Computer and Modernization ›› 2019, Vol. 0 ›› Issue (08): 92-.doi: 10.3969/j.issn.1006-2475.2019.08.017

Previous Articles     Next Articles

GQM-based Risk Assessment Method for Industrial Control Systems

  

  1. (1. College of Control Technology, Wuxi Institute of Technology, Wuxi 214121, China;
      2. Jiangsu Information Technology Security Evaluation Center, Wuxi 214073, China;
      3. Wuxi Research Center for Environmental Science & Engineering, Wuxi 214153, China)
  • Received:2019-02-15 Online:2019-08-15 Published:2019-08-16

Abstract: Risk assessment is an essential component of safety and security assurance infrastructure mechanisms for industrial control systems. And safety and security attributes are tightly coupled. Information security assessment of industrial control systems should be coupled with the business goals. Based on Goal-Question-Metric (GQM) model, the industrial control systems risk assessment process is defined as identifying business goals, describing questions, and specification of metrics. The proposed risk assessment method is guided by the business goals, which are supported by the industrial control systems. The questions are raised on account of the scenario-based risk model. Information and data are collected concentrating on these questions. Then metrics are measured or evaluated using association analysis. Finally, a risk assessment instance of programmable logic controller (PLC) is described to specify the effectiveness of the proposed GQM-based risk assessment method for industrial control systems.

Key words: information security, function safety, risk assessment, threat modeling

CLC Number: