Authors:
Fernando Rocha Moreira
1
;
Edna Canedo
1
;
Rafael Rabelo Nunes
2
;
André Serrano
3
;
Cláudia Jacy Barenco Abbas
4
;
Marcelo Lopes Pereira Júnior
4
and
Fábio Lopes de Mendonça
4
Affiliations:
1
University of Brasília (UnB), Department of Computer Science, Brasília–DF, Brazil
;
2
UniAtenas University Center, Paracatu-MG, Brazil
;
3
University of Brasília (UnB), Professional Postgraduate Program in Electrical Engineering - PPEE, Brasília–DF, Brazil
;
4
University of Brasília (UnB), Department of Electrical Engineering, Brasília–DF, Brazil
Keyword(s):
Cybersecurity Risk Management, NIST Cybersecurity Framework, Analytic Hierarchy Process, Multicriteria Decision-Making, Public Sector Cybersecurity.
Abstract:
Context: Cybersecurity is increasingly critical for public institutions, particularly as digital transformations expose them to a wide range of cybersecurity risks. Managing these risks effectively requires a structured approach that aligns with recognized standards and frameworks. Methods: This study presents the process of cybersecurity risk management within a Brazilian public agency, utilizing the cybersecurity incident detection controls proposed by the NIST Cybersecurity Framework (NIST-CSF). To assess and prioritize these controls, the Analytic Hierarchy Process (AHP) was applied as a multicriteria decision-making method. Expert judgments were collected and integrated into the AHP model to determine the relative importance of each control. Results: The application of the AHP method resulted in a prioritized list of cybersecurity controls. This list outlines the sequence in which controls should be implemented, enabling decision-makers to direct resources effectively and make i
nformed choices in mitigating cybersecurity risks. Conclusion: The findings underscore the value of adopting multicriteria methods like AHP in cybersecurity risk management. This paper contributes to the literature by encouraging the use of such methods as best practices for improving cybersecurity risk assessment and management in public sector organizations.
(More)