DOE OSTI · 2480935
Integrating Cyber-Informed Engineering into Enterprise Risk Management
Abstract
This document supports the application of Cyber-Informed Engineering (CIE) within the context of Enterprise Risk Management (ERM) to enhance cyber-resilience. It highlights that many critical infrastructure organizations use ERM to manage business risks and emphasizes the importance of evaluating critical systems and assets. The proposed approach can be adopted independently of formal ERM processes and offers a starting point for integrating CIE alongside existing or new ERM practices. Both CIE and ERM are iterative, and their alignment fosters continuous improvement and supports the engineering and operations cultures of an organization.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Ohrt, Andrew, Jones, Amanda, Smith, Jeremy, Wright, Virginia L., Lampe, Benjamin Ruhlig, Stolworthy, Remy Vanece. 2024-09-30. Integrating Cyber-Informed Engineering into Enterprise Risk Management. https://doi.org/10.2172/2480935
Cite the original work for its findings. Save a collection to share your selection of sources.