Bu çalışmanın amacı Küresel Siber Güvenlik İndeksi’nde (2024) [(GCI (2024)] yer alan Karadeniz Ekonomik İşbirliği Örgütü (KEİ) üyesi ülkelerin siber güvenlik performanlarının belirlenmesidir. Ülkelerin siber güvenlik performanslarının belirlenmesinde Çok Kriterli Karar Verme (ÇKKV) yöntemlerinden yararlanılmıştır. GCI’de (2024) yasal ölçümler, teknik ölçümler, organizasyonel ölçümler, kapasite gelişimi ölçümleri ve işbirliği ölçümleri olmak üzere beş temel kriter yer almaktadır. Çalışma kapsamında mevcut indekste yer alan kriterlerin ağırlıklandırılmasında SD (Standard Deviation) ve MEREC (Method based on the Removal Effects of Criteria); ülkelerin siber güvenlik performansı açısından sıralanmasında ise CoCoSo yönteminden yararlanılmış olup her iki ağırlıklandırma yönteminden elde edilen sonuçlar doğrultusunda ülke sıralamaları karşılaştırılmıştır. Yapılan analizler doğrultusunda SD yöntemine göre en yüksek önem derecesine sahip kriter kapasite gelişimi ölçümleri kriteri; MEREC yöntemine göre ise en yüksek önem derecesine sahip kriter organizasyonel ölçümler kriteri olarak belirlenmiştir. Ülkelerin siber güvenlik performanslarının sıralanması amacıyla SD-CoCoSo ve MEREC-CoCoSo yöntemlerinin uygulanması sonucunda bulguların birbirleriyle büyük ölçüde tutarlı olduğu tespit edilmiştir. Siber güvenlik performansı açısından en yüksek performansa sahip ülkeler SD tabanlı CoCoSo yöntemine göre Türkiye, Yunanistan ve Sırbistan olarak sıralanırken; en düşük performans sergileyen ülkelerin Ermenistan, Moldova ve Kuzey Makedonya olduğu sonucuna ulaşılmıştır. MEREC-CoCoSo yöntemlerinin birlikte uygulanması ile ülkelerin SD-CoCoSo yöntemi sonuçlarına benzer şekilde en yüksek performansı sırasıyla Türkiye, Yunanistan ve Sırbistan’ın sergilediği; Ermenistan Ermenistan, Moldova ve Kuzey Makedonya’nın ise son sıralarda yer aldığı görülmüştür.
The aim of this study is to determine the cybersecurity performance of the Black Sea Economic Cooperation Organization (BSEC) member countries included in the Global Cybersecurity Index (2024) [(GCI (2024)]. Multi-Criteria Decision Making Techniques (MCDM) were used to determine the cybersecurity performance of the countries. The GCI (2024) includes five main criteria: legal measures, technical measures, organizational measures, capacity building measures, and cooperation measures. In this study, the SD and MEREC methods were used to weight the criteria in the current index, and the CoCoSo method was used to rank the countries in terms of cybersecurity performance. The results obtained from both methods were compared. According to the analyses, the criterion with the highest importance level according to the SD (Standard Deviation) method was the capacity building measures criterion; according to the MEREC (Method based on the Removal Effects of Criteria) method, the criterion with the highest importance level was the organizational measures criterion. As a result of applying the SD-CoCoSo and MEREC-CoCoSo methods to rank the cybersecurity performance of the countries, it was determined that the findings were largely consistent with each other. In terms of cybersecurity performance, the countries with the highest performance according to the SD-based CoCoSo method were ranked as Turkey, Greece, and Serbia; while the countries with the lowest performance were found to be Armenia, Moldova, and North Macedonia. When the MEREC-CoCoSo methods were applied together, similar to the SD-CoCoSo method results, it was observed that Turkey, Greece, and Serbia exhibited the highest performance in that order, while Armenia, Moldova, and North Macedonia were at the bottom.
Cybersecurity Performance, MCDM, SD Method, MEREC Method, CoCoSo Method