Title :
What does the Assurance Case Approach deliver for Critical Information Infrastructure Protection in cybersecurity?
Author :
Goodger, A.C. ; Caldwell, N.H.M. ; Knowles, J.T.
Author_Institution :
Dept. of Eng., Univ. of Cambridge, Cambridge, UK
Abstract :
This paper describes how the Assurance Case Approach (ACA) was applied for Cyber Security and Critical National Infrastructure resilience, using for a single asset an individual Assurance Case (AC), and for system-of-systems clustering a `Mesh´ case concept. Despite its common use in the Safety domain, the ACA concept had not been applied to a dynamic situation. It allowed for Cases to be clustered using a `Mesh´ Case to summarise a particular ecosystem/environment. This ACA is defined using basic elements of an assurance case ie Claim, argument and evidence - often associated with a legal analogy. Using the case study research method [27], the main methodology as stated in the paper combined the organisational learning cycle [1] with the 6-step based process based on a GSN [16] and CAE [2] notational hybrid for the construction of an argument structure. This was implemented with a CII asset, and further pilotted to demonstrate the ACA for other CII nodes [13]. The clustering using the `Mesh´ cases closely aligns with Interdependency Analysis for the UK interconnected system-of-systems. Further work is required to expand the `Mesh´ case principle for the 21st century information-centric ecosystem to provide a continual resilience work process framework, which eventually must include real-time inputs.
Keywords :
information management; security of data; ACA concept; CAE; Cyber Security and Critical National Infrastructure; GSN; UK interconnected system-of-systems; United Kingdom; assurance case approach; case study research method; computer aided engineering; continual resilience work process framework; critical information infrastructure protection; cybersecurity; goal structuring notation; individual assurance case; information-centric ecosystem; interdependency analysis; mesh case concept; organisational learning cycle; safety domain; system-of-systems clustering; Assurance Case; Cyber-security; Information Security; Informationcentric;
Conference_Titel :
System Safety, incorporating the Cyber Security Conference 2012, 7th IET International Conference on
Conference_Location :
Edinburgh
Electronic_ISBN :
978-1-84919-678-9
DOI :
10.1049/cp.2012.1501