A systemic framework for addressing cybersecurity in construction

被引:43
作者
Turk, Ziga [1 ]
de Soto, Borja Garcia [2 ]
Mantha, Bharadwaj R. K. [2 ]
Maciel, Abel [3 ]
Georgescu, Alexandru [4 ]
机构
[1] Univ Ljubljana, Fac Civil & Geodet Engn, Jamova 2, Ljubljana 1000, Slovenia
[2] New York Univ Abu Dhabi NYUAD, Div Engn, SMART Construct Res Grp, Expt Res Bldg,POB 129188, Abu Dhabi, U Arab Emirates
[3] Univ Coll London UCL, Bartlett Fac Built Environm, 22 Gordon St, London WC1H 0QB, England
[4] ICI Bucharest, Natl Inst Res & Dev Informat, European Ctr Excellence Blockchain, Bd Maresal Averescu 8-10,Sect 1, Bucureti 011455, Romania
关键词
BIM; Construction; 4; 0; Cybersecurity; Cyber-Physical Systems; Digitalization; Digital twins; Information Technology (IT); Operational Technology (OT); Privacy; Confidentiality; Integrity; CIA Triad; Parkerian Hexad;
D O I
10.1016/j.autcon.2021.103988
中图分类号
TU [建筑科学];
学科分类号
0813 ;
摘要
Today, the built environment is designed, built, and managed using digital technology, making it increasingly exposed to cyber security risks. Cybersecurity is a general topic, and the construction sector has been borrowing general solutions and frameworks. However, the construction industry is specific and needs a specialized framework that would assist in understanding and managing cybersecurity. We have studied general cyberse-curity frameworks, cybersecurity standards, research literature, and first principles of systems theory and process engineering. Drawing from that, we developed an original framework that identifies three kinds of wrongful activities: stealing, lying, and harming. It identifies four elements that can be affected by wrongful activities: information asset, material asset, person, and system. It defines cybersecurity as the absence of the three wrongs across the four kinds of elements. The framework is construction-specific, and as such, a useful tool for senior management to understand security problems and organize security processes. It can lead to better standardi-zation and also helps the researchers to structure future work on the topic. The latter should be concentrated in areas where construction was found to be different: the dynamic and overlapping process and organizational boundaries in the design stage, the exposed shared design information, and the vulnerability of control infor-mation of the built environment, particularly in critical infrastructures.
引用
收藏
页数:14
相关论文
共 64 条
[1]  
Abootorabi SM, 2014, J HEALTH SAF WORK, V4, P67
[2]  
Ågotnes HJ, 2017, WORK AR GLOB-HIST CO, P165
[3]   CYBERSECURITY FOR DIGITAL TWINS IN THE BUILT ENVIRONMENT: CURRENT RESEARCH AND FUTURE DIRECTIONS [J].
Alshammari, Kaznah ;
Beach, Thomas ;
Rezgui, Yacine .
JOURNAL OF INFORMATION TECHNOLOGY IN CONSTRUCTION, 2021, 26 :159-173
[4]   Safety risk assessment using analytic hierarchy process (AHP) during planning and budgeting of construction projects [J].
Aminbakhsh, Saman ;
Gunduz, Murat ;
Sonmez, Rifat .
JOURNAL OF SAFETY RESEARCH, 2013, 46 :99-105
[5]  
[Anonymous], 2014, Framework for improving critical infrastructure cybersecurity, DOI 10.6028/NIST.CSWP.02122014
[6]  
[Anonymous], 2018, ISOIEC27001
[7]  
[Anonymous], 2013, CIB PUBLICATION
[8]   Modelling design information to evaluate pre-fabricated and pre-cast design solutions for reducing construction waste in high rise residential buildings [J].
Baldwin, A. N. ;
Shen, L. Y. ;
Poon, C. S. ;
Austin, S. A. ;
Wong, I. .
AUTOMATION IN CONSTRUCTION, 2008, 17 (03) :333-341
[9]  
Bjork B.-C., 2002, Construction Innovation: Information, Process, Management, V2, P133, DOI DOI 10.1108/14714170210814739
[10]  
Boyes H., 2014, CODE PRACTICE CYBER