Industrial control systems (ICS) are part of critical infrastructure and have continuously evolved, with physical control mechanisms being replaced by automated systems. In the past, ICS were more susceptible to malfunctions, which were addressed through functional safety measures. In recent years, however, ICS have additionally been exposed to attacks and cyber threats that must be mitigated using information security mechanisms. Risk management is therefore a central aspect of the safe operation of industrial facilities. Currently, associated methods treat functional safety (safety) and information security (security) separately and rely on manual assessments, which are time-consuming and can lead to unintended errors and, consequently, incorrect evaluations.
To address the challenges of fragmented and manual security risk assessments in ICS, this project develops an integrated, (semi-)automated methodology tailored to the specific requirements of modern industrial automation environments. In view of the increasing complexity in Industry 4.0, the Industrial Internet of Things (IIoT), and digital transformation in general, this approach unifies safety and security perspectives using a framework based on Bayesian Belief Networks (BBNs). The selected approach enables probabilistic modeling of uncertainties and dependencies within ICS components to predict failures or security breaches. The methodology is supported by information modeling techniques using AutomationML (AML) and Asset Administration Shells (AAS), as well as semantic ontologies, which provide an unambiguous, structured, and interoperable foundation for risk-relevant data