Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid

The critical infrastructure is constantly under cyber and physical threats. Applying security controls without guidance or traceability can create a false sense of security. Security standards facilitate security knowledge and control best practices in a more systematic way. However, the number of s...

Full description

Bibliographic Details
Main Authors: Milan Stojkov, Nikola Dalčeković, Branko Markoski, Branko Milosavljević, Goran Sladić
Format: Article
Language:English
Published: MDPI AG 2021-10-01
Series:Energies
Subjects:
Online Access:https://www.mdpi.com/1996-1073/14/21/6862
_version_ 1797512631357014016
author Milan Stojkov
Nikola Dalčeković
Branko Markoski
Branko Milosavljević
Goran Sladić
author_facet Milan Stojkov
Nikola Dalčeković
Branko Markoski
Branko Milosavljević
Goran Sladić
author_sort Milan Stojkov
collection DOAJ
description The critical infrastructure is constantly under cyber and physical threats. Applying security controls without guidance or traceability can create a false sense of security. Security standards facilitate security knowledge and control best practices in a more systematic way. However, the number of standards is continually increasing. Product providers that operate in multiple geographical regions often face the obligation to comply with multiple standards simultaneously. This introduces the problem of the convenient interpretation of different standards. Thus, a comprehensive analysis of the requirements from different security standards and guidelines applicable to the smart grid has been performed to detect similarities that can be shaped into entities of the conceptual model for requirement representation. The purpose of the model—presented in a form of a Unified Modeling Language (UML) class diagram—is to give product providers a canonical way to map requirements from arbitrary standards, guidelines, and regulations and accelerate the cross-standard compliance readiness by defining priority for requirement implementation. In addition, the research showed that multiple vectors should impact the priority of the implementation of the security controls defined through the requirements: domain affiliation, the essence of the requirement, associated threats, risks, and social dependencies between actors involved in the implementation. To examine the model correctness, NISTIR 7628—de facto smart grid standard—was used to provide insights into how the model would be used for requirements implementation tracking. The structure of individual requirements was analyzed to detect the building blocks and extract relevant parts that can be mapped to the model components. Further, all requirements were classified into one of the defined domains to provide the basis for referencing similar requirements from different standards. Finally, one arbitrary requirement was used to demonstrate model usage, and depict all available information that can be provided to the users in a custom-made scenario where the need arises to have simultaneous alignment with three standards—NISTIR 7628, NIST 800-53, and IEC 62443-3-3.
first_indexed 2024-03-10T06:04:30Z
format Article
id doaj.art-46f7e67820df49c399cbb0898f3fe9c5
institution Directory Open Access Journal
issn 1996-1073
language English
last_indexed 2024-03-10T06:04:30Z
publishDate 2021-10-01
publisher MDPI AG
record_format Article
series Energies
spelling doaj.art-46f7e67820df49c399cbb0898f3fe9c52023-11-22T20:40:02ZengMDPI AGEnergies1996-10732021-10-011421686210.3390/en14216862Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart GridMilan Stojkov0Nikola Dalčeković1Branko Markoski2Branko Milosavljević3Goran Sladić4Faculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaFaculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaTechnical Faculty Mihajlo Pupin, University of Novi Sad, Đure Đakovića bb, 23000 Zrenjanin, SerbiaFaculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaFaculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaThe critical infrastructure is constantly under cyber and physical threats. Applying security controls without guidance or traceability can create a false sense of security. Security standards facilitate security knowledge and control best practices in a more systematic way. However, the number of standards is continually increasing. Product providers that operate in multiple geographical regions often face the obligation to comply with multiple standards simultaneously. This introduces the problem of the convenient interpretation of different standards. Thus, a comprehensive analysis of the requirements from different security standards and guidelines applicable to the smart grid has been performed to detect similarities that can be shaped into entities of the conceptual model for requirement representation. The purpose of the model—presented in a form of a Unified Modeling Language (UML) class diagram—is to give product providers a canonical way to map requirements from arbitrary standards, guidelines, and regulations and accelerate the cross-standard compliance readiness by defining priority for requirement implementation. In addition, the research showed that multiple vectors should impact the priority of the implementation of the security controls defined through the requirements: domain affiliation, the essence of the requirement, associated threats, risks, and social dependencies between actors involved in the implementation. To examine the model correctness, NISTIR 7628—de facto smart grid standard—was used to provide insights into how the model would be used for requirements implementation tracking. The structure of individual requirements was analyzed to detect the building blocks and extract relevant parts that can be mapped to the model components. Further, all requirements were classified into one of the defined domains to provide the basis for referencing similar requirements from different standards. Finally, one arbitrary requirement was used to demonstrate model usage, and depict all available information that can be provided to the users in a custom-made scenario where the need arises to have simultaneous alignment with three standards—NISTIR 7628, NIST 800-53, and IEC 62443-3-3.https://www.mdpi.com/1996-1073/14/21/6862critical infrastructure protectionsmart gridstandardscompliancesecurity requirementsrequirement prioritization
spellingShingle Milan Stojkov
Nikola Dalčeković
Branko Markoski
Branko Milosavljević
Goran Sladić
Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
Energies
critical infrastructure protection
smart grid
standards
compliance
security requirements
requirement prioritization
title Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
title_full Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
title_fullStr Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
title_full_unstemmed Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
title_short Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
title_sort towards cross standard compliance readiness security requirements model for smart grid
topic critical infrastructure protection
smart grid
standards
compliance
security requirements
requirement prioritization
url https://www.mdpi.com/1996-1073/14/21/6862
work_keys_str_mv AT milanstojkov towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid
AT nikoladalcekovic towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid
AT brankomarkoski towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid
AT brankomilosavljevic towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid
AT goransladic towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid