Cyber insurance, which protects insured organizations against financial losses from cyberattacks and data breaches, can be difficult and expensive to obtain for many organizations. These difficulties stem from insurers difficulty in understanding and accurately assessing the risks that they are undertaking. Cybersecurity audits, which are already implemented in many organizations for compliance and other purposes, present a potential solution to this challenge. This paper provides a structured review and analysis of prior work in this area, analysis of the challenges and potential benefits that cyber audits provide and recommendations for the use of cyber audits to reduce cyber insurance costs and improve its availability.
翻译:网络安全保险旨在保护投保组织免受网络攻击和数据泄露造成的财务损失,然而对许多组织而言,获取此类保险既困难又昂贵。这些困难源于保险公司难以理解和准确评估其承担的风险。已在众多组织中为合规等目的实施的网络安全审计,为应对这一挑战提供了潜在的解决方案。本文对该领域的已有研究进行了系统性综述与分析,剖析了网络安全审计带来的挑战与潜在效益,并就如何利用网络安全审计降低网络安全保险成本并提升其可及性提出了建议。