Devil's in the Detail: Through-Life Safety and Security Co-assurance Using SSAF

被引:7
作者
Johnson, Nikita [1 ]
Kelly, Tim [1 ]
机构
[1] Univ York, Dept Comp Sci, York, N Yorkshire, England
来源
COMPUTER SAFETY, RELIABILITY, AND SECURITY, SAFECOMP 2019 | 2019年 / 11698卷
基金
英国工程与自然科学研究理事会;
关键词
System safety; Cyber security; Co-assurance framework;
D O I
10.1007/978-3-030-26601-1_21
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Regulatory bodies, industry and academia present a plethora of approaches for risk analysis and engineering for safety and security. However, few standards and approaches discuss the management of both safety and security risks. Fewer yet provide detail on how the two attributes interact within a given system. In this paper, the SafetySecurity Assurance Framework (SSAF) is presented as a candidate solution to many of the extant challenges of attribute co-assurance. It is a holistic approach, based on the concept of independent co-assurance, that considers both the technical risk impact and the socio-technical impact on assurance. The Framework's Technical Risk Model (TRM) is applied and evaluated against a case study of an insulin pump. It is argued that SSAF TRM is not only a plausible and practical approach, but also more effective for co-assurance than many existing approaches alone.
引用
收藏
页码:299 / 314
页数:16
相关论文
共 39 条
[1]   Security Tradeoffs in Cyber Physical Systems: A Case Study Survey on Implantable Medical Devices [J].
Altawy, Ham ;
Youssef, Amr M. .
IEEE ACCESS, 2016, 4 :959-979
[2]  
[Anonymous], 2003, COMMON CONCEPTS UNDE
[3]  
[Anonymous], 2007, 149712007 ISO
[4]  
[Anonymous], 2013, ISO/IEC 27001:2013
[5]  
[Anonymous], 2011, 2011 IEEE 13th International Conference on e-Health Networking, Applications and Services, DOI DOI 10.1109/HEALTH.2011.6026732
[6]  
Association for the Advancement of Medical Instrumentation, 2016, TIR572016 AAMI
[7]  
Bostrom R. P., 1977, MIS Quarterly, P17, DOI [DOI 10.2307/248710, DOI 10.2307/249019]
[8]   Security and privacy issues in implantable medical devices: A comprehensive survey [J].
Camara, Carmen ;
Pens-Lopez, Pedro ;
Tapiador, Juan E. .
JOURNAL OF BIOMEDICAL INFORMATICS, 2015, 55 :272-289
[9]  
Chen Yihai., 2014, Insulin Pump Software Certification. pages, P87
[10]   Addressing Challenges of Hazard Analysis in Systems of Systems [J].
Despotou, George ;
Alexander, Robert ;
Kelly, Tim .
2009 IEEE INTERNATIONAL SYSTEMS CONFERENCE, PROCEEDINGS, 2009, :167-172