Model-Based Cyber Security at the Enterprise and Systems Level

被引:1
|
作者
Brooks, Mitchell [1 ]
Hause, Matthew [2 ]
机构
[1] SSI, 229 Manzanita Dr, Orinda,CA, United States
[2] Principal, SSI, 3208 Misty Oaks Way, Round Rock,TX, United States
关键词
Modeling languages;
D O I
10.1002/iis2.13044
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Model-Based Engineering (MBE) has transformed the worlds of mechanical, electrical, chemical, software, systems engineering, and now cybersecurity. Model based cybersecurity allows this concern to be addressed as an integrated part of the solution as opposed to being a separate solution. To best take advantage of this, we must examine which modeling practices, languages, and standards are best suited to handle cybersecurity. Currently, UAF is the most effective tool being used to provide Model-Based Cyber Security at the Enterprise and Systems Level. It achieves this largely through its integrated security viewpoint as well as by facilitating capability-based engineering. Furthermore, it allows modelers to integrate with other cybersecurity-focused modeling tools to include cybersecurity in the digital thread. The INCOSE Future of Systems Engineering (FuSE) Initiative defined 12 key concepts including Capability-Based Security Engineering and Security as a Functional Requirement. This paper discusses these FuSE concepts and demonstrates how they can be effectively realized via the use of UAF and shows how UAF coupled with complementary tools and standards provides powerful verification and validation capabilities. Note that this paper is derived from INCOSE Insight articles Brooks, Hause (2022) and Hause, Brooks (2022) published in a special issue on FuSE Security. References are included below. Copyright © 2023 by M Brooks, M Hause. Permission granted to INCOSE to publish and use.
引用
收藏
页码:649 / 665
相关论文
共 50 条
  • [31] Utilizing an Enterprise Architecture Framework for Model-Based Industrial Systems Engineering
    Binder, Christoph
    Leiter, Werner
    Joebstl, Oliver
    Mair, Lukas
    Neureiter, Christian
    Lueder, Arndt
    2021 IEEE 19TH INTERNATIONAL CONFERENCE ON INDUSTRIAL INFORMATICS (INDIN), 2021,
  • [32] MODEL-BASED SERVICE INTEGRATION FOR EXTENSIBLE ENTERPRISE SYSTEMS WITH ADAPTATION PATTERNS
    Heller, Markus
    Allgaier, Matthias
    ICE-B 2010: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON E-BUSINESS, 2010, : 163 - 168
  • [33] Digital Enterprise and Cyber Security Evolution
    Raicu, Alexandra
    Raicu, Gabriel
    MACROMOLECULAR SYMPOSIA, 2021, 396 (01)
  • [34] Model-Based Security Risk Analysis for Networked Embedded Systems
    Vasilevskaya, Maria
    Nadjm-Tehrani, Simin
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2014), 2016, 8985 : 381 - 386
  • [35] A model-based methodology to support systems security design and assessment
    Shaked, Avi
    JOURNAL OF INDUSTRIAL INFORMATION INTEGRATION, 2023, 33
  • [36] Model-based security testing in IoT systems: A Rapid Review
    Lonetti, Francesca
    Bertolino, Antonia
    Di Giandomenico, Felicita
    INFORMATION AND SOFTWARE TECHNOLOGY, 2023, 164
  • [37] Lightweight Model-Based Testing for Enterprise IT
    Bernard, Elodie
    Ambert, Fabrice
    Legeard, Bruno
    Bouzy, Arnaud
    2018 IEEE 11TH INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION WORKSHOPS (ICSTW), 2018, : 224 - 230
  • [38] Model-based security engineering
    Juerjens, Jan
    SIGMAP 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND MULTIMEDIA APPLICATIONS, 2006, : IS23 - IS29
  • [39] Model-based security engineering
    Juerjens, Jan
    SECRYPT 2006: PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2006, : IS23 - IS29
  • [40] Model-based security engineering
    Juerjens, Jan
    ICE-B 2006: Proceedings of the International Conference on e-Business, 2006, : IS23 - IS29