How Do Organizations Seek Cyber Assurance? Investigations on the Adoption of the Common Criteria and Beyond
Nan Sun, Chang-Tsun Li, Hin Chan, Md Zahidul Islam, Md Rafiqul Islam,, Warren Armstrong

TL;DR
This paper investigates how organizations adopt cybersecurity standards like the Common Criteria, identifies barriers to adoption, and explores additional risk management strategies to enhance cyber assurance across various sectors.
Contribution
It provides empirical insights into adoption barriers of cybersecurity standards and offers recommendations to promote their use, along with exploring alternative risk management strategies.
Findings
Identified seven barriers to adopting the Common Criteria
Surveyed 258 participants across sectors and countries
Provided recommendations for increasing cybersecurity standards adoption
Abstract
Cyber assurance, which is the ability to operate under the onslaught of cyber attacks and other unexpected events, is essential for organizations facing inundating security threats on a daily basis. Organizations usually employ multiple strategies to conduct risk management to achieve cyber assurance. Utilizing cybersecurity standards and certifications can provide guidance for vendors to design and manufacture secure Information and Communication Technology (ICT) products as well as provide a level of assurance of the security functionality of the products for consumers. Hence, employing security standards and certifications is an effective strategy for risk management and cyber assurance. In this work, we begin with investigating the adoption of cybersecurity standards and certifications by surveying 258 participants from organizations across various countries and sectors.…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
