Home / Current Issue / Paper 1707181
Cyber Risk Assessment Frameworks for Protecting U.S. Critical Infrastructure Against Emerging Threats
Subject area: Science,Engineering and Technology · Area of research: Cyber Security
Abstract
The United States' critical infrastructure is essential for national security, economic stability, and public safety. However, the increasing frequency and sophistication of cyber-attacks present significant risks to these vital systems. This research aims to explore the effectiveness of various cyber risk assessment frameworks in protecting U.S. critical infrastructure from emerging cyber threats. Through an in-depth analysis of existing frameworks, such as the NIST Cybersecurity Framework (CSF), ISO/IEC 27001, and others, the study evaluates their suitability, applicability, and adaptability in the face of evolving cyber threats. By identifying gaps and challenges, the research offers recommendations for enhancing these frameworks to better address emerging threats. The findings of this study contribute to the ongoing efforts of securing critical infrastructure, supporting the development of proactive strategies for risk management in the cybersecurity domain.
Keywords
Cyber risk assessment, critical infrastructure, cybersecurity frameworks, emerging threats, risk management, NIST Cybersecurity Framework, ISO/IEC 27001
References
[1] Anderson, R., Barton, C., Böhme, R., Clayton, R., van Eeten, M., Levi, M., … Moore, T. (2020). Measuring the costs of cybercrime. Journal of Cybersecurity, 6(1), taaa007. https://doi.org/10.1093/cybsec/taaa007
[2] Clarke, R. A., & Knake, R. K. (2010). Cyber War: The Next Threat to National Security and What to Do About It . HarperCollins Publishers.
[3] International Organization for Standardization/International Electrotechnical Commission (ISO/IEC). (2018). Information technology — Security techniques — Information security risk management (ISO/IEC 27005:2018). ISO/IEC.
[4] National Institute of Standards and Technology (NIST). (2018). Framework for Improving Critical Infrastructure Cybersecurity (Version 1.1). U.S. Department of Commerce. https://www.nist.gov/cyberframework
[5] U.S. Department of Energy. (2021). Colonial Pipeline Incident Response Report . Office of Cybersecurity, Energy Security, and Emergency Response. https://www.energy.gov/ceser/articles/colonial-pipeline-incident-response-report
[6] Anderson, R., Barton, C., Böhme, R., Clayton, R., van Eeten, M., Levi, M., … Moore, T. (2020). Measuring the costs of cybercrime. Journal of Cybersecurity, 6(1), taaa007. https://doi.org/10.1093/cybsec/taaa007
[7] Cherepanov, A. (2016). Industroyer: Biggest threat to industrial control systems since Stuxnet . Kaspersky Lab. https://securelist.com/industroyer/78612/
[8] Clarke, R. A., & Knake, R. K. (2010). Cyber War: The Next Threat to National Security and What to Do About It . HarperCollins Publishers.
[9] Dinh, H. T., & Liang, W. (2019). IoT security: Review, challenges, and opportunities. IEEE Internet of Things Journal , 6(3), 4818–4834. https://doi.org/10.1109/JIOT.2019.2908035
[10] European Union Agency for Cybersecurity (ENISA). (2020). Threat Landscape for 5G Networks. https://www.enisa.europa.eu/publications/threat-landscape-for-5g-networks
[11] Federal Bureau of Investigation (FBI). (2020). Ransomware Attack on Universal Health Services. FBI Press Release. https://www.fbi.gov/news/stories/ransomware-attack-on-universal-health-services
[12] FireEye. (2020). SUNBURST: Adversary Exploitation of SolarWinds Orion Platform. FireEye Blog. https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
[13] International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC). (2013). Information technology — Security techniques — Information security management systems — Requirements (ISO/IEC 27001:2013). ISO/IEC.
[14] National Institute of Standards and Technology (NIST). (2018). Framework for Improving Critical Infrastructure Cybersecurity (Version 1.1). U.S. Department of Commerce. https://www.nist.gov/cyberframework
[15] Cherepanov, A. (2016). Industroyer: Biggest threat to industrial control systems since Stuxnet. Kaspersky Lab. https://securelist.com/industroyer/78612/
[16] Creswell, J. W., & Poth, C. N. (2018). Qualitative inquiry and research design: Choosing among five approaches (4th ed.). Sage Publications.
[17] FireEye. (2020). SUNBURST: Adversary Exploitation of SolarWinds Orion Platform. FireEye Blog. https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html
How to cite this paper
@article{1707181,
author = {Temitope Adeniyan},
title = {Cyber Risk Assessment Frameworks for Protecting U.S. Critical Infrastructure Against Emerging Threats},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {8},
number = {8},
pages = {821-830},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1707181.pdf},
abstract = {The United States' critical infrastructure is essential for national security, economic stability, and public safety. However, the increasing frequency and sophistication of cyber-attacks present significant risks to these vital systems. This research aims to explore the effectiveness of various cyber risk assessment frameworks in protecting U.S. critical infrastructure from emerging cyber threats. Through an in-depth analysis of existing frameworks, such as the NIST Cybersecurity Framework (CSF), ISO/IEC 27001, and others, the study evaluates their suitability, applicability, and adaptability in the face of evolving cyber threats. By identifying gaps and challenges, the research offers recommendations for enhancing these frameworks to better address emerging threats. The findings of this study contribute to the ongoing efforts of securing critical infrastructure, supporting the development of proactive strategies for risk management in the cybersecurity domain.},
keywords = {Cyber risk assessment, critical infrastructure, cybersecurity frameworks, emerging threats, risk management, NIST Cybersecurity Framework, ISO/IEC 27001},
month = {February},
}