Proposing Cyber Security Vulnerability and Exposure Indices for Detailed Cybersecurity Risk Management of Industrial Automation and Control Systems
Mohammad Mehdi Ahmadian, Bahareh Maleki Rad, Mohammad Hosein Ahmadian · 2025
The frequency of cyber-attacks on Industrial Automation and Control Systems (IACSs), particularly in critical infrastructure, has shown a significant increase over the past two decades. While existing literature often relies on the Common Vulnerability Scoring System (CVSS) for assessing vulnerabilities, there is a need for a more comprehensive risk management approach that includes a detailed vulnerability index. This study proposes a fresh perspective on “security exposures,” aiming to address the complexities in modeling and quantifying threats alongside identified vulnerabilities, including those with CVE-IDs. Instead of viewing threats and vulnerabilities as separate entities, this paper emphasizes their interconnected nature. By introducing a methodology that goes beyond CVSS scoring, the research seeks to provide a more holistic evaluation of security risks. While recognizing the value of CVSS in determining the technical severity of vulnerabilities, it is important to note that CVSS alone does not adequately capture the overall security risks. To address this limitation, the paper introduces the concept of Vulnerability and Exposure Indices that complement existing frameworks like CVSS. This approach enables a more nuanced assessment of security vulnerabilities and exposures, especially those with higher significance. The effectiveness of this methodology is demonstrated through a case study conducted on a simulated boiling water power plant. By incorporating the proposed Vulnerability and Exposure Indices, the study showcases the enhanced capability in evaluating the impact of security risks beyond what traditional CVSS assessments offer.