{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/157124"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/157124","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Quantifying the Severity of a Cybersecurity Incident for Incident Reporting","abstract":"In the field of cybersecurity, the lack of standardized data collection and incident reporting methods pose significant challenges to address and respond to incidents affecting critical infrastructure. Various initiatives aim to resolve this issue by mandating the collection of data on cyber incidents; however, there is often a lack of clear guidelines on how the collected data will be utilized effectively. This paper introduces the Cyber Incident Severity Scale (CISS), a framework designed to guide the selection of relevant data for analysis and communicate the severity of a cybersecurity incident. By drawing insights from established scales in other fields, such as natural disasters and public health, this research produces a single score for a reporting entity which can be aggregated to determine the overall severity of an incident. The ability to swiftly assess and score an incident is a critical tool to quantify incident severity and prioritize response, support policy development, and bolster the overall security of critical infrastructure.","abstract_html":"In the field of cybersecurity, the lack of standardized data collection and incident reporting methods pose significant challenges to address and respond to incidents affecting critical infrastructure. Various initiatives aim to resolve this issue by mandating the collection of data on cyber incidents; however, there is often a lack of clear guidelines on how the collected data will be utilized effectively. This paper introduces the Cyber Incident Severity Scale (CISS), a framework designed to guide the selection of relevant data for analysis and communicate the severity of a cybersecurity incident. By drawing insights from established scales in other fields, such as natural disasters and public health, this research produces a single score for a reporting entity which can be aggregated to determine the overall severity of an incident. The ability to swiftly assess and score an incident is a critical tool to quantify incident severity and prioritize response, support policy development, and bolster the overall security of critical infrastructure.","abstract_has_math":false,"creators":["Conard, Chelsea Foushee"],"institution":"Massachusetts Institute of Technology","degree_name":"Master","degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Institute for Data, Systems, and Society","school":null,"contributors":[],"advisors":["Reynolds, Taylor","Weitzner, Daniel J."],"committee_chairs":[],"committee_members":[],"year":2024,"date_issued":"2024-09","date_published":"2024-09","updated_at":"2026-07-22T22:21:12Z","subjects":[],"languages":[],"rights":["Attribution-NonCommercial-NoDerivatives 4.0 International (CC BY-NC-ND 4.0)","Copyright retained by author(s)"],"rights_urls":["https://creativecommons.org/licenses/by-nc-nd/4.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1721.1/157124","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Reynolds, Taylor","Weitzner, Daniel J."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Institute for Data, Systems, and Society"]},{"key":"dc:creator","label":"Author","values":["Conard, Chelsea Foushee"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2024-10-02T17:32:04Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2024-10-02T17:32:04Z"]},{"key":"dc:date.issued","label":"Date","values":["2024-09"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master","Master of Science in Technology and Policy"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["Attribution-NonCommercial-NoDerivatives 4.0 International (CC BY-NC-ND 4.0)","Copyright retained by author(s)"]},{"key":"dc:rights.uri","label":"Rights URI","values":["https://creativecommons.org/licenses/by-nc-nd/4.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1721.1/157124"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["In the field of cybersecurity, the lack of standardized data collection and incident reporting methods pose significant challenges to address and respond to incidents affecting critical infrastructure. Various initiatives aim to resolve this issue by mandating the collection of data on cyber incidents; however, there is often a lack of clear guidelines on how the collected data will be utilized effectively. This paper introduces the Cyber Incident Severity Scale (CISS), a framework designed to guide the selection of relevant data for analysis and communicate the severity of a cybersecurity incident. By drawing insights from established scales in other fields, such as natural disasters and public health, this research produces a single score for a reporting entity which can be aggregated to determine the overall severity of an incident. The ability to swiftly assess and score an incident is a critical tool to quantify incident severity and prioritize response, support policy development, and bolster the overall security of critical infrastructure."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["S.M."]},{"key":"dc:title","label":"Title","values":["Quantifying the Severity of a Cybersecurity Incident for Incident Reporting"]}]}],"canonical_facts":{"dc:contributor.advisor":["Reynolds, Taylor","Weitzner, Daniel J."],"dc:contributor.department":["Massachusetts Institute of Technology. Institute for Data, Systems, and Society"],"dc:creator":["Conard, Chelsea Foushee"],"dc:date.accessioned":["2024-10-02T17:32:04Z"],"dc:date.available":["2024-10-02T17:32:04Z"],"dc:date.issued":["2024-09"],"dc:description.abstract":["In the field of cybersecurity, the lack of standardized data collection and incident reporting methods pose significant challenges to address and respond to incidents affecting critical infrastructure. Various initiatives aim to resolve this issue by mandating the collection of data on cyber incidents; however, there is often a lack of clear guidelines on how the collected data will be utilized effectively. This paper introduces the Cyber Incident Severity Scale (CISS), a framework designed to guide the selection of relevant data for analysis and communicate the severity of a cybersecurity incident. By drawing insights from established scales in other fields, such as natural disasters and public health, this research produces a single score for a reporting entity which can be aggregated to determine the overall severity of an incident. The ability to swiftly assess and score an incident is a critical tool to quantify incident severity and prioritize response, support policy development, and bolster the overall security of critical infrastructure."],"dc:description.degree":["S.M."],"dc:identifier.uri":["https://hdl.handle.net/1721.1/157124"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["Attribution-NonCommercial-NoDerivatives 4.0 International (CC BY-NC-ND 4.0)","Copyright retained by author(s)"],"dc:rights.uri":["https://creativecommons.org/licenses/by-nc-nd/4.0/"],"dc:title":["Quantifying the Severity of a Cybersecurity Incident for Incident Reporting"],"dc:type":["Thesis"],"thesis:degree_name":["Master","Master of Science in Technology and Policy"]},"updated_at":"2026-07-22T22:21:12Z"}