Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid
The critical infrastructure is constantly under cyber and physical threats. Applying security controls without guidance or traceability can create a false sense of security. Security standards facilitate security knowledge and control best practices in a more systematic way. However, the number of s...
Main Authors: | , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2021-10-01
|
Series: | Energies |
Subjects: | |
Online Access: | https://www.mdpi.com/1996-1073/14/21/6862 |
_version_ | 1797512631357014016 |
---|---|
author | Milan Stojkov Nikola Dalčeković Branko Markoski Branko Milosavljević Goran Sladić |
author_facet | Milan Stojkov Nikola Dalčeković Branko Markoski Branko Milosavljević Goran Sladić |
author_sort | Milan Stojkov |
collection | DOAJ |
description | The critical infrastructure is constantly under cyber and physical threats. Applying security controls without guidance or traceability can create a false sense of security. Security standards facilitate security knowledge and control best practices in a more systematic way. However, the number of standards is continually increasing. Product providers that operate in multiple geographical regions often face the obligation to comply with multiple standards simultaneously. This introduces the problem of the convenient interpretation of different standards. Thus, a comprehensive analysis of the requirements from different security standards and guidelines applicable to the smart grid has been performed to detect similarities that can be shaped into entities of the conceptual model for requirement representation. The purpose of the model—presented in a form of a Unified Modeling Language (UML) class diagram—is to give product providers a canonical way to map requirements from arbitrary standards, guidelines, and regulations and accelerate the cross-standard compliance readiness by defining priority for requirement implementation. In addition, the research showed that multiple vectors should impact the priority of the implementation of the security controls defined through the requirements: domain affiliation, the essence of the requirement, associated threats, risks, and social dependencies between actors involved in the implementation. To examine the model correctness, NISTIR 7628—de facto smart grid standard—was used to provide insights into how the model would be used for requirements implementation tracking. The structure of individual requirements was analyzed to detect the building blocks and extract relevant parts that can be mapped to the model components. Further, all requirements were classified into one of the defined domains to provide the basis for referencing similar requirements from different standards. Finally, one arbitrary requirement was used to demonstrate model usage, and depict all available information that can be provided to the users in a custom-made scenario where the need arises to have simultaneous alignment with three standards—NISTIR 7628, NIST 800-53, and IEC 62443-3-3. |
first_indexed | 2024-03-10T06:04:30Z |
format | Article |
id | doaj.art-46f7e67820df49c399cbb0898f3fe9c5 |
institution | Directory Open Access Journal |
issn | 1996-1073 |
language | English |
last_indexed | 2024-03-10T06:04:30Z |
publishDate | 2021-10-01 |
publisher | MDPI AG |
record_format | Article |
series | Energies |
spelling | doaj.art-46f7e67820df49c399cbb0898f3fe9c52023-11-22T20:40:02ZengMDPI AGEnergies1996-10732021-10-011421686210.3390/en14216862Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart GridMilan Stojkov0Nikola Dalčeković1Branko Markoski2Branko Milosavljević3Goran Sladić4Faculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaFaculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaTechnical Faculty Mihajlo Pupin, University of Novi Sad, Đure Đakovića bb, 23000 Zrenjanin, SerbiaFaculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaFaculty of Technical Sciences, University of Novi Sad, Trg D. Obradovića 6, 21000 Novi Sad, SerbiaThe critical infrastructure is constantly under cyber and physical threats. Applying security controls without guidance or traceability can create a false sense of security. Security standards facilitate security knowledge and control best practices in a more systematic way. However, the number of standards is continually increasing. Product providers that operate in multiple geographical regions often face the obligation to comply with multiple standards simultaneously. This introduces the problem of the convenient interpretation of different standards. Thus, a comprehensive analysis of the requirements from different security standards and guidelines applicable to the smart grid has been performed to detect similarities that can be shaped into entities of the conceptual model for requirement representation. The purpose of the model—presented in a form of a Unified Modeling Language (UML) class diagram—is to give product providers a canonical way to map requirements from arbitrary standards, guidelines, and regulations and accelerate the cross-standard compliance readiness by defining priority for requirement implementation. In addition, the research showed that multiple vectors should impact the priority of the implementation of the security controls defined through the requirements: domain affiliation, the essence of the requirement, associated threats, risks, and social dependencies between actors involved in the implementation. To examine the model correctness, NISTIR 7628—de facto smart grid standard—was used to provide insights into how the model would be used for requirements implementation tracking. The structure of individual requirements was analyzed to detect the building blocks and extract relevant parts that can be mapped to the model components. Further, all requirements were classified into one of the defined domains to provide the basis for referencing similar requirements from different standards. Finally, one arbitrary requirement was used to demonstrate model usage, and depict all available information that can be provided to the users in a custom-made scenario where the need arises to have simultaneous alignment with three standards—NISTIR 7628, NIST 800-53, and IEC 62443-3-3.https://www.mdpi.com/1996-1073/14/21/6862critical infrastructure protectionsmart gridstandardscompliancesecurity requirementsrequirement prioritization |
spellingShingle | Milan Stojkov Nikola Dalčeković Branko Markoski Branko Milosavljević Goran Sladić Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid Energies critical infrastructure protection smart grid standards compliance security requirements requirement prioritization |
title | Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid |
title_full | Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid |
title_fullStr | Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid |
title_full_unstemmed | Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid |
title_short | Towards Cross-Standard Compliance Readiness: Security Requirements Model for Smart Grid |
title_sort | towards cross standard compliance readiness security requirements model for smart grid |
topic | critical infrastructure protection smart grid standards compliance security requirements requirement prioritization |
url | https://www.mdpi.com/1996-1073/14/21/6862 |
work_keys_str_mv | AT milanstojkov towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid AT nikoladalcekovic towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid AT brankomarkoski towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid AT brankomilosavljevic towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid AT goransladic towardscrossstandardcompliancereadinesssecurityrequirementsmodelforsmartgrid |