arrow
返回

A Model-Based Framework for Developing Security-Safety Incident Response Plans

delete2025-11-03
delete0
delete
OA
AI
V
Vahiny Gnanasekaran *
U
Urooj Fatima
M
Magdalena Glas
P
Poul E. Heegaard
DOI:10.1007/s10207-025-01147-4delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Cyberattacks are increasingly affecting the safe operation of critical infrastructure (e.g., energy, manufacturing) and potentially endangering production, people, equipment, and the environment. A cyber-incident with physical consequences requires personnel responsible for aggregating log information, analyzing root cause (i.e., cybersecurity), and ensuring the production and safe operation of safety-critical systems (i.e., safety) to collaborate. For this, they must understand their own and each other's roles in the incident response process, as well as when and how to interact with different roles. To address this problem, this paper proposes a framework that utilizes a model-based approach to illustrate the critical roles and their interactions within a security-safety incident response plan. To demonstrate its applicability, the framework was applied in a qualitative study within the Norwegian oil and gas industry, involving two companies. This research sheds light on the relevance of applying a model-based approach to developing security and safety incident response plans for organizations. It investigates the relevance of using two modeling languages: a general-purpose software systems modeling language, the Unified Modeling Language (UML), and an enterprise process workflow modeling language, the Business Process Modeling Notation (BPMN), for visualizing the security-safety incident response plan. The findings indicate that the modeling languages are suitable and relevant for understanding and discussing the collaboration and coordination of different personnel's roles during security-safety incident response. The distinct diagrams highlight various aspects, including roles, transmitted information, tasks, and the sequence of tasks. Future work should consider how the diagrams can be applied during the training and learning of the incident response plans.
Keyword:
Modeling language
Incident response
Critical infrastructure
Roles
Cyber security
Safety

期刊

I
International Journal of Information Security
IF:
3.2
论文数:
136
被引数:
1.8K

机构

U
university of regensburg
学者数:
1.6W
论文数: 1.2W
被引数: 11
引用论文

引用论文

Process Mining
err
IF0
err2016-01-01
err0
PREAI
errWil van der Aalst
err分享
err收藏
err分享
err收藏
err分享
err收藏
How can organizations develop situation awareness for incident response: A case study of management practice
err2021-02-01
err49
errOAAI
errAhmad, Atif; Maynard, Sean B.; Desouza, Kevin C.; Kotsias, James; Whitty, Monica T.; Baskerville, Richard L.
err分享
err收藏
err分享
err收藏
学者 查看更多内容