Abstract
AbstractWe must explicitly capture relationships and hierarchies between the multitude of system and security standards requirements. Current security requirements specification methods do not capture such structure effectively, making requirements management and traceability harder, consequently increasing costs and time to market for developing certified ICS. We propose a novel requirements repository model for ICS that uses labelled property graphs to structure and store system-specific and standards-based requirements using well-defined relationship types. Furthermore, we integrate the proposed requirements repository with design-time ICS tools to establish requirements traceability. A wind turbine case study illustrates the overall workflow in our framework. We demonstrate that a robust requirements traceability matrix is a natural consequence of using labelled property graphs. We also introduce a compatible requirements change management procedure that aids in adapting to changes in development and certification schemes.
Funder
Auckland University of Technology
Publisher
Springer Science and Business Media LLC
Subject
Modeling and Simulation,Software
Reference55 articles.
1. 62443-4-1:2018, B.E.I.: BS EN IEC 62443-4-1 : 2018 BSI Standards Publication Security for industrial automation and control systems (2018)
2. Ahsan, M., Motla, Y.H., Azeem, M.W.: An ontology-based approach for handling the issues in requirement engineering. Pak. Acad. Sci. 52(3), 187–200 (2015)
3. Beckers, K.: Relating ISO 27001 to the conceptual framework for security requirements engineering methods. In: Pattern and Security Requirements, pp. 85–108. Springer (2015)
4. Bicaku, A., Zsilak, M., Theiler, P., Tauber, M., Delsing, J.: Security standard compliance verification in system of systems. IEEE Syst. J. (2021). https://doi.org/10.1109/JSYST.2021.3064196
5. Borg, M., de la Vara, J.L., Wnuk, K.: Practitioners’ perspectives on change impact analysis for safety-critical software–a preliminary analysis. In: International Conference on Computer Safety, Reliability, and Security, pp. 346–358. Springer (2016)
Cited by
2 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. DIY Wind Turbines: A Low-Cost Smart ICPS for Educational Research;2023 IEEE International Conference on Teaching, Assessment and Learning for Engineering (TALE);2023-11-28
2. Balancing software and training requirements for information security;Computers & Security;2023-11