Better security assessment communication
Fabien Sechi, Gran Bjørn Axel, Per-Arne Jørgensen, Kilyukh Oleh · 2022
Security of complex process plants, such as nuclear power plants, requires assessing the information technology process and the operation technology process. When business processes and humans are included, it becomes challenging to identify all possible consequences arising from different business and technical threats and communicate them, when the case involves different languages, cultures, and competence backgrounds. This paper presents a four-step concept for supporting an ISO27002 security assessment using a unified model language (UML) sequence diagram capable of modeling actors and systems objects and their messages. First, we used the ISO27001 and RASCI table to identify the different levels of information security responsibility within a complex process plant. Secondly, together with the stakeholders of the plant, we built scenarios by making a reference architecture including the connection between IT and OT systems. Thirdly, we mapped the ISO 27002 security controls to the scenarios exemplified with the UML sequence diagram. Lastly, we assessed the maturity level. We tested the method together with the ICT team of a Ukrainian NPP on four different scenarios. The reference architecture included the plant data storage system that is making the plant data accessible for users on the enterprise network. The results indicate that communicating security controls by using UML sequence diagram scenarios displaying the bridge between IT and OT, ease the stakeholder's understanding of a complex process. Visualizing sequence diagrams and security controls in a combined way is an enabler for better communication during a security assessment.