Cybersecurity regulation: cybersecurity certification of operational technologies

The object of research is the system and schemes of conformity assessment (certification) of cybersecurity of operational technologies (OT), as a set of rules and procedures that describe the objects of certification, determine the specified requirements and provide a methodology for certification....

Full description

Bibliographic Details
Main Author: Olena Tsvilii
Format: Article
Language:English
Published: PC Technology Center 2021-02-01
Series:Technology Audit and Production Reserves
Subjects:
Online Access:http://journals.uran.ua/tarp/article/view/225271
id doaj-189eb29f0d5a4eae9f67e3475f64712d
record_format Article
spelling doaj-189eb29f0d5a4eae9f67e3475f64712d2021-03-11T15:55:08ZengPC Technology CenterTechnology Audit and Production Reserves2664-99692706-54482021-02-0112(57)546010.15587/2706-5448.2021.225271262745Cybersecurity regulation: cybersecurity certification of operational technologiesOlena Tsvilii0https://orcid.org/0000-0002-4414-9881O. S. Popov Odesa National Academy of TelecommunicationsThe object of research is the system and schemes of conformity assessment (certification) of cybersecurity of operational technologies (OT), as a set of rules and procedures that describe the objects of certification, determine the specified requirements and provide a methodology for certification. The terminological base and conceptual apparatus of the study of cybersecurity certification of operational technologies are based on the international standard ISO 17000:2020 Conformity assessment – Vocabulary and general principles. Cybersecurity certification systems and schemes are based on assessment standards, the choice and application of which is not unambiguous and historically has many interpretations and application mechanisms. These standards consist of tools, policies, security concepts, security assurances, guidelines, risk management approaches, best practices, safeguards, and technologies. But they have, to one degree or another, a significant drawback – the complexity of transforming the results of information security assessment according to these standards into security guarantees with any wide international recognition. In the context of globalization, this significantly degrades the cybersecurity quality. The main hypothesis of research is that the cybersecurity quality can be improved by converging towards a common methodology that is based on agreed international standards and international best practice for certification. The question of the key role of cybersecurity for operational technologies, which become the basis for Economy 4.0 and are now considered as a new frontier of cybersecurity, is considered. The need to create a system and schemes for certification of OT cybersecurity based on international and European certification principles is shown. A hierarchical model of cybersecurity certification system assessment standards and a hierarchical model of agreements on mutual recognition of cybersecurity certificates have been developed, which will allow a systematic approach to the creation of a system and schemes for OT cybersecurity certification. This provides an opportunity for developers of systems and certification schemes to form OT cybersecurity certification systems based on the principles of wide cross-border recognition of OT cybersecurity certificates.http://journals.uran.ua/tarp/article/view/225271cybersecurity systemconformity assessment systemhierarchical modelcybersecurity certification scheme
collection DOAJ
language English
format Article
sources DOAJ
author Olena Tsvilii
spellingShingle Olena Tsvilii
Cybersecurity regulation: cybersecurity certification of operational technologies
Technology Audit and Production Reserves
cybersecurity system
conformity assessment system
hierarchical model
cybersecurity certification scheme
author_facet Olena Tsvilii
author_sort Olena Tsvilii
title Cybersecurity regulation: cybersecurity certification of operational technologies
title_short Cybersecurity regulation: cybersecurity certification of operational technologies
title_full Cybersecurity regulation: cybersecurity certification of operational technologies
title_fullStr Cybersecurity regulation: cybersecurity certification of operational technologies
title_full_unstemmed Cybersecurity regulation: cybersecurity certification of operational technologies
title_sort cybersecurity regulation: cybersecurity certification of operational technologies
publisher PC Technology Center
series Technology Audit and Production Reserves
issn 2664-9969
2706-5448
publishDate 2021-02-01
description The object of research is the system and schemes of conformity assessment (certification) of cybersecurity of operational technologies (OT), as a set of rules and procedures that describe the objects of certification, determine the specified requirements and provide a methodology for certification. The terminological base and conceptual apparatus of the study of cybersecurity certification of operational technologies are based on the international standard ISO 17000:2020 Conformity assessment – Vocabulary and general principles. Cybersecurity certification systems and schemes are based on assessment standards, the choice and application of which is not unambiguous and historically has many interpretations and application mechanisms. These standards consist of tools, policies, security concepts, security assurances, guidelines, risk management approaches, best practices, safeguards, and technologies. But they have, to one degree or another, a significant drawback – the complexity of transforming the results of information security assessment according to these standards into security guarantees with any wide international recognition. In the context of globalization, this significantly degrades the cybersecurity quality. The main hypothesis of research is that the cybersecurity quality can be improved by converging towards a common methodology that is based on agreed international standards and international best practice for certification. The question of the key role of cybersecurity for operational technologies, which become the basis for Economy 4.0 and are now considered as a new frontier of cybersecurity, is considered. The need to create a system and schemes for certification of OT cybersecurity based on international and European certification principles is shown. A hierarchical model of cybersecurity certification system assessment standards and a hierarchical model of agreements on mutual recognition of cybersecurity certificates have been developed, which will allow a systematic approach to the creation of a system and schemes for OT cybersecurity certification. This provides an opportunity for developers of systems and certification schemes to form OT cybersecurity certification systems based on the principles of wide cross-border recognition of OT cybersecurity certificates.
topic cybersecurity system
conformity assessment system
hierarchical model
cybersecurity certification scheme
url http://journals.uran.ua/tarp/article/view/225271
work_keys_str_mv AT olenatsvilii cybersecurityregulationcybersecuritycertificationofoperationaltechnologies
_version_ 1724223678085857280