Åpne denne publikasjonen i ny fane eller vindu >>Vise andre…
2025 (engelsk)Inngår i: 2025 AIAA DATC/IEEE 44th Digital Avionics Systems Conference (DASC), IEEE conference proceedings, 2025Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]
The security risk management discipline has historically been less developed than safety management systems, but the rapid digitalization of industries creates an urgent need for more proactive approaches. Current methods often rely on outdated lists and paper-based processes, leading to overlooked vulnerabilities and delayed responses to emerging threats. This paper presents a possible enhancement of the existing cyber and physical Security Risk Assessment Methodology (SecRAM). The enhanced SecRAM is currently validated through dedicated exercises and expert input. The approach considers cascading effects for attack and impact propagation, and is embedded within a system framework that recognizes interconnections and dependencies between services, systems, procedures, roles, and functions. With its web-based tool and user-friendly interface, the enhanced SecRAM proves its general applicability and shows potential for broader adoption across sectors, particularly aviation. Future work will focus on integrating automation and AI to improve efficiency and accuracy in risk assessments.
sted, utgiver, år, opplag, sider
IEEE conference proceedings, 2025
Serie
Conference on Digital Avionics Systems (DASC), ISSN 2155-7195, E-ISSN 2155-7209
Emneord
cyber, security, risk assessment, risk management, tool support
HSV kategori
Identifikatorer
urn:nbn:se:liu:diva-220306 (URN)10.1109/DASC66011.2025.11257275 (DOI)9798331525194 (ISBN)9798331525200 (ISBN)
Konferanse
2025 AIAA DATC/IEEE 44th Digital Avionics Systems Conference (DASC), Montreal, QC, Canada, 14-18 September 2025
Forskningsfinansiär
EU, Horizon Europe, 101114635
Merknad
This project has received funding from the SESAR Joint Undertaking under the European Union’s Horizon Europe research and innovation programme under grant agreement No 101114635.
2026-01-092026-01-092026-01-12