SwePub
Sök i LIBRIS databas

  Utökad sökning

id:"swepub:oai:DiVA.org:ltu-76428"
 

Sökning: id:"swepub:oai:DiVA.org:ltu-76428" > Cybersecurity for r...

Cybersecurity for railways : A maturity model

Kour, Ravdeep, 1981- (författare)
Luleå tekniska universitet,Drift, underhåll och akustik
Karim, Ramin, 1964- (författare)
Luleå tekniska universitet,Drift, underhåll och akustik
Thaduri, Adithya (författare)
Luleå tekniska universitet,Drift, underhåll och akustik
 (creator_code:org_t)
2019-10-18
2020
Engelska.
Ingår i: Proceedings of the Institution of mechanical engineers. Part F, journal of rail and rapid transit. - : Sage Publications. - 0954-4097 .- 2041-3017. ; 234:10, s. 1129-1148
  • Tidskriftsartikel (refereegranskat)
Abstract Ämnesord
Stäng  
  • With the advancements in and widespread adoption of information and communication technologies in infrastructures, cyber-attacks are becoming more frequent and more severe. Advanced cybersecurity threats with automated capabilities are increasing in such sectors as finance, health, grid, retail, government, telecommunications, transportation, etc. Cyber-attacks are also increasing in railways with an impact on railway stakeholders, e.g. threat to the safety of employees, passengers, or the public in general; loss of sensitive railway information; reputational damage; monetary loss; erroneous decisions; loss of dependability, etc. There is a need to move towards advanced security analytics and automation to identify, respond to, and prevent such security breaches. The objective of this research is to reduce cyber risks and vulnerabilities and to improve the cybersecurity capabilities of railways by evaluating their cybersecurity maturity levels and making recommendations for improvements. After assessing various cybersecurity maturity models, the Cybersecurity Capability Maturity Model (C2M2) was selected to assess the cybersecurity capabilities of railway organizations. The contributions of this research are as follows. First, a new maturity level MIL4 (Maturity Indicator Level 4) is introduced in the C2M2 model. Second, the C2M2 model is adapted by adding advanced security analytics and threat intelligence to develop the Railway-Cybersecurity Capability Maturity Model (R-C2M2). The cybersecurity maturity of three railway organizations is evaluated using this model. Third, recommendations and available standards & guidelines are provided to the three railway organizations to improve maturity levels within different domains. In addition, they are given an action plan to implement the recommendations in a streamlined way. The application of this model will allow railway organizations to improve their capability to reduce the impacts of cyber-attacks and eradicate vulnerabilities. The approach can also be extended to other infrastructures with necessary adaptations.

Ämnesord

TEKNIK OCH TEKNOLOGIER  -- Samhällsbyggnadsteknik -- Annan samhällsbyggnadsteknik (hsv//swe)
ENGINEERING AND TECHNOLOGY  -- Civil Engineering -- Other Civil Engineering (hsv//eng)

Nyckelord

Cybersecurity
maturity level
Railway-Cybersecurity Capability Maturity Model
railway organizations
Cybersecurity Capability Maturity Model
Drift och underhållsteknik
Operation and Maintenance

Publikations- och innehållstyp

ref (ämneskategori)
art (ämneskategori)

Hitta via bibliotek

Till lärosätets databas

Sök utanför SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Stäng

Kopiera och spara länken för att återkomma till aktuell vy