A Multi-level Reference Model and a Dedicated Method for Cyber-Security by Design
Sybren Kinderen (),
Monika Kaczmarek-Heß and
Simon Hacks
Additional contact information
Sybren Kinderen: Eindhoven University of Technology
Monika Kaczmarek-Heß: University of Duisburg-Essen
Simon Hacks: Stockholm University
Business & Information Systems Engineering: The International Journal of WIRTSCHAFTSINFORMATIK, 2025, vol. 67, issue 4, No 5, 530 pages
Abstract:
Abstract The increased reliance of organizations on information technology inherently increases their vulnerability to cyber-security attacks. As a response, a host of cyber-security approaches exists. While useful, these approaches exhibit shortcomings such as an inclination to be fragmented, not accounting for up-to-date organizational data, focusing on singular vulnerabilities only, and being reactive, i.e., focusing on patching up vulnerabilities in current systems. The paper presents and evaluates a modeling method aiming to address those shortcomings and to support security by design with a focus on the electricity sector. The proposed modeling method encompasses a multi-level reference model reconstructing and integrating existing initiatives and supporting top-down and bottom-up analyses. Compared to earlier work, the paper contributes (1) a process model for cyber-security by design, which proactively considers security as a first-class citizen during the design process, (2) a complete coverage of the multi-level model, in terms of three views complementing the introduced process model, (3) an elaborated evaluation, in terms of reporting on an additional design science cycle.
Keywords: Cyber-security by design; Modeling method; Security reference framework; Security analysis; Multi-level modeling (search for similar items in EconPapers)
Date: 2025
References: Add references at CitEc
Citations:
Downloads: (external link)
http://link.springer.com/10.1007/s12599-024-00899-y Abstract (text/html)
Access to the full text of the articles in this series is restricted.
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:spr:binfse:v:67:y:2025:i:4:d:10.1007_s12599-024-00899-y
Ordering information: This journal article can be ordered from
http://www.springer.com/economics/journal/12599
DOI: 10.1007/s12599-024-00899-y
Access Statistics for this article
Business & Information Systems Engineering: The International Journal of WIRTSCHAFTSINFORMATIK is currently edited by Martin Bichler
More articles in Business & Information Systems Engineering: The International Journal of WIRTSCHAFTSINFORMATIK from Springer, Gesellschaft für Informatik e.V. (GI)
Bibliographic data for series maintained by Sonal Shukla () and Springer Nature Abstracting and Indexing ().