2017
DOI: 10.2172/1369373
|View full text |Cite
|
Sign up to set email alerts
|

Cyber-Informed Engineering

Abstract: Securing critical digital assets in an ever-changing threat landscape requires more than a dedicated team of cybersecurity professionals. Traditional static defense mechanisms like airgaps and reliance on obscure protocols and access mechanisms may not be sufficient for in-depth defense in an always-connected, information-rich cyber environment. Though technical solutions exist to protect availability, integrity and confidentiality of industrial control systems, these solutions typically secure external system… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
5
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 7 publications
(5 citation statements)
references
References 0 publications
0
5
0
Order By: Relevance
“…Cyber-Informed Engineering (CIE) is a methodology or approach that can be used by engineers to characterize the risks presented by the implementation of digital assets in control system environments and provides a strategy to apply engineering risk processes to mitigate those risks [47]. CIE is applied throughout the entire systems engineering lifecycle, from conceptual design to decommissioning.…”
Section: Cyber-informed Engineeringmentioning
confidence: 99%
“…Cyber-Informed Engineering (CIE) is a methodology or approach that can be used by engineers to characterize the risks presented by the implementation of digital assets in control system environments and provides a strategy to apply engineering risk processes to mitigate those risks [47]. CIE is applied throughout the entire systems engineering lifecycle, from conceptual design to decommissioning.…”
Section: Cyber-informed Engineeringmentioning
confidence: 99%
“…CIE is a multidisciplinary approach that advocates the use of CIE principles in each of the systems engineering lifecycle stages to ensure that cyber considerations are included in every aspect of design, testing, implementation, operation, maintenance, and disposal or decommissioning [36]. CIE is fundamentally a cyber risk management tool that complements existing OT cybersecurity risk standards and guidelines by incorporating engineering solutions along with ICT and OT cyber solutions to minimize risks from malicious and unintentional cyber incidents.…”
Section: Cie Overviewmentioning
confidence: 99%
“…On the other hand, implementing engineering risk treatments during design stages can actually eliminate specifically identified risks by designing it out altogether or more efficiently and effectively reduce risk by incorporating security controls into the design. CIE principles adapted from [36].…”
Section: Engineering Risk Treatmentmentioning
confidence: 99%
“…CIE is a multidisciplinary approach to integrating cybersecurity concepts into all phases of the systems engineering lifecycle. Using CIE provides stakeholders unfamiliar with cybersecurity practices the knowledge to incorporate risk management techniques to understand, eliminate, and/or mitigate cyber risks from the conceptual design phase through operation, maintenance, and disposal phases [12]. Considering and designing for cyber risks early in the lifecycle provides a simplified, more secure solution at lower cost.…”
Section: Cyber-informed Engineering Throughout the Systems Engineerin...mentioning
confidence: 99%
“…Figure 3 illustrates CIE elements adapted from the framework provided by Anderson et al [12]. The CIE secure-bydesign elements are those fundamental cybersecurity engineering design practices and techniques that build cybersecurity and cyber-resilience into the system early in the lifecycle.…”
Section: Cie Elementsmentioning
confidence: 99%