Szczegóły publikacji
Opis bibliograficzny
Approach to sector-specific cybersecurity schemes: key elements and security problem definition / Consuelo Colabuono, Douglas Wiemer, Maria Vittoria Marabello, Domenico Lofù, Marco Pappalardo, Piotr Bogacki, Andrzej Dziech, Jan DERKACZ, Luis Angel Galindo Sanchez, Ewa Konieczna, Maya Bojilova, Giuseppe Chechile, Riccardo Feletto, Marco Dri, Massimo Zamagni, Emanuele Sansebastiano, Grégory Depaix, Cyril Ceresola, Bernard Opic, Massimo Ravenna, Marco Quartullo, Andrea Guarino, Paolo Modica, Raniero Rapone, Massimiliano Tarquini, Stefano Armenia // W: Multimedia Communications, Services and Security : 11th international conference, MCSS 2022 : Kraków, Poland, November 3–4, 2022 : proceedings / eds. Andrzej Dziech, Wim Mees, Marcin Niemiec. — Cham : Springer Nature Switzerland, cop. 2022. — (Communications in Computer and Information Science ; ISSN 1865-0929 ; vol. 1689). — ISBN: 978-3-031-20214-8; e-ISBN: 978-3-031-20215-5. — S. 104–117. — Bibliogr., Abstr. — Publikacja dostępna online od: 2022-10-15. — P. Bogacki, A. Dziech - afiliacja: RHEA Group, Wavre, Belgium
Autorzy (26)
- Colabuono Consuelo Assunta
- Wiemer Douglas
- Marabello Maria Vittoria
- Lofù Domenico
- Pappalardo Marco
- Bogacki Piotr
- Dziech Andrzej
- AGHDerkacz Jan
- Sanchez Luis Angel Galindo
- Konieczna Ewa
- Bojilova Maya
- Chechile Giuseppe
- Feletto Riccardo
- Dri Marco
- Zamagni Massimo
- Sansebastiano Emanuele
- Depaix Gregory
- Ceresola Cyril
- Opic Bernard
- Ravenna Massimo
- Quartullo Marco
- Guarino Andrea
- Modica Paolo
- Rapone Raniero
- Tarquini Massimiliano
- Armenia Stefano
Słowa kluczowe
Dane bibliometryczne
| ID BaDAP | 143191 |
|---|---|
| Data dodania do BaDAP | 2022-10-24 |
| DOI | 10.1007/978-3-031-20215-5_9 |
| Rok publikacji | 2022 |
| Typ publikacji | materiały konferencyjne (aut.) |
| Otwarty dostęp | |
| Wydawca | Springer |
| Czasopismo/seria | Communications in Computer and Information Science |
Abstract
This paper documents the approach to define cybersecurity certification schemes as candidate methods for sector cybersecurity product certification as part of the EU Cybersecurity Certification Framework being prepared by ENISA. Indeed, it is a very recent area of research within the EU landscape. Our work was undertaken within H2020 ECHO project (www.echonetwork.eu) and it is reported in detail in its deliverables. This document is completing the research reported in our previous publication, which had complete references to the existing state of the art about the certification topic in EU. Our work started with the identification of the sector-specific needs to be addressed for specific critical sectors. The mandatory Key Elements of a certification scheme, as described in the EU Cybersecurity Act, have been customized and the sector specific analysis allowed to define a Security Problem Definition baseline to be used to quickly draft a Protection Profile of an asset category of the considered sectors. Security needs have been identified using also the sectoral risk assessment guidelines provided by ENISA for certification purposes. It has also been developed an inter sector risk scenario to highlight the most important security needs to mitigate cross-sector security failures. Finally, Cyber Range technologies have been leveraged for the Conformity Assessment activities of two Maritime and a Healthcare product prototypes, for which the substantial assurance level certification has been simulated for the sake of validation of our approach.