Ani, UPD;
He, HM;
Tiwari, A;
(2018)
A framework for Operational Security Metrics Development for industrial control environment.
Journal of Cyber Security Technology
, 2
(3-4)
pp. 201-237.
10.1080/23742917.2018.1554986.
Preview |
Text
Ani_A framework for Operational Security Metrics Development for industrial control environment_AAM.pdf - Accepted Version Download (614kB) | Preview |
Abstract
Security metrics are very crucial towards providing insights when measuring security states and susceptibilities in industrial operational environments. Obtaining practical security metrics depend on effective security metrics development approaches. To be effective, a security metrics development framework should be scope-definitive, objective-oriented, reliable, simple, adaptable, and repeatable (SORSAR). A framework for Operational Security Metrics Development (OSMD) for industry control environments is presented, which combines concepts and characteristics from existing approaches. It also adds the new characteristic of adaptability. The OSMD framework is broken down into three phases of: target definition, objective definition, and metrics synthesis. A case study scenario is used to demonstrate an instance of how to implement and apply the proposed framework to demonstrate its usability and workability. Expert elicitation has also be used to consolidate the validity of the proposed framework. Both validation approaches have helped to show that the proposed framework can help create effective and efficient ICS-centric security metrics taxonomy that can be used to evaluate capabilities or vulnerabilities. The understanding from this can help enhance security assurance within industrial operational environments.
Type: | Article |
---|---|
Title: | A framework for Operational Security Metrics Development for industrial control environment |
Open access status: | An open access version is available from UCL Discovery |
DOI: | 10.1080/23742917.2018.1554986 |
Publisher version: | https://doi.org/10.1080/23742917.2018.1554986 |
Language: | English |
Additional information: | This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions. |
Keywords: | OSMD framework, security metrics, Operational Security metrics, industry control environments, security measurement |
UCL classification: | UCL UCL > Provost and Vice Provost Offices > UCL BEAMS UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > STEaPP |
URI: | https://discovery.ucl.ac.uk/id/eprint/10084101 |




Archive Staff Only
![]() |
View Item |