Lubis Muharman, Safitra Muhammad Fakhrul, Fakhrurroja Hanif, Muttaqin Alif Noorachmad
Master of Information System Study Program, School of Industrial Engineering, Telkom University, Main Campus (Bandung Campus), Jl. Telekomunikasi No. 1, Bandung 40257, West Java, Indonesia.
Department of Network and Security, Pelayaran Nasional Indonesia, Jakarta 10130, Special Capital Region of Jakarta, Indonesia.
Sensors (Basel). 2025 Jul 22;25(15):4545. doi: 10.3390/s25154545.
The increased occurrence and severity of cyber-attacks on critical infrastructure have underscored the need to embrace systematic and prospective approaches to resilience. The current research takes as its hypothesis that the InfraGuard Cybersecurity Framework-a capability model that measures the maturity of cyber resilience through three functional pillars, Cyber as a Shield, Cyber as a Space, and Cyber as a Sword-is an implementable and understandable means to proceed with. The model treats the significant aspects of situational awareness, active defense, risk management, and recovery from incidents and is measured using globally standardized maturity models like ISO/IEC 15504, NIST CSF, and COBIT. The contributions include multidimensional measurements of resilience, a scored scale of capability (0-5), and domain-based classification enabling organizations to assess and enhance their cybersecurity situation in a formalized manner. The framework's applicability is illustrated in three exploratory settings of power grids, healthcare systems, and airports, each constituting various levels of maturity in resilience. This study provides down-to-earth recommendations to policymakers through the translation of the attributes of resilience into concrete assessment indicators, promoting policymaking, investment planning, and global cyber defense collaboration.
对关键基础设施的网络攻击在发生频率和严重程度上的增加,凸显了采用系统和前瞻性方法来增强恢复力的必要性。当前的研究假设,“信息基础设施保护网络安全框架”(一种通过“网络盾牌”“网络空间”和“网络利剑”这三个功能支柱来衡量网络恢复力成熟度的能力模型)是一种可行且易于理解的推进方式。该模型涵盖态势感知、主动防御、风险管理以及事件恢复等重要方面,并使用ISO/IEC 15504、美国国家标准与技术研究院网络安全框架(NIST CSF)和信息及相关技术控制目标(COBIT)等全球标准化的成熟度模型进行衡量。其贡献包括对恢复力的多维度测量、能力评分量表(0至5分)以及基于领域的分类,使组织能够以一种形式化的方式评估和改善其网络安全状况。该框架的适用性在电网、医疗系统和机场这三个探索性场景中得到了说明,每个场景在恢复力方面都构成了不同的成熟度水平。本研究通过将恢复力的属性转化为具体的评估指标,为政策制定者提供了切实可行的建议,促进了政策制定、投资规划以及全球网络防御合作。
Sensors (Basel). 2025-7-22
Sensors (Basel). 2021-7-28
J Med Internet Res. 2024-11-20
Front Public Health. 2025-6-20
JBI Database System Rev Implement Rep. 2016-4
Sensors (Basel). 2023-8-19
Sensors (Basel). 2019-1-3
IEEE Trans Cybern. 2017-9-29