Cybersecurity Standards in the Context of Operating System

Syed Wasif Abbas Hamdani,Haider Abbas,Abdul Rehman Janjua,Waleed Bin Shahid,Muhammad Faisal Amjad,Jahanzaib Malik,Malik Hamza Murtaza,Mohammed Atiquzzaman,Abdul Waheed Khan
DOI: https://doi.org/10.1145/3442480
IF: 16.6
2021-06-01
ACM Computing Surveys
Abstract:Cyber threats have been growing tremendously in recent years. There are significant advancements in the threat space that have led towards an essential need for the strengthening of digital infrastructure security. Better security can be achieved by fine-tuning system parameters to the best and optimized security levels. For the protection of infrastructure and information systems, several guidelines have been provided by well-known organizations in the form of cybersecurity standards. Since security vulnerabilities incur a very high degree of financial, reputational, informational, and organizational security compromise, it is imperative that a baseline for standard compliance be established. The selection of security standards and extracting requirements from those standards in an organizational context is a tedious task. This article presents a detailed literature review, a comprehensive analysis of various cybersecurity standards, and statistics of cyber-attacks related to operating systems (OS). In addition to that, an explicit comparison between the frameworks, tools, and software available for OS compliance testing is provided. An in-depth analysis of the most common software solutions ensuring compliance with certain cybersecurity standards is also presented. Finally, based on the cybersecurity standards under consideration, a comprehensive set of minimum requirements is proposed for OS hardening and a few open research challenges are discussed.
computer science, theory & methods
What problem does this paper attempt to address?