Risk Management and Standard Compliance for Cyber-Physical Systems of Systems
Publisher
Scientific Association for Infocommunications (HTE)
Source
Infocommunications Journal, 13(2), 32-39
Journal
ISSN
0018-2028
Date Issued
2021
Author(s)
Chlup, Sebastian
Shaaban, Abdelkader Magdy
Schmittner, Christoph
Pinzenöhler, Andreas
Abstract
The Internet of Things (IoT) and cloud technologies are increasingly implemented in the form of Cyber-Physical Systems of Systems (CPSoS) for the railway sector. In order to satisfy the security requirements of Cyber-Physical Systems (CPS), domainspecific risk identification assessment procedures have been developed. Threat modelling is one of the most commonly used methods for threat identification for the security analysis of CPSoS and is capable of targeting various domains. This paper reports our experience of using a risk management framework identify the most critical security vulnerabilities in CPSoS in the domain and shows the broader impact this work can have on the domain of safety and security management. Moreover, we emphasize the application of common analytical methods for cyber-security based on international industry standards to identify the most vulnerable assets. These will be applied to a meta-model for automated railway systems in the concept phase to support the development and deployment of these systems. Furthermore, it is the first step to create a secure and standard complaint system by design.
Type
Wissenschaftlicher Artikel
File(s)![Thumbnail Image]()
Loading...
Name
InfocomJ_2021_2_5_Matta.pdf
Size
1.09 MB
Format
Adobe PDF
Checksum
(MD5):c5dc5de76e1e11a1da1298383c216c32