Pre-studies in information security – cyber situational awareness, virtualised staging environments and data-centric security
Publish date: 2021-01-28
Report number: FOI-R--5068--SE
Pages: 51
Written in: Swedish
Keywords:
- cyber-situational awareness
- cyber-situation awareness
- virtualized staging environments
- data-centric security
Abstract
This report presents three pre-studies carried out in 2020 within the research and development project IT Security Methods. The purpose of the pre-studies is to investigate new research areas and identify research questions that are suitable for in-depth studies. The pre-studies include the subject areas (1) cybersituational awareness, (2) virtualised staging environments, and (3) data-centric security. The subject areas was discussed in a series of workshops with stakeholders from the Swedish Armed Forces, the Swedish Defence Materiel Administration, the Swedish Defence and Research Agency and the Royal Institute of Technology. The three pre-studies have each resulted in a number of research questions that was deemed relevant and researchable according to set criteria. For cyber-situational awareness, research questions was identified about the need for information, how the information should be presented and how the information should be technically produced and analysed. In addition, it was identified that threats and risks toward systems for cyber-situational awareness need to be analysed. In virtualized reference environments, questions was identified regarding which cybersecurity risks can be tested or practiced in a virtualized reference environment and what knowledge of a system is needed to build a virtualized copy of its physical counterpart. In data-centered security, research questions have been identified regarding automatic labeling of data, multi-layered security and artificial intelligence, as well as how systems can be built that have both high availability and the required protection of data.