Security assessment methodology for industrial control system products

A. Hristova, Roman Schlegel, S. Obermeier
{"title":"Security assessment methodology for industrial control system products","authors":"A. Hristova, Roman Schlegel, S. Obermeier","doi":"10.1109/CYBER.2014.6917472","DOIUrl":null,"url":null,"abstract":"Industrial control systems (ICS) are at the heart of critical infrastructures and security is therefore important for such systems. In order to determine the security level of existing and planned systems, ICS products should be efficiently and comprehensively assessed. In this paper we present a methodology for assessing the security of a product or a system that can be used by security experts and non-experts alike. The methodology contains specific and concrete security recommendations (what), a rationale for each recommendation (why) as well as concrete implementation guidance (how). The methodology aims to help product teams to quickly and efficiently assess the security level of their products, prioritize resources on future development efforts, and generate security requirements for future products. We validate the approach by applying a concrete instantiation of the methodology to a fictitious ICS product.","PeriodicalId":183401,"journal":{"name":"The 4th Annual IEEE International Conference on Cyber Technology in Automation, Control and Intelligent","volume":"9 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-06-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"The 4th Annual IEEE International Conference on Cyber Technology in Automation, Control and Intelligent","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CYBER.2014.6917472","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

Industrial control systems (ICS) are at the heart of critical infrastructures and security is therefore important for such systems. In order to determine the security level of existing and planned systems, ICS products should be efficiently and comprehensively assessed. In this paper we present a methodology for assessing the security of a product or a system that can be used by security experts and non-experts alike. The methodology contains specific and concrete security recommendations (what), a rationale for each recommendation (why) as well as concrete implementation guidance (how). The methodology aims to help product teams to quickly and efficiently assess the security level of their products, prioritize resources on future development efforts, and generate security requirements for future products. We validate the approach by applying a concrete instantiation of the methodology to a fictitious ICS product.
工业控制系统产品安全评价方法
工业控制系统(ICS)是关键基础设施的核心,因此安全对这些系统非常重要。为了确定现有和计划中的系统的安全级别,应该对ICS产品进行有效和全面的评估。在本文中,我们提出了一种评估产品或系统安全性的方法,可以由安全专家和非专家使用。该方法包含具体和具体的安全性建议(什么),每个建议的基本原理(为什么)以及具体的实现指导(如何)。该方法旨在帮助产品团队快速有效地评估其产品的安全级别,为未来的开发工作确定资源的优先级,并为未来的产品生成安全需求。我们通过将该方法的具体实例应用于一个虚构的ICS产品来验证该方法。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信