Szczegóły publikacji

Opis bibliograficzny

Balancing cybersecurity in a supply chain under direct and indirect cyber risks / Tadeusz SAWIK // International Journal of Production Research ; ISSN 0020-7543. — 2022 — vol. 60 no. 2, s. 766-782. — Bibliogr. s. 782, Abstr. — Publikacja dostępna online od: 2021-04-20. — Dod. afiliacja: Reykjavik University, Reykjavik, Iceland


Autor


Słowa kluczowe

mixed integer linear programmingcybersecurity investmentcyber risk managementportfolio of security controlssupply chain cybersecurity

Dane bibliometryczne

ID BaDAP139232
Data dodania do BaDAP2022-02-24
Tekst źródłowyURL
DOI10.1080/00207543.2021.1914356
Rok publikacji2022
Typ publikacjiartykuł w czasopiśmie
Otwarty dostęptak
Czasopismo/seriaInternational Journal of Production Research

Abstract

Cybersecurity is an essential requirement for the sustainability of global supply chains. In this paper, a stochastic programming formulation is presented for optimisation of cybersecurity investment and selection of security controls to mitigate and balance the impact of direct and indirect (propagated) cyber risks in a multi-tier supply chain. Using a network transformation combined with the first-order Taylor series approximation of natural logarithm to linearise the nonlinear constraints, a nonlinear stochastic combinatorial optimisation model is approximated by its linear equivalent. The problem objective is to determine an optimal cybersecurity investment under limited budget and portfolio of security controls for each supply chain node to balance the cybersecurity over the entire supply chain. The minmax objective functions are applied to minimise either the maximum breach probability or the maximum loss of supply chain nodes. Alternatively, maxmin objectives are used to maximise either the minimum non-breach probability or the minimum saving of loss. The proposed integrated modelling approach is illustrated with results of computational study and a comparison of approximated and exact solution values is presented. The decision-making insights are provided and discussed.

Publikacje, które mogą Cię zainteresować

artykuł
A linear model for optimal cybersecurity investment in Industry 4.0 supply chains / Tadeusz SAWIK // International Journal of Production Research ; ISSN 0020-7543. — 2022 — vol. 60 no. 4, s. 1368-1385. — Bibliogr. s. 1383-1384, Abstr. — Publikacja dostępna online od: 2020-12-08. — Dod. afiliacja: Department of Engineering, Reykjavik University, Reykjavik, Iceland
artykuł
A rough cut cybersecurity investment using portfolio of security controls with maximum cybersecurity value / Tadeusz SAWIK, Bartosz SAWIK // International Journal of Production Research ; ISSN 0020-7543. — 2022 — vol. 60 no. 21, s. 6556–6572. — Bibliogr. s. 6569–6570, Abstr. — Publikacja dostępna online od: 2021-11-05. — T. Sawik - dod. afiliacja: Reykjavik University, Reykjavik, Iceland ; B. Sawik - dod. afiliacje: Public University of Navarre, Pamplona, Spain; University of California, Berkeley, USA