Samenvatting
The increased reliance of organizations on information technology inherently increases their vulnerability to cyber-security attacks. As a response, a host of cyber-security approaches exists. While useful, these approaches exhibit shortcomings such as an inclination to be fragmented, not accounting for up-to-date organizational data, focusing on singular vulnerabilities only, and being reactive, i.e., focusing on patching up vulnerabilities in current systems. The paper presents and evaluates a modeling method aiming to address those shortcomings and to support security by design with a focus on the electricity sector. The proposed modeling method encompasses a multi-level reference model reconstructing and integrating existing initiatives and supporting top-down and bottom-up analyses. Compared to earlier work, the paper contributes (1) a process model for cyber-security by design, which proactively considers security as a first-class citizen during the design process, (2) a complete coverage of the multi-level model, in terms of three views complementing the introduced process model, (3) an elaborated evaluation, in terms of reporting on an additional design science cycle.
| Originele taal-2 | Engels |
|---|---|
| Pagina's (van-tot) | 511-530 |
| Aantal pagina's | 20 |
| Tijdschrift | Business and Information Systems Engineering |
| Volume | 67 |
| Nummer van het tijdschrift | 4 |
| Vroegere onlinedatum | 28 okt 2024 |
| DOI's | |
| Status | Gepubliceerd - aug 2025 |
Bibliografische nota
Publisher Copyright:© The Author(s) 2024.
Vingerafdruk
Duik in de onderzoeksthema's van 'A Multi-level Reference Model and a Dedicated Method for Cyber-Security by Design: On the Example of the Electricity Sector'. Samen vormen ze een unieke vingerafdruk.Citeer dit
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver