The NCSC research problem book
Pages
Page 18 of 21
CP4 - How do we have confidence in the security of a cyber-physical system?

How do we have confidence in the security of a cyber-physical system?
We can’t always be sure that our actions to secure a system have worked. To have confidence here, we need to understand the claims being made. Fundamentally this is about how we validate and verify that security is doing what it should do in a system, and that this will continue over time.
Providing an evidence base to say how well a system is meeting security objectives is core to this. But as many cyber-physical systems are bespoke, it's difficult to create systems that are verifiably secure.
Strands or sub-problems
-
Assurance
It's a significant challenge to create and then implement wide-scale assurance schemes for all the technology underpinning critical infrastructure. How can we better understand what needs to be assured, how can it be assured, and how do we build confidence in the process and outputs?
-
Hardware
For a cyber-physical system to operate, the interface between the digital and physical worlds must be accurate and reliable. There is currently a significant assumption that these components will perform the tasks expected of them, but with little to no security consideration. For systems that rely on accuracy operation to specific tolerances, a set of clear operational principles need to be defined.
-
Testing
Testing cyber-physical systems can be difficult, either because it’s hard to create testing environments in the first place, or because of the safety restrictions that are often in place in a live system. This limits how realistically techniques for testing and evaluation processes can explore real-world impacts. As a result, the newer approaches explored in IT systems can’t be as easily applied to an OT environment.
-
Risk
When we think about risk in the cyber-physical context, there is a need to create a clear and robust way to describe risk for cyber-physical systems, as well as to understand how best to approach security risk in this environment and what can be taken from wider risk management approaches. It’s also important to consider what is unique about risk in cyber-physical systems – for example, thinking about risk over a longer timeframe than in a ‘traditional’ risk assessment. This also means looking at intricacies in the overlaps of safety and security, and considering policy decisions that impact the effectiveness of security decisions.