arrow
Return

A Multi-level Reference Model and a Dedicated Method for Cyber-Security by Design

delete2024-10-28
delete0
delete
OA
AI
S
Sybren de Kinderen *
M
Monika Kaczmarek
S
Simon Hacks
DOI:10.1007/s12599-024-00899-ydelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The increased reliance of organizations on information technology inherently increases their vulnerability to cyber-security attacks. As a response, a host of cyber-security approaches exists. While useful, these approaches exhibit shortcomings such as an inclination to be fragmented, not accounting for up-to-date organizational data, focusing on singular vulnerabilities only, and being reactive, i.e., focusing on patching up vulnerabilities in current systems. The paper presents and evaluates a modeling method aiming to address those shortcomings and to support security by design with a focus on the electricity sector. The proposed modeling method encompasses a multi-level reference model reconstructing and integrating existing initiatives and supporting top-down and bottom-up analyses. Compared to earlier work, the paper contributes (1) a process model for cyber-security by design, which proactively considers security as a first-class citizen during the design process, (2) a complete coverage of the multi-level model, in terms of three views complementing the introduced process model, (3) an elaborated evaluation, in terms of reporting on an additional design science cycle.
Keywords:
Cyber-security by design
Modeling method
Security reference framework
Security analysis
Multi-level modeling

Journal

Business and Information Systems Engineering cover
Business and Information Systems Engineering
IF:
10.4
Papers:
862
Citations:
4.0K

Organization

U
University of Duisburg Essen
Scholars:
2.2W
Papers: 1.7W
Citations: 22
S
Stockholm University
Scholars:
1.8W
Papers: 1.7W
Citations: 32
E
Eindhoven University of Technology
Scholars:
1.6W
Papers: 1.5W
Citations: 2.2W
researcher View more organizations