Cyber Physical Systems Security for Maritime Assets

Безопасность киберфизических систем морских активов
Iosif Progoulakis, Paul Rohmeyer, Никитас Никитакос
2021-12-05

IT and OT securityMITRE ATT&CKNIST Cybersecurity Frameworkcybersecurity risk assessmentmaritime cyber physical systems
The integration of IT, OT, and human factor elements in maritime assets is critical for their efficient and safe operation and performance. This integration defines cyber physical systems and involves a number of IT and OT components, systems, and functions that involve multiple and diverse communication paths that are technologically and operationally evolving along with credible cyber security threats. These cyber security threats and risks as well as a number of known security breach scenarios are described in this paper to highlight the evolution of cyber physical systems in the maritime domain and their emerging cyber vulnerabilities. Current industry and governmental standards and directives related to cyber security in the maritime domain attempt to enforce the regulatory compliance and reinforce asset cyber security integrity for optimum and safe performance with limited focus, however, in the existing OT infrastructure and systems. The use of outside-of-the-maritime industry security risk assessment tools and processes, such the API STD 780 Security Risk Assessment (SRA) and the Bow Tie Analysis methodologies, can assist the asset owner to assess its IT and OT infrastructure for cyber and physical security vulnerabilities and allocate proper mitigation measures assuming their similarities to ICS infrastructure. The application of cyber security controls deriving from the adaptation of the NIST CSF and the MITRE ATT&CK Threat Model can further increase the cyber security integrity of maritime assets, assuming they are periodically evaluated for their effectiveness and applicability. Finally, the improvement in communication among stakeholders, the increase in operational and technical cyber and physical security resiliency, and the increase in operational cyber security awareness would be further increased for maritime assets by the convergence of the distinct physical and cyber security functions as well as onshore- and offshore-based cyber infrastructure of maritime companies and asset owners.
1
API STD 780 Security Risk Assessment and Bow Tie Analysis can help maritime asset owners identify cyber and physical vulnerabilities and assign mitigation measures.
2
Adapting the NIST Cybersecurity Framework and MITRE ATT&CK Threat Model can strengthen maritime asset cybersecurity when controls are periodically evaluated for effectiveness and applicability.
3
Converging physical and cybersecurity functions, onshore and offshore infrastructure, and stakeholder communication can improve maritime operational and technical resilience and cybersecurity awareness.
4
Existing maritime cybersecurity standards and directives provide limited coverage of vulnerabilities in operational technology infrastructure and systems.
5
Maritime cyber physical systems integrate IT, OT, and human factors across diverse, evolving communication paths, creating emerging cybersecurity vulnerabilities.

Maritime assets as cyber-physical systems integrating IT, OT, human factors, and maritime cyber infrastructure

Cybersecurity vulnerabilities, threat and risk scenarios, security assessment, mitigation controls, regulatory compliance, and cyber-physical resilience of maritime assets

Publication Details
Publication Date
2021-12-05
Journal
Publisher
ISSN
Cited by
72
Access Type
Author Information
Authors
Iosif Progoulakis
Paul Rohmeyer
Никитас Никитакос
Explore further
Open the scid.ai AI chat with a ready-made request: it will find papers on a similar topic and help build a literature review.
Find similar papers in the chat
Make a presentation
100%