Authors:
Jan Evang
1
;
2
Affiliations:
1
Oslo Metropolitan University, Oslo, Norway
;
2
Simula Metropolitan Center for Digital Engineering, Oslo, Norway
Keyword(s):
Risk Assessment, Availability Management.
Abstract:
Effective management of service availability risk is a critical aspect of Network Operations Centers (NOCs) as network uptime is a key performance indicator. However, commonly used risk classification systems such as ISO27001:2013, NIST CSF, and NIST 800-53 often do not prioritize network availability, resulting in the potential oversight of certain risks and ambiguous classifications. This paper presents a comprehensive examination of network availability risk and proposes a 10-layer model that aligns closely with the operational framework of NOCs. The 10-layer model encompasses hardware risk, risks across various network layers, as well as external risks such as cloud, human errors, and political governance. By adopting this model, critical risks are less likely to be overlooked, and the NOC’s risk management process is streamlined. The paper outlines each layer of the model, provides illustrative examples of related risks and outages, and presents the successful evaluation of the
model on two real-life networks, where all risks were identified and appropriately classified.
(More)