Towards a Comprehensive Cybersecurity Information Sharing Framework
DOI:
https://doi.org/10.34190/eccws.24.1.3628Keywords:
Information sharing, Framework, Threat intelligent, Cybersecurity, Information exchangeAbstract
In today's digital age, cybersecurity has become a critical concern for nations around the world. With South Africa facing a significant cybersecurity challenge, ranking as the most targeted country on the African continent. The number and sophistication of cyber-attacks such as ransomware attacks, data breaches, phishing and pharming attacks have been steadily rising in recent years with the public sector and financial institutions being highly prone to these attacks. As cyber threats grow in sophistication and frequency, the need for robust defences and proactive measures is of high importance. Information sharing helps organizations and governments to analyse and understand existing cyber-attack trends and use the intelligence gathered to prevent future cyber-attacks, this helps to improve their overall security posture. It is evident from several scholars that organizations that share cybersecurity information have a high probability of reducing cyber-attacks within their environments. Most scholars agrees that, generally, information sharing, and collaboration may greatly reduce cybersecurity risk while ensuring resilience. But confusion and controversy remain around the following particulars such as: Who should share information? What should be shared? When should it be shared? What is the quality and utility of what is shared? How should it be shared? Why is it being shared? What can be done with the information? This paper therefore seeks to analyse the existing Cybersecurity information sharing frameworks, highlight the gaps and propose a comprehensive framework. Firstly, the paper formulates metrics that are used to evaluate the various identified frameworks, then compare and contract them. We then formulate a comprehensive information sharing framework building from the identified gaps. The proposed framework will then be adopted and used by various stakeholders, such as cybersecurity organizations, government bodies, and security experts who intend to share cybersecurity information.
Downloads
Published
Issue
Section
License
Copyright (c) 2025 European Conference on Cyber Warfare and Security

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.