TY - GEN
T1 - Conceptualizing Business Process Dependencies That Propagate Cyber Risk
AU - Engelberg, Gal
AU - Hadad, Moshe
AU - Soffer, Pnina
N1 - Publisher Copyright: © The Author(s), under exclusive license to Springer Nature Switzerland AG 2025.
PY - 2025
Y1 - 2025
N2 - This paper explores the propagation of cyber risks within business processes, addressing the lack of process-awareness in existing research, especially regarding dependencies between process model elements. We propose a conceptualization that incorporates process model elements, dependencies, cyber risk events, and inference rules for capturing cascading effects. The conceptualization covers control flow, data flow, and resource-to-activity dependencies. A proof of concept, analyzing risk propagation in a credit evaluation process, demonstrates how confidentiality, integrity, and availability risks cascade across components. Our findings show how this approach uncovers cascading risks, providing insights for cyber risk assessment in interconnected environments.
AB - This paper explores the propagation of cyber risks within business processes, addressing the lack of process-awareness in existing research, especially regarding dependencies between process model elements. We propose a conceptualization that incorporates process model elements, dependencies, cyber risk events, and inference rules for capturing cascading effects. The conceptualization covers control flow, data flow, and resource-to-activity dependencies. A proof of concept, analyzing risk propagation in a credit evaluation process, demonstrates how confidentiality, integrity, and availability risks cascade across components. Our findings show how this approach uncovers cascading risks, providing insights for cyber risk assessment in interconnected environments.
KW - Risk Assessment
KW - Risk Propagation
KW - Secure Business Process
UR - http://www.scopus.com/inward/record.url?scp=105008664835&partnerID=8YFLogxK
U2 - 10.1007/978-3-031-94590-8_11
DO - 10.1007/978-3-031-94590-8_11
M3 - Conference contribution
SN - 9783031945892
T3 - Lecture Notes in Business Information Processing
SP - 86
EP - 94
BT - Intelligent Information Systems - CAiSE 2025 Forum and Doctoral Consortium, Proceedings
A2 - Pufahl, Luise
A2 - Rosenthal, Kristina
A2 - España, Sergio
A2 - Nurcan, Selmin
PB - Springer Science and Business Media Deutschland GmbH
T2 - Forum and the Doctoral Consortium of the 37th International Conference on Advanced Information Systems Engineering, CAiSE 2025
Y2 - 16 June 2025 through 20 June 2025
ER -