SET-THEORETICAL METRIC MODEL FOR ASSESSING CYBER RESILIENCE OF CRITICAL INFRASTRUCTURE FACILITIES
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1305Keywords:
cyber resilience, cyber resilience assessment, critical infrastructure facilities, cyber resilience metrics, set-theoretic model, set-theoretic approach, MITRE CREF, information security, cybersecurity, information protection.Abstract
The problem of formalized assessment of cyber resilience of critical infrastructure under increasing cyber threat complexity is addressed. Existing approaches are fragmented and lack a strict connection between basic cyber resilience measures and their evaluation metrics. This study aims to develop a set-theoretic metric model that formalizes the set of possible metrics for each base measure. A formal representation of metrics as a function of base measures is proposed, introducing the concept of set cardinality and its dependence on application context. Structural (ex-ante) and operational (ex-post) metrics are integrated within a unified mathematical framework, and a functional mapping “base measure → set of possible metrics” is defined. The results enable a transition to formalized quantitative evaluation and support the development of integral indicators and automated analysis, improving reproducibility, comparability, and validity of cyber resilience assessment.Downloads
References
Bodeau, D., Graubart, R., McQuaid, R., & Woodill, J. (2018). Cyber resiliency metrics, measures of effectiveness, and scoring: Enabling systems engineers and program managers to select the most useful assessment methods. MITRE Technical Report.
Bodeau, D., Brtis, J., Graubart, R., & Salwen, J. (2015). Cyber resiliency engineering aid-The updated cyber resiliency engineering framework and guidance on applying cyber resiliency techniques (MITRE Technical Report MTR150264). MITRE.
Ross, R., Pillitteri, V., Graubart, R., Bodeau, D., & McQuaid, R. (2021). Developing cyber-resilient systems: A systems security engineering approach (NIST Special Publication 800-160, Vol. 2, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-160v2r1
Linkov, I., Eisenberg, D., Plourde, K., et al. (2013). Resilience metrics for cyber systems. Environment Systems and Decisions, 33(4), 471-476. https://doi.org/10.1007/s10669-013-9485-y
Björck, F., Henkel, M., Stirna, J., & Zdravkovic, J. (2015). Cyber resilience-Fundamentals for a definition. In New contributions in information systems and technologies (pp. 311–316). Springer. https://doi.org/10.1007/978-3-319-16486-1_31
Cam, H., Mouallem, P., Mo, J., & Farris, J. (2016). Resilience metrics for cyber systems. INCOSE International Symposium, 26(1), 1476-1489.
Linkov, I., & Kott, A. (2019). Cyber resilience of systems and networks. Springer.
Zio, E. (2016). Challenges in the vulnerability and risk analysis of critical infrastructures. Reliability Engineering & System Safety, 152, 137-150. https://doi.org/10.1016/j.ress.2016.02.009
Petersen, L., Fallou, L., Reilly, P., & Serafinelli, E. (2019). A resilience assessment framework for critical infrastructure. International Journal of Critical Infrastructure Protection, 25, 1-14. https://doi.org/10.1016/j.ijcip.2019.01.002
Yusta, J., Correa, G., & Lacal-Arántegui, R. (2011). Methodologies and applications for critical infrastructure protection: State-of-the-art. Energy Policy, 39(10), 6100-6119. https://doi.org/10.1016/j.enpol.2011.07.010
Rinaldi, S., Peerenboom, J., & Kelly, T. (2001). Identifying, understanding, and analyzing critical infrastructure interdependencies. IEEE Control Systems Magazine, 21(6), 11-25. https://doi.org/10.1109/37.969131
Ouyang, M. (2014). Review on modeling and simulation of interdependent critical infrastructure systems. Reliability Engineering & System Safety, 121, 43-60. https://doi.org/10.1016/j.ress.2013.06.040
Alcaraz, C., & Zeadally, S. (2015). Critical infrastructure protection: Requirements and challenges for the 21st century. International Journal of Critical Infrastructure Protection, 8, 53-66. https://doi.org/10.1016/j.ijcip.2014.12.002
Musman, S., & Temin, A. (2015). A cyber mission impact assessment tool. In IEEE International Symposium on Technologies for Homeland Security (HST) (pp. 1-7).
Falco, G., Caldera, C., & Shrobe, H. (2018). IIoT cybersecurity risk modeling for SCADA systems. IEEE Internet of Things Journal, 5(6), 4486-4495. https://doi.org/10.1109/JIOT.2018.2822842
Haque, M., Shetty, S., & Krishnappa, B. (2020). Cybersecurity resilience model for industrial control systems. IET Cyber-Physical Systems: Theory & Applications, 5(3), 271-282.
Jackson, S., & Ferris, T. (2013). Resilience principles for engineered systems. Systems Engineering, 16(2), 152-164. https://doi.org/10.1002/sys.21228
Rieger, C., Gertman, D., & McQueen, M. (2009). Resilient control systems: Next generation design research. In IEEE Conference on Human System Interactions (pp. 632-636).
Woods, D. (2015). Four concepts for resilience and the implications for the future of resilience engineering. Reliability Engineering & System Safety, 141, 5-9. https://doi.org/10.1016/j.ress.2015.03.018
Stergiopoulos, G., Kotzanikolaou, P., Theocharidou, M., et al. (2016). Time-based critical infrastructure dependency analysis for large-scale and cross-sectoral failures. International Journal of Critical Infrastructure Protection, 12, 46-60. https://doi.org/10.1016/j.ijcip.2015.12.002
Hossain, M., Moniruzzaman, M., Muhammad, G., et al. (2014). Big data-driven service composition using parallel clustered particle swarm optimization in mobile environment. IEEE Transactions on Services Computing, 9(5), 806-817.
Teixeira, A., Shames, I., Sandberg, H., & Johansson, K. H. (2015). A secure control framework for resource-limited adversaries. Automatica, 51, 135-148. https://doi.org/10.1016/j.automatica.2014.10.067
Vugrin, E., Warren, D., Ehlen, M., & Camphouse, R. (2010). A framework for assessing the resilience of infrastructure and economic systems. In Sustainable and resilient critical infrastructure systems (pp. 77-116). Springer. https://doi.org/10.1007/978-3-642-11405-2_3
Hosseini, S., Barker, K., & Ramirez-Marquez, J. (2016). A review of definitions and measures of system resilience. Reliability Engineering & System Safety, 145, 47-61. https://doi.org/10.1016/j.ress.2015.08.006
Ganin, A., Massaro, E., Gutfraind, A., et al. (2016). Operational resilience: Concepts, design and analysis. Scientific Reports, 6(1), 19540. https://doi.org/10.1038/srep19540
Amin, M. (2005). Energy infrastructure defense systems. Proceedings of the IEEE, 93(5), 861-875. https://doi.org/10.1109/JPROC.2005.847254
Pursiainen, C. (2018). Critical infrastructure resilience: A Nordic model in the making? International Journal of Disaster Risk Reduction, 27, 632-641. https://doi.org/10.1016/j.ijdrr.2017.10.007
Theocharidou, M., Kotzanikolaou, P., & Gritzalis, D. (2016). A multi-layer criticality assessment methodology based on interdependencies. Computers & Security, 62, 251-272. https://doi.org/10.1016/j.cose.2016.08.004
Giannopoulos, G., Filippini, R., & Schimmer, M. (2012). Risk assessment methodologies for critical infrastructure protection. Part I: A state of the art (European Commission Joint Research Centre Technical Report 25286).
Setola, R., Rosato, V., Kyriakides, E., & Rome, E. (Eds.). (2016). Managing the complexity of critical infrastructures: A modeling and simulation approach. Springer International Publishing. https://doi.org/10.1007/978-3-319-31074-9
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29
National Institute of Standards and Technology. (2025). Integrating cybersecurity and enterprise risk management (ERM) (NIST IR 8286 Rev. 1). https://doi.org/10.6028/NIST.IR.8286r1
European Parliament & Council of the European Union. (2022). Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA). Official Journal of the European Union, L 333.
MITRE Corporation. (2024). Cyber Resiliency Engineering Framework (CREF) Navigator. The MITRE Corporation.
AlHidaifi, A., et al. (2024). Simulation-based quantification of cyber resilience for critical systems. Decision Support Systems, 178.
Lezzi, M., et al. (2025). Measuring cyber resilience in Industrial IoT: A systematic review. Service Oriented Computing and Applications.
Cho, H., et al. (2025). A quantitative framework for cyber resilience assessment with normalization techniques. Electronics, 14, 2465.
Cybersecurity and Infrastructure Security Agency. (2020). Cyber Resilience Review (CRR): Method description and self-assessment user guide. CISA.
Caralli, R. A., Allen, J. H., & White, D. W. (2011). CERT resilience management model (CERT-RMM): A maturity model for managing operational resilience. Addison-Wesley Professional.
Cyber Resilience Capability Maturity Model (CR-CMM): Standard and tools for organizational resilience assessment. (n.d.). https://cr-cmm.org/
Korchenko, O., Kharchenko, V., Khokhlachova, Yu., & Zhurov, Yu. (2026). Sustainable development of smart regions: A set-theoretic data model for assessing the cyber resilience of critical infrastructure entities. Zviazok, 4, 22-44.
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Олександр Корченко, Юлія Хохлачова

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.