• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

Research on a Technology-Centric Evaluation Framework for Cyber Resilience based on MITRE D3FEND: Supplementing the Practical Application of Assessment Guidelines for Financial Institutions


Gwang-Hyun Ahn, Dong-kyoo Shin, Journal of Internet Computing and Services, Vol. 26, No. 4, pp. 161-177, Aug. 2025
10.7472/jksii.2025.26.4.161, Full Text:  HTML
Keywords: Cyber Resilience, MITRE D3FEND, risk management, Security Assessment

Abstract

While the financial sector's prevailing "Cyber Resilience Assessment Guidelines" offer a governance-based framework for ensuring crisis response, recovery capabilities, and operational continuity, they lack specific criteria to evaluate the practical implementation level or the applied effectiveness of defensive technologies. To bridge this gap, this study aims to design a technology-centric cyber resilience evaluation framework based on the MITRE D3FEND framework, thereby providing a practical supplement to the existing guidelines. n this research, the domains of detection, protection, analysis, and recovery were reconfigured based on D3FEND's Tactics, Techniques, and Procedures (TTPs) classification system, and quantitative indicators such as implementation level and degree of automation were established for each technological component. Furthermore, to secure the scientific validity of the proposed metrics, a systematic metric selection framework was adopted , and the effectiveness of these evaluation metrics was validated through linkage with ATT&CK and CVE information. Furthermore, to validate its effectiveness and feasibility, the proposed framework was objectively verified through a Delphi survey conducted with a panel of security experts. The results of this research can be utilized as a practical assessment tool for strengthening the cyber resilience of financial institutions and are expected to contribute to narrowing the gap between policy formulation and technological application.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Ahn, G. & Shin, D. (2025). Research on a Technology-Centric Evaluation Framework for Cyber Resilience based on MITRE D3FEND: Supplementing the Practical Application of Assessment Guidelines for Financial Institutions. Journal of Internet Computing and Services, 26(4), 161-177. DOI: 10.7472/jksii.2025.26.4.161.

[IEEE Style]
G. Ahn and D. Shin, "Research on a Technology-Centric Evaluation Framework for Cyber Resilience based on MITRE D3FEND: Supplementing the Practical Application of Assessment Guidelines for Financial Institutions," Journal of Internet Computing and Services, vol. 26, no. 4, pp. 161-177, 2025. DOI: 10.7472/jksii.2025.26.4.161.

[ACM Style]
Gwang-Hyun Ahn and Dong-kyoo Shin. 2025. Research on a Technology-Centric Evaluation Framework for Cyber Resilience based on MITRE D3FEND: Supplementing the Practical Application of Assessment Guidelines for Financial Institutions. Journal of Internet Computing and Services, 26, 4, (2025), 161-177. DOI: 10.7472/jksii.2025.26.4.161.