Skip to main content

2018 | OriginalPaper | Buchkapitel

Towards Educational Guidelines for the Security Systems Engineer

verfasst von : Suné von Solms, Annlizé Marnewick

Erschienen in: Information Security Education – Towards a Cybersecure Society

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Industry 4.0 will impact the systems engineering landscape and cybersecurity in the future. The education needs of system engineers working in these environments will change as the system landscape adapt to the Industry 4.0 changes. This research aims to explore the impact of Industry 4.0 on systems engineering and security requirements which must be catered for in future in this changing Industry 4.0 landscape. Although it is not certain yet how the landscape will change, this research starts to explore what the potential education needs could be for system engineers to understand all future cybersecurity requirements. The results of this research indicate that security requirements engineering will be needed in the first requirements stage of the systems development life cycle. Secondly, a new set of expert engineering skills will be required to identify future threats and vulnerabilities which could impact the system landscape. These results can be used as a guideline to start thinking how system engineers should be educated for the future.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Kiel, A.: What do we know about “Industry 4.0” so far? In: Proceedings of the International Association for Management of Technology (IAMOT 2017) (2017) Kiel, A.: What do we know about “Industry 4.0” so far? In: Proceedings of the International Association for Management of Technology (IAMOT 2017) (2017)
2.
Zurück zum Zitat Hermann, M., Pentek, T., Otto, B.: Design principles for Industrie 4.0 scenarios. In: 49th Hawaii International Conference on System Sciences (HICSS), pp. 3928–3937 (2016) Hermann, M., Pentek, T., Otto, B.: Design principles for Industrie 4.0 scenarios. In: 49th Hawaii International Conference on System Sciences (HICSS), pp. 3928–3937 (2016)
4.
Zurück zum Zitat Motyl, B., Baronio, G., Uberti, S., Speranza, D., Filippi, S.: How will change the future engineers’ skills in the Industry 4.0 framework? A questionnaire survey. Procedia Manuf. 11, 1501–1509 (2017)CrossRef Motyl, B., Baronio, G., Uberti, S., Speranza, D., Filippi, S.: How will change the future engineers’ skills in the Industry 4.0 framework? A questionnaire survey. Procedia Manuf. 11, 1501–1509 (2017)CrossRef
6.
Zurück zum Zitat Kim, Y.: Activities of security engineering in system development life cycle: security engineer’s view. Presented at the 14th International Conference on Applications of Computer Engineering (ACE 2015), Seoul, South Korea, 5–7 September 2015 Kim, Y.: Activities of security engineering in system development life cycle: security engineer’s view. Presented at the 14th International Conference on Applications of Computer Engineering (ACE 2015), Seoul, South Korea, 5–7 September 2015
8.
Zurück zum Zitat Haridas, N.: Software Engineering – Security as a Process in the SDLC. SANS Institute InfoSec Reading Room (2007) Haridas, N.: Software Engineering – Security as a Process in the SDLC. SANS Institute InfoSec Reading Room (2007)
11.
Zurück zum Zitat Newhouse, W., Keith, S., Scribner, B., Witte, G.: National Initiative for Cybersecurity Education (NICE) cybersecurity workforce framework. In: Special Publication 800-181, NIST 2017 (2017) Newhouse, W., Keith, S., Scribner, B., Witte, G.: National Initiative for Cybersecurity Education (NICE) cybersecurity workforce framework. In: Special Publication 800-181, NIST 2017 (2017)
12.
Zurück zum Zitat Kissel, R.L., Stine, K.M., Scholl, M.A., Rossman, H., Fahlsing, J., Gulick, J.: Security considerations in the system development life cycle. In: NIST Special Publication 800-64, NIST 2018 (2018) Kissel, R.L., Stine, K.M., Scholl, M.A., Rossman, H., Fahlsing, J., Gulick, J.: Security considerations in the system development life cycle. In: NIST Special Publication 800-64, NIST 2018 (2018)
13.
Zurück zum Zitat Dawson, M., Burrell, D., Rahim, E., Brewster, S.: Integrating software assurance into the Software Development Life Cycle (SDLC). J. Inf. Syst. Technol. Plan. 3(6), 49–53 (2010) Dawson, M., Burrell, D., Rahim, E., Brewster, S.: Integrating software assurance into the Software Development Life Cycle (SDLC). J. Inf. Syst. Technol. Plan. 3(6), 49–53 (2010)
14.
Zurück zum Zitat Mailloux, L.O., Garrison, C., Dove, R., Biondo, R.C.: Guidance for working group maintenance of the Systems Engineering Body of Knowledge (SEBoK) with systems security engineering example. In: INCOSE International Symposium, vol. 25, no. 1, pp. 1004–1019 (2015)CrossRef Mailloux, L.O., Garrison, C., Dove, R., Biondo, R.C.: Guidance for working group maintenance of the Systems Engineering Body of Knowledge (SEBoK) with systems security engineering example. In: INCOSE International Symposium, vol. 25, no. 1, pp. 1004–1019 (2015)CrossRef
15.
Zurück zum Zitat Salini, P., Kanmani, S.: Survey and analysis on security requirements engineering. Comput. Electr. Eng. 38(6), 1785–1797 (2012)CrossRef Salini, P., Kanmani, S.: Survey and analysis on security requirements engineering. Comput. Electr. Eng. 38(6), 1785–1797 (2012)CrossRef
16.
Zurück zum Zitat Evans, S., Heinbuch, D., Kyle, E., Piorkowski, J., Wallner, J.: Risk-based systems security engineering: stopping attacks with intention. IEEE Secur. Priv. 2(6), 59–62 (2004)CrossRef Evans, S., Heinbuch, D., Kyle, E., Piorkowski, J., Wallner, J.: Risk-based systems security engineering: stopping attacks with intention. IEEE Secur. Priv. 2(6), 59–62 (2004)CrossRef
17.
Zurück zum Zitat ISO, ISO/IEC/IEEE International Standard - Systems and software engineering – System life cycle processes. ISO/IEC/IEEE 15288 First edition 2015–05–15, pp. 1–118 (2015) ISO, ISO/IEC/IEEE International Standard - Systems and software engineering – System life cycle processes. ISO/IEC/IEEE 15288 First edition 2015–05–15, pp. 1–118 (2015)
18.
Zurück zum Zitat Parnell, G.S., Driscoll, P.J., Henderson, D.: Decision Making in Systems Engineering and Management. Systems Engineering and Management, p. 497. Wiley, Hoboken (2011) Parnell, G.S., Driscoll, P.J., Henderson, D.: Decision Making in Systems Engineering and Management. Systems Engineering and Management, p. 497. Wiley, Hoboken (2011)
19.
Zurück zum Zitat Sage, A.P., Rouse, W.: Handbook of Systems Engineering and Management. Wiley Series in Systems Engineering and Management. Wiley, Chicester (2009) Sage, A.P., Rouse, W.: Handbook of Systems Engineering and Management. Wiley Series in Systems Engineering and Management. Wiley, Chicester (2009)
20.
Zurück zum Zitat Walden, D.D., Roedler, G.J., Forsberg, K.J., Hamelin, R.D., Shortell, T.M.: INCOSE Systems Engineering Handbook: A Guide for System Life Cycle Processes and Activities. Wiley, Hoboken (2015) Walden, D.D., Roedler, G.J., Forsberg, K.J., Hamelin, R.D., Shortell, T.M.: INCOSE Systems Engineering Handbook: A Guide for System Life Cycle Processes and Activities. Wiley, Hoboken (2015)
21.
Zurück zum Zitat Nejib, P., Beyer, D., Yakabovicz, E.: Systems security engineering: what every system engineer needs to know. In: INCOSE International Symposium, vol. 27, no. 1, pp. 434–445 (2017)CrossRef Nejib, P., Beyer, D., Yakabovicz, E.: Systems security engineering: what every system engineer needs to know. In: INCOSE International Symposium, vol. 27, no. 1, pp. 434–445 (2017)CrossRef
22.
Zurück zum Zitat Zemrowski, K.M.: NIST bases flagship security engineering publication on ISO/IEC/IEEE 15288:2015. Computer 49(12), 86–88 (2016)CrossRef Zemrowski, K.M.: NIST bases flagship security engineering publication on ISO/IEC/IEEE 15288:2015. Computer 49(12), 86–88 (2016)CrossRef
23.
Zurück zum Zitat Türpe, S.: The trouble with security requirements. In: IEEE 25th International Requirements Engineering Conference (RE 2017), pp. 122–133 (2017) Türpe, S.: The trouble with security requirements. In: IEEE 25th International Requirements Engineering Conference (RE 2017), pp. 122–133 (2017)
24.
Zurück zum Zitat National Institute of Standards and Technology (NIST), Guide for Conducting Risk Assessments, NIST 800-30 (2012) National Institute of Standards and Technology (NIST), Guide for Conducting Risk Assessments, NIST 800-30 (2012)
25.
Zurück zum Zitat Blanchard, B.S., Blyler, J.E.: System Engineering Management. Wiley, Hoboken (2016)CrossRef Blanchard, B.S., Blyler, J.E.: System Engineering Management. Wiley, Hoboken (2016)CrossRef
26.
Zurück zum Zitat Bayuk, J.L., Horowitz, B.M.: An architectural systems engineering methodology for addressing cyber security. Syst. Eng. 14(3), 294–304 (2011)CrossRef Bayuk, J.L., Horowitz, B.M.: An architectural systems engineering methodology for addressing cyber security. Syst. Eng. 14(3), 294–304 (2011)CrossRef
29.
Zurück zum Zitat von Solms, S., Futcher, L.: Towards the design of a cybersecurity module for postgraduate engineering studies. In: Eleventh International Symposium on Human Aspects of Information Security and Assurance (HAISA 2017), Adelaide, Australia (2017) von Solms, S., Futcher, L.: Towards the design of a cybersecurity module for postgraduate engineering studies. In: Eleventh International Symposium on Human Aspects of Information Security and Assurance (HAISA 2017), Adelaide, Australia (2017)
Metadaten
Titel
Towards Educational Guidelines for the Security Systems Engineer
verfasst von
Suné von Solms
Annlizé Marnewick
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-99734-6_5

Premium Partner