search

CSGE Cybersecurity Goal Elicitation

# PROCESS PURPOSE 
The purpose is to derive cybersecurity goals and to ensure traceability between the cybersecurity assessment and the cybersecurity goals.

# PROCESS OUTCOMES 
  • O1 Threats are analyzed and cybersecurity evaluated
  • O2 Cybersecurity treatment options are determined
  • O3 Cybersecurity goals are defined for reduction and avoidance
  • O4 Traceability is established between the cybersecurity goals and the threat scenarios

# BASE PRACTICES 
BP1 Analyze threats and evaluate cybersecurity risks. ( O1 )
BP2 Define cybersecurity risk treatment option. ( O2 )
BP3 Derive and align cybersecurity goals for risk reduction and avoidance. ( O3 )
BP4 Establish traceability between the cybersecurity goals and the threat scenarios. ( O4 )

# OUTPUT INFORMATION ITEMS 
13-51 Consistency Evidence ( O4 )
17-51 Cybersecurity goals ( O3 )
14-51 Cybersecurity scenario register ( O1 )
13-20 Risk action request ( O2 )
15-08 Risk analysis ( O1, O2 )
08-55 Risk measure ( O2, O3 )