The goal of the project is to identify approaches for modeling secure system architectures in an industrial environment. The resulting model is intended to fulfill both cybersecurity requirements and functional safety requirements. Assets to be protected are identified using a risk-based approach, since the failure of a safety-critical device can cause greater damage across the overall architecture.
Attack vectors and threats to the assets are identified, taking into account communication between machines and the integration of IT (Information Technology) with OT (Operational Technology). To model the desired secure architecture, classical IT threat models and threat models relevant to functional safety are reviewed, adapted, and combined.
Depending on the identified threats, a threat model is created that estimates the overall risk. Based on the identified threats, a catalog of protective measures is developed to evaluate the existing level of cybersecurity and functional safety for OT systems. International standards are used to create the architecture model.