Skip to main content Skip to footer site map
Updates

A Methodology for Quantifying the Value of Cybersecurity Investments in the Navy : RAND Corporation , 2022

2022

RAND Corporation

Download PDF

From the abstract: "RAND Corporation researchers developed and supported the implementation of a methodology to assess the value of resource options for U.S. Navy cybersecurity investments. The proposed methodology features 12 scales in two categories (impact and exploitability) that allow the Navy to score potential cybersecurity investments in the Program Objective Memorandum (POM) process. The authors include a test implementation using publicly available historical U.S. Navy data to demonstrate how the methodology facilitates valuable comparisons of potential cybersecurity investments.

When compared with existing methods used by the Navy, this methodology could improve the consistency of ratings and provide a more defined structure for thinking through the risk reduction and prioritization of different investments."

Authors - Wilson, Bradley, Arena, Mark, Mayer, Lauren A., Heitzenrater, Chad, Mastbaum, Jason, Connolly, Kevin J.

Subjects

Authors

Wilson, Bradley, Arena, Mark, Mayer, Lauren A., Heitzenrater, Chad, Mastbaum, Jason, Connolly, Kevin J.

Publishers

RAND Corporation

Format

PDF - Download

Related Resources

s