Designing a Model-agnostic Cybersecurity and Functional Safety Risk Assessment Tool
2025 (English)Independent thesis Basic level (degree of Bachelor), 10,5 credits / 16 HE credits
Student thesisAlternative title
Utformning av ett modellagnostiskt riskbedömningsverktyg inom cybersäkerhet och funktionell säkerhet (Swedish)
Abstract [en]
Security and safety are two concerns within digital infrastructure that have thus far only been mapped out separately by tools that currently exist. Security revolves around the intended operation of software and hardware in accordance with the CIA attributes (Confidentiality, Integrity, and Availability). Safety, on the other hand, generally pertains to upholding the quality of life for the people depending on, operating, and using said systems. However, there are several sectors within critical infrastructure that need to consider both when conducting risk analysis. The purpose of this study is to propose a solution to the problems that arise when assessing risks associated with both cybersecurity and functional safety in parallel. Using the design science research method, we conducted the work in two cycles. The first cycle was focused on the gathering of information and forming a basis for the tool. The second was more focused on developing the actual tool. The output of the study results in the HARA/TARA Tool. It was designed to be flexible and lightweight. The flexibility comes from the user's ability to create methods with custom dimensions, parameters, and formulas. This allows for a diverse set of risk assessment methods to be crafted and used, and for functional safety to be integrated. The tool was evaluated by professionals, who thought the features showed promise. At the end of the study, the tool was a proof of concept in terms of its ability to incorporate functional safety, and will see further maintenance beyond the study.
Place, publisher, year, edition, pages
2025. , p. 10
Keywords [en]
cybersecurity, functional safety, safety, security, tool, HARA, TARA, HATARA, THARA, TARA+AD, HEAVENS, STRIDE, CIA, Qt, SQL
National Category
Security, Privacy and Cryptography Human Computer Interaction
Identifiers
URN: urn:nbn:se:liu:diva-216017ISRN: LIU-IDA/LITH-EX-G--25/051--SEOAI: oai:DiVA.org:liu-216017DiVA, id: diva2:1981884
External cooperation
RISE Research Institutes of Sweden AB
Subject / course
Computer Engineering
Supervisors
Examiners
Projects
CyREC (Cybersecurity for Resilient Energy Communities of the Future)2025-11-272025-07-072025-11-27Bibliographically approved