Traceable Security-by-Design Decisions for Cyber-Physical Systems (CPSs) by Means of Function-Based Diagrams and Security Libraries.
cyber-physical systems
cybersecurity
function-based engineering
industrial control systems
security by design
visualization
Journal
Sensors (Basel, Switzerland)
ISSN: 1424-8220
Titre abrégé: Sensors (Basel)
Pays: Switzerland
ID NLM: 101204366
Informations de publication
Date de publication:
13 Jun 2023
13 Jun 2023
Historique:
received:
08
05
2023
revised:
05
06
2023
accepted:
08
06
2023
medline:
10
7
2023
pubmed:
8
7
2023
entrez:
8
7
2023
Statut:
epublish
Résumé
"Security by design" is the term for shifting cybersecurity considerations from a system's end users to its engineers. To reduce the end users' workload for addressing security during the systems operation phase, security decisions need to be made during engineering, and in a way that is traceable for third parties. However, engineers of cyber-physical systems (CPSs) or, more specifically, industrial control systems (ICSs) typically neither have the security expertise nor time for security engineering. The security-by-design decisions method presented in this work aims to enable them to identify, make, and substantiate security decisions autonomously. Core features of the method are a set of function-based diagrams as well as libraries of typical functions and their security parameters. The method, implemented as a software demonstrator, is validated in a case study with the specialist for safety-related automation solutions HIMA, and the results show that the method enables engineers to identify and make security decisions they may not have made (consciously) otherwise, and quickly and with little security expertise. The method is also well suited to make security-decision-making knowledge available to less experienced engineers. This means that with the security-by-design decisions method, more people can contribute to a CPS's security by design in less time.
Identifiants
pubmed: 37420712
pii: s23125547
doi: 10.3390/s23125547
pmc: PMC10301087
pii:
doi:
Types de publication
Journal Article
Langues
eng
Sous-ensembles de citation
IM
Subventions
Organisme : Federal Ministry of Education and Research
ID : 16KIS1269K
Références
J Gen Psychol. 2000 Oct;127(4):439-59
pubmed: 11110005