ESSAM: A Method for Security Assessments by Embedded Systems Manufacturers
Friedrich Köster, Michael Klaas, HanhQuyen Nguyen, Markus Braendle, Martin Naedele, Walter Brenner · Alexandria (UniSG) (University of St.Gallen) · 2008
Abstract. The increasing integration of embedded systems for monitoring and control of critical infrastructures into enterprise networks has increased system manufacturers’ efforts to cover security aspects at the device level for a better “defense in depth”. This paper describes a security assessment method which has been developed in a joint research project with a large system manufacturer. A system’s assets and their security objectives as well as the security measures in place are documented. Collaborative reasoning of system and security experts about the rationales and assumptions behind current or planned implementations of a security architecture help to uncover weaknesses and vulnerabilities and to find mitigations. Keywords: Threat Modeling Method, Industrial Control System Security, Security Assessment, Embedded System Manufacturer, IT Security Risk Acknowledgement: This research project is funded with the help of the Swiss Confederation’s innovation promotion agency CTI. 1 Introduction