Blockchain-based model for tracking compliance with security requirements
Computer Science and Information Systems, Tome 20 (2023) no. 1.

Voir la notice de l'article provenant de la source Computer Science and Information Systems website

The increasing threat landscape in Industrial Control Systems (ICS) brings different risk profiles with comprehensive impacts on society and safety. The complexity of cybersecurity risk assessment increases with a variety of third-party software components that comprise a modern ICS supply chain. A central issue in software supply chain security is the evaluation whether the secure development lifecycle process (SDL) is being methodologically and continuously practiced by all vendors. In this paper, we investigate the possibility of using a decentralized, tamper-proof system that will provide trustworthy visibility of the SDL metrics over a certain period, to any authorized auditing party. Results of the research provide a model for creating a blockchain-based approach that allows inclusion of auditors through a consortium decision while responding to SDL use cases defined by this paper. The resulting blockchain architecture successfully responded to requirements mandated by the security management practice as defined by IEC 62443-4-1 standard.
Keywords: industrial control systems, secure development lifecycle, blockchain
@article{CSIS_2023_20_1_a20,
     author = {Jelena Marjanovi\'c and Nikola Dal\v{c}ekovi\'c and Goran Sladi\'c},
     title = {Blockchain-based model for tracking compliance with security requirements},
     journal = {Computer Science and Information Systems},
     publisher = {mathdoc},
     volume = {20},
     number = {1},
     year = {2023},
     url = {http://geodesic.mathdoc.fr/item/CSIS_2023_20_1_a20/}
}
TY  - JOUR
AU  - Jelena Marjanović
AU  - Nikola Dalčeković
AU  - Goran Sladić
TI  - Blockchain-based model for tracking compliance with security requirements
JO  - Computer Science and Information Systems
PY  - 2023
VL  - 20
IS  - 1
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/CSIS_2023_20_1_a20/
ID  - CSIS_2023_20_1_a20
ER  - 
%0 Journal Article
%A Jelena Marjanović
%A Nikola Dalčeković
%A Goran Sladić
%T Blockchain-based model for tracking compliance with security requirements
%J Computer Science and Information Systems
%D 2023
%V 20
%N 1
%I mathdoc
%U http://geodesic.mathdoc.fr/item/CSIS_2023_20_1_a20/
%F CSIS_2023_20_1_a20
Jelena Marjanović; Nikola Dalčeković; Goran Sladić. Blockchain-based model for tracking compliance with security requirements. Computer Science and Information Systems, Tome 20 (2023) no. 1. http://geodesic.mathdoc.fr/item/CSIS_2023_20_1_a20/