The Cyber Security Requirements Methodology and Meta‐Model for Design of Cyber‐Resilience
Tim Sherburne, Megan M. Clifford, Barry Horowitz, Peter A. Beling · 2023
In this chapter, a methodology called the Cyber Security Requirements Methodology (CSRM) is introduced as a means of identifying resilience requirements during the initial design phase of physical system programs. CSRM is designed to provide a framework for implementing cyber defense and resilience solutions, as well as security-based software engineering solutions. The methodology involves six sequential steps, each executed by one of four distinct teams representing stakeholders in the security engineering process. CSRM is built upon the STPA, Mission Aware, and FOREST methodologies, which are covered in Chapters 23–25, respectively, and is implemented using a model-based engineering framework. To illustrate the methodology, the chapter includes a demonstration using a hypothetical weapons system called Silverfish, which is also the focus of Chapter 27.