Loading [MathJax]/extensions/MathMenu.js
Qualitative Analysis for Validating IEC 62443-4-2 Requirements in DevSecOps | IEEE Conference Publication | IEEE Xplore

Qualitative Analysis for Validating IEC 62443-4-2 Requirements in DevSecOps


Abstract:

Validation of conformance to cybersecurity standards for industrial automation and control systems is an expensive and time consuming process which can delay the time to ...Show More

Abstract:

Validation of conformance to cybersecurity standards for industrial automation and control systems is an expensive and time consuming process which can delay the time to market. It is therefore crucial to introduce conformance validation stages into the continuous integration/continuous delivery pipeline of products. However, designing such conformance validation in an automated fashion is a highly non-trivial task that requires expert knowledge and depends upon available security tools, ease of integration into the DevOps pipeline, as well as support for IT and OT interfaces and protocols.This paper addresses the aforementioned problem focusing on the automated validation of ISA/IEC 62443-4-2 standard component requirements. We present an extensive qualitative analysis of the standard requirements and the current tooling landscape to perform validation. Our analysis demonstrates the coverage established by the currently available tools and sheds light on current gaps to achieve full automation and coverage. Furthermore, we showcase for every component requirement where in the CI/CD pipeline stage it is recommended to test it and the tools to do so.
Date of Conference: 12-15 September 2023
Date Added to IEEE Xplore: 12 October 2023
ISBN Information:

ISSN Information:

Conference Location: Sinaia, Romania

Contact IEEE to Subscribe

References

References is not available for this document.