TELSAFE: Security Gap Quantitative Risk Assessment Framework

📅 2025-07-08
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
A persistent gap between security standards and their practical implementation often introduces compliance risks, while existing assessment methods suffer from subjectivity and poor cross-organizational consistency. To address this, we propose a novel hybrid risk assessment framework: first, standardized compliance analysis identifies regulatory gaps; second, an expert-independent probabilistic model enables objective, quantitative risk evaluation; third, integration of CVE vulnerability data validates the framework in real-world telecommunications scenarios. Our approach significantly improves risk quantification accuracy and reproducibility, supports organization-specific risk management customization, and demonstrates strong generalizability across multiple regulated industries. Experimental results confirm enhanced reliability and scalability compared to conventional qualitative or expert-driven methodologies.

Technology Category

Application Category

📝 Abstract
Gaps between established security standards and their practical implementation have the potential to introduce vulnerabilities, possibly exposing them to security risks. To effectively address and mitigate these security and compliance challenges, security risk management strategies are essential. However, it must adhere to well-established strategies and industry standards to ensure consistency, reliability, and compatibility both within and across organizations. In this paper, we introduce a new hybrid risk assessment framework called TELSAFE, which employs probabilistic modeling for quantitative risk assessment and eliminates the influence of expert opinion bias. The framework encompasses both qualitative and quantitative assessment phases, facilitating effective risk management strategies tailored to the unique requirements of organizations. A specific use case utilizing Common Vulnerabilities and Exposures (CVE)-related data demonstrates the framework's applicability and implementation in real-world scenarios, such as in the telecommunications industry.
Problem

Research questions and friction points this paper is trying to address.

Assesses gaps between security standards and implementation risks
Introduces TELSAFE for quantitative risk assessment without bias
Demonstrates framework applicability using CVE data in telecom
Innovation

Methods, ideas, or system contributions that make the work stand out.

Hybrid risk assessment framework TELSAFE
Probabilistic modeling for quantitative assessment
Combines qualitative and quantitative risk phases
🔎 Similar Papers
No similar papers found.
Sarah Ali Siddiqui
Sarah Ali Siddiqui
Data 61, CSIRO
Chandra Thapa
Chandra Thapa
CSIRO Data61
Collaborative Machine LearningQuantum Machine LearningCybersecurityNetwork Information Theory
D
Derui Wang
CSIRO Data61, Sydney, Australia
Rayne Holland
Rayne Holland
Postdoctoral Fellow, CSIRO
data privacynetwork securitydata structures
W
Wei Shao
CSIRO Data61, Sydney, Australia
S
Seyit Camtepe
CSIRO Data61, Sydney, Australia
Hajime Suzuki
Hajime Suzuki
CSIRO
R
Rajiv Shah
MDR Security, Canberra, Australia