返回
A Model-Based Framework for Developing Security-Safety Incident Response Plans
DOI:10.1007/s10207-025-01147-4.png)
摘要
En 中文
Cyberattacks are increasingly affecting the safe operation of critical infrastructure (e.g., energy, manufacturing) and potentially endangering production, people, equipment, and the environment. A cyber-incident with physical consequences requires personnel responsible for aggregating log information, analyzing root cause (i.e., cybersecurity), and ensuring the production and safe operation of safety-critical systems (i.e., safety) to collaborate. For this, they must understand their own and each other's roles in the incident response process, as well as when and how to interact with different roles. To address this problem, this paper proposes a framework that utilizes a model-based approach to illustrate the critical roles and their interactions within a security-safety incident response plan. To demonstrate its applicability, the framework was applied in a qualitative study within the Norwegian oil and gas industry, involving two companies. This research sheds light on the relevance of applying a model-based approach to developing security and safety incident response plans for organizations. It investigates the relevance of using two modeling languages: a general-purpose software systems modeling language, the Unified Modeling Language (UML), and an enterprise process workflow modeling language, the Business Process Modeling Notation (BPMN), for visualizing the security-safety incident response plan. The findings indicate that the modeling languages are suitable and relevant for understanding and discussing the collaboration and coordination of different personnel's roles during security-safety incident response. The distinct diagrams highlight various aspects, including roles, transmitted information, tasks, and the sequence of tasks. Future work should consider how the diagrams can be applied during the training and learning of the incident response plans.
Keyword:
Modeling language
Incident response
Critical infrastructure
Roles
Cyber security
Safety
期刊
I
IF:
3.2
论文数:
136
被引数:
1.8K
机构
引用论文
Characteristic and comparison of UML, BPMN and EPC based on process models of a training company基于培训公司流程模型的UML、BPMN和EPC的特性与比较
Business Process Modeling Languages: A Comparative FrameworkPereira, J.L.; Silva, D. 业务流程建模语言:一个比较框架。载于《信息系统与技术的新进展》;Springer International Publishing: 瑞士楚格,2016;第619-628页。 [Google Scholar] [CrossRef]
How can organizations develop situation awareness for incident response: A case study of management practice
COMPUTERS & SECURITY
IF5.4
Schlette, D., Empl, P., Caselli, M., Schreck, T., Pernul, G., 2024. Do you play it by the books? a study on incident response playbooks and influencing factors, in: 2024 IEEE Symposium on Security and Privacy (SP), pp. 3625–3643. 10.1109/SP54263.2024.00060.Schlette, D., Empl, P., Caselli, M., Schreck, T., Pernul, G., 2024. 你是否按规则行事?一项关于事件响应演练手册及其影响因素的研究,发表于:2024年IEEE安全与隐私研讨会(SP),第3625-3643页。10.1109/SP54263.2024.00060。

