Risk Assessments Considering Safety, Security, and Their Interdependencies in OT Environments

被引:7
|
作者
Hollerer, Siegfried [1 ]
Sauter, Thilo [2 ,3 ]
Kastner, Wolfgang [1 ]
机构
[1] TU Wien, Inst Comp Engn, Vienna, Austria
[2] TU Wien, Inst Comp Techn, Vienna, Austria
[3] Danube Univ Krems, Dept Integrated Sensor Syst, Krems, Austria
来源
PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, ARES 2022 | 2022年
关键词
Threat Modeling; OT Security; Safety; IT / OT convergence; MODELS;
D O I
10.1145/3538969.3543814
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information Technology (IT) and Operational Technology (OT) are converging further, which increases the number of interdependencies of safety and security risks arising in industrial architectures. Cyber attacks interfering safety functionality may lead to serious injuries as a consequence. Intentionally triggering a safety function may introduce a security vulnerability during the emergency procedure, e.g., by opening emergency exit doors leading to enabling unauthorized physical access. This paper introduces a risk evaluation methodology to prioritize and manage identified threats considering security, safety, and their interdepedencies. The presented methodology uses metrics commonly used in the industry to increase its applicability and enable the combination with other risk assessment approaches. These metrics are Common Vulnerability Scoring System (CVSS), Security Level (SL) from the standard IEC 62443 and Safety Integrity Level (SIL) from the standard IEC 61508. Conceptional similarities of those metrics are considered during the risk calculation, including an identified relation between CVSS and SL. Besides this relation, the skill level and resources of threat actors, threats enabling multiple identified attacks, the SIL of safety-relevant components affected, business criticality of the targeted asset, and the SL-T of the zone targeted by the attack are considered for risk evaluation. The industrial architecture to be analyzed is separated into zones and conduits according to IEC 62443, enabling the analyzed system to be compliant with its requirements.
引用
收藏
页数:8
相关论文
共 50 条
  • [31] Animal health and food safety risk assessments
    Makita, K.
    REVUE SCIENTIFIQUE ET TECHNIQUE-OFFICE INTERNATIONAL DES EPIZOOTIES, 2021, 40 (02): : 533 - 544
  • [32] Including detonations in industrial safety and risk assessments
    Kolbe, M.
    Simoes, V.
    Salzano, E.
    JOURNAL OF LOSS PREVENTION IN THE PROCESS INDUSTRIES, 2017, 49 : 171 - 176
  • [33] Requirements Analysis for the Evaluation of Automated Security Risk Assessments
    Ehrlich, Marco
    Lukas, Georg
    Trsek, Henning
    Jasperneite, Juegen
    Kastner, Wolfgang
    Diedrich, Christian
    2024 IEEE 20TH INTERNATIONAL CONFERENCE ON FACTORY COMMUNICATION SYSTEMS, WFCS, 2024, : 180 - 183
  • [34] Risk assessment of infrastructure facilities considering spatial and operational interdependencies: temporal simulation model
    Atef, Ahmed
    Bristow, David
    STRUCTURE AND INFRASTRUCTURE ENGINEERING, 2022, 18 (08) : 1138 - 1151
  • [35] Comparison of risk-based and deterministic security assessments
    Kirschen, D. S.
    Jayaweera, D.
    IET GENERATION TRANSMISSION & DISTRIBUTION, 2007, 1 (04) : 527 - 533
  • [36] Risk response decisions for projects in project portfolios considering objective adjustments and project interdependencies
    Zhang, Xu
    Goh, Mark
    Bai, Sijun
    Wang, Zonghan
    KYBERNETES, 2024, 53 (07) : 2217 - 2246
  • [37] Systemic seismic risk assessment of urban healthcare system considering interdependencies to critical infrastructures
    Poudel, Astha
    Argyroudis, Sotirios
    Pitilakis, Kyriazis
    INTERNATIONAL JOURNAL OF DISASTER RISK REDUCTION, 2024, 103
  • [38] Integrated Safety and Security by Design in the IT/OT Convergence of Industrial Cyber-Physical Systems
    Amiri, Amirali
    Steindl, Gernot
    Hollerer, Siegfried
    2024 IEEE 7TH INTERNATIONAL CONFERENCE ON INDUSTRIAL CYBER-PHYSICAL SYSTEMS, ICPS 2024, 2024,
  • [39] A Methodological Framework for AI-Assisted Security Assessments of Active Directory Environments
    Nebbione, Giuseppe
    Calzarossa, Maria Carla
    IEEE ACCESS, 2023, 11 : 15119 - 15130
  • [40] A framework for considering social, political and economic factors in risk assessments
    Kildow, J
    ASSESSING THE RISKS OF NUCLEAR AND CHEMICAL CONTAMINATION IN THE FORMER SOVIET UNION, 1996, 10 : 11 - 22