify and structure key requirements based on expert interviews as a first step toward this transition. From these requirements, we derive a framework for further guidance during the transition to structured security playbooks and their utilisation in a tool-assisted fashion. We discuss the implications of our framework and lessons learned before outlining directions for future research.
Author(s)
Akbari Gurabi, Mehdi  orcid-logo
Fraunhofer-Institut für Angewandte Informationstechnik FIT  
Nitz, Lasse  orcid-logo
Fraunhofer-Institut für Angewandte Informationstechnik FIT  
Bregar, Andrej
Popanda, Jan  
Fraunhofer-Institut für Angewandte Informationstechnik FIT  
Siemers, Christian
Matzutt, Roman  orcid-logo
Fraunhofer-Institut für Angewandte Informationstechnik FIT  
Mandal, Avikarsha  
Fraunhofer-Institut für Angewandte Informationstechnik FIT  
Journal
Digital Threats: Research and Practice  
Open Access
File(s)
Download (1.16 MB)
Rights
CC BY 4.0: Creative Commons Attribution
DOI
10.1145/3688810
10.24406/publica-6523
Additional link
Full text
Language
English
Fraunhofer-Institut für Angewandte Informationstechnik FIT  
Keyword(s)
  • Cybersecurity playbooks

  • response and recovery

  • machine-readability

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024