Understanding Security Requirements for Industrial Control System Supply Chains

Ye Hou, Jose Such, Awais Rashid

Research output: Chapter in Book/Report/Conference proceedingConference Contribution (Conference Proceeding)

19 Citations (Scopus)
382 Downloads (Pure)

Abstract

We address the need for security requirements to take into account risks arising from complex supply chains underpinning cyber-physical infrastructures such as industrial control systems (ICS). We present SEISMiC (SEcurity Industrial control SysteM supply Chains), a framework that takes into account the whole spectrum of security risks – from technical aspects through to human and organizational issues – across an ICS supply chain. We demonstrate the effectiveness of SEISMiC through a supply chain risk assessment of Natanz, Iran’s nuclear facility that was the subject of the Stuxnet attack.
Original languageEnglish
Title of host publicationProceedings of 5th International Workshop on Software Engineering for Smart Cyber-Physical Systems (SEsCPS'19)
PublisherInstitute of Electrical and Electronics Engineers (IEEE)
Pages50-53
Number of pages4
ISBN (Electronic)9781728122823
ISBN (Print)9781728134383
DOIs
Publication statusPublished - 5 Sept 2019

Research Groups and Themes

  • Cyber Security

Fingerprint

Dive into the research topics of 'Understanding Security Requirements for Industrial Control System Supply Chains'. Together they form a unique fingerprint.

Cite this