社会技术安全建模和模拟在网络物理系统:展望知识,观念,实践,使能者和障碍

IF 1.7 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
Uchenna Daniel Ani, Mohammed Al-Mhiqani, Nilufer Tuptuk, Stephen Hailes, Jeremy Daniel McKendrick Watson
{"title":"社会技术安全建模和模拟在网络物理系统:展望知识,观念,实践,使能者和障碍","authors":"Uchenna Daniel Ani,&nbsp;Mohammed Al-Mhiqani,&nbsp;Nilufer Tuptuk,&nbsp;Stephen Hailes,&nbsp;Jeremy Daniel McKendrick Watson","doi":"10.1049/cps2.70017","DOIUrl":null,"url":null,"abstract":"<p>Socio-Technical Security Modelling and Simulation (STSec-M&amp;S) is a technique used for reasoning and representing security viewpoints that include both the social and technical aspects of a system. It has shown great potential for improving the cybersecurity and resilience of Critical Infrastructure (CI). This study involved a multi-methods approach, consisting of a scoping literature review and a focus group workshop, conducted with stakeholder engagement from critical infrastructure stakeholders to explore their perceptions and practices regarding the use of socio-technical security modelling and simulation. The findings suggest that the current state of knowledge regarding the use and effectiveness of STSec-M&amp;Ss approaches is limited in CI domains. Consequently, there is little application of it in existing CI systems, regardless of its recognised benefits of enabling a better understanding of CI functionalities, security goals, early and more holistic risk identifications and selection of appropriate countermeasures. The benefits of the STSec-M&amp;S approach can be better realised by effective cross-sector communications and collaborations, team partnerships, system and approach sophistication, and better security awareness amongst others. The potential barriers that can impede such benefits include high expense for implementing the technique, low data availability and quality, regulatory compliance, and competency gaps etc. Helpful recommendations include exploring and using realistic data, validating system security models, and exploring new ways of reskilling and upskilling CI stakeholders in socio-technical security-thinking and M&amp;S approaches to enhance cybersecurity and resilience of CIs.</p>","PeriodicalId":36881,"journal":{"name":"IET Cyber-Physical Systems: Theory and Applications","volume":"10 1","pages":""},"PeriodicalIF":1.7000,"publicationDate":"2025-04-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/cps2.70017","citationCount":"0","resultStr":"{\"title\":\"Socio-Technical Security Modelling and Simulations in Cyber-Physical Systems: Outlook on Knowledge, Perceptions, Practices, Enablers, and Barriers\",\"authors\":\"Uchenna Daniel Ani,&nbsp;Mohammed Al-Mhiqani,&nbsp;Nilufer Tuptuk,&nbsp;Stephen Hailes,&nbsp;Jeremy Daniel McKendrick Watson\",\"doi\":\"10.1049/cps2.70017\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>Socio-Technical Security Modelling and Simulation (STSec-M&amp;S) is a technique used for reasoning and representing security viewpoints that include both the social and technical aspects of a system. It has shown great potential for improving the cybersecurity and resilience of Critical Infrastructure (CI). This study involved a multi-methods approach, consisting of a scoping literature review and a focus group workshop, conducted with stakeholder engagement from critical infrastructure stakeholders to explore their perceptions and practices regarding the use of socio-technical security modelling and simulation. The findings suggest that the current state of knowledge regarding the use and effectiveness of STSec-M&amp;Ss approaches is limited in CI domains. Consequently, there is little application of it in existing CI systems, regardless of its recognised benefits of enabling a better understanding of CI functionalities, security goals, early and more holistic risk identifications and selection of appropriate countermeasures. The benefits of the STSec-M&amp;S approach can be better realised by effective cross-sector communications and collaborations, team partnerships, system and approach sophistication, and better security awareness amongst others. The potential barriers that can impede such benefits include high expense for implementing the technique, low data availability and quality, regulatory compliance, and competency gaps etc. Helpful recommendations include exploring and using realistic data, validating system security models, and exploring new ways of reskilling and upskilling CI stakeholders in socio-technical security-thinking and M&amp;S approaches to enhance cybersecurity and resilience of CIs.</p>\",\"PeriodicalId\":36881,\"journal\":{\"name\":\"IET Cyber-Physical Systems: Theory and Applications\",\"volume\":\"10 1\",\"pages\":\"\"},\"PeriodicalIF\":1.7000,\"publicationDate\":\"2025-04-30\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://onlinelibrary.wiley.com/doi/epdf/10.1049/cps2.70017\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IET Cyber-Physical Systems: Theory and Applications\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://onlinelibrary.wiley.com/doi/10.1049/cps2.70017\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Cyber-Physical Systems: Theory and Applications","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1049/cps2.70017","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

摘要

社会技术安全建模和仿真(STSec-M&;S)是一种用于推理和表示安全观点的技术,包括系统的社会和技术方面。它在提高关键基础设施(CI)的网络安全和弹性方面显示出巨大的潜力。本研究采用了多种方法,包括范围界定文献综述和焦点小组研讨会,在关键基础设施利益相关者的参与下进行,探讨他们对使用社会技术安全建模和模拟的看法和实践。研究结果表明,目前关于STSec-M&; s方法的使用和有效性的知识状况在CI领域是有限的。因此,它在现有CI系统中的应用很少,尽管它可以更好地理解CI功能、安全目标、早期和更全面的风险识别以及选择适当的对策。透过有效的跨界别沟通和合作、团队伙伴关系、完善的系统和方法,以及更强的保安意识,可以更有效地发挥STSec-M&;S方法的好处。可能阻碍这些好处的潜在障碍包括实现技术的高费用、低数据可用性和质量、法规遵从性和能力差距等。有用的建议包括探索和使用现实数据,验证系统安全模型,以及探索在社会技术安全思维和M&;S方法方面重新培训和提高CI利益相关者的技能的新方法,以增强CI的网络安全和弹性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。

Socio-Technical Security Modelling and Simulations in Cyber-Physical Systems: Outlook on Knowledge, Perceptions, Practices, Enablers, and Barriers

Socio-Technical Security Modelling and Simulations in Cyber-Physical Systems: Outlook on Knowledge, Perceptions, Practices, Enablers, and Barriers

Socio-Technical Security Modelling and Simulation (STSec-M&S) is a technique used for reasoning and representing security viewpoints that include both the social and technical aspects of a system. It has shown great potential for improving the cybersecurity and resilience of Critical Infrastructure (CI). This study involved a multi-methods approach, consisting of a scoping literature review and a focus group workshop, conducted with stakeholder engagement from critical infrastructure stakeholders to explore their perceptions and practices regarding the use of socio-technical security modelling and simulation. The findings suggest that the current state of knowledge regarding the use and effectiveness of STSec-M&Ss approaches is limited in CI domains. Consequently, there is little application of it in existing CI systems, regardless of its recognised benefits of enabling a better understanding of CI functionalities, security goals, early and more holistic risk identifications and selection of appropriate countermeasures. The benefits of the STSec-M&S approach can be better realised by effective cross-sector communications and collaborations, team partnerships, system and approach sophistication, and better security awareness amongst others. The potential barriers that can impede such benefits include high expense for implementing the technique, low data availability and quality, regulatory compliance, and competency gaps etc. Helpful recommendations include exploring and using realistic data, validating system security models, and exploring new ways of reskilling and upskilling CI stakeholders in socio-technical security-thinking and M&S approaches to enhance cybersecurity and resilience of CIs.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
IET Cyber-Physical Systems: Theory and Applications
IET Cyber-Physical Systems: Theory and Applications Computer Science-Computer Networks and Communications
CiteScore
5.40
自引率
6.70%
发文量
17
审稿时长
19 weeks
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信