A Multi-level Reference Model and a Dedicated Method for Cyber-Security by Design
Abstract
EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.
Full text
de Kinderen, Sybren; Kaczmarek-Heß, Monika; Hacks, Simon Article — Published Version A Multi-level Reference Model and a Dedicated Method for Cyber-Security by Design Business & Information Systems Engineering Provided in Cooperation with: Springer Nature Suggested Citation: de Kinderen, Sybren; Kaczmarek-Heß, Monika; Hacks, Simon (2024) : A Multi-level Reference Model and a Dedicated Method for Cyber-Security by Design, Business & Information Systems Engineering, ISSN 1867-0202, Springer Fachmedien Wiesbaden GmbH, Wiesbaden, Vol. 67, Iss. 4, pp. 511-530, https://doi.org/10.1007/s12599-024-00899-y This Version is available at: https://hdl.handle.net/10419/330634 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/4.0/
RESEARCH PAPER A Multi-level Reference Model and a Dedicated Method for Cyber-Security by Design On the Example of the Electricity Sector Sybren de Kinderen •Monika Kaczmarek-Heß •Simon Hacks Received: 10 October 2023 / Accepted: 24 May 2024 / Published online: 28 October 2024 ÓThe Author(s) 2024 Abstract The increased reliance of organizations on information technology inherently increases their vulnerability to cyber-security attacks. As a response, a host of cyber-security approaches exists. While useful, these approaches exhibit shortcomings such as an inclination to be fragmented, not accounting for up-to-date organizational data, focusing on singular vulnerabilities only, and being reactive, i.e., focusing on patching up vulnerabilities in current systems. The paper presents and evaluates a modeling method aiming to address those shortcomings and to support security by design with a focus on the electricity sector. The proposed modeling method encompasses a multi-level reference model reconstructing and integrating existing initiatives and supporting top-down and bottom-up analyses. Compared to earlier work, the paper contributes (1) a process model for cyber-security by design, which proactively considers security as a first-class citizen during the design process, (2) a complete coverage of the multi-level model, in terms of three views complementing the introduced process model, (3) an elaborated evaluation, in terms of reporting on an additional design science cycle. Keywords Cyber-security by design Modeling method Security reference framework Security analysis Multilevel modeling 1 Introduction In the context of digital transformation, information technology (IT) has brought about considerable changes in various industries, whether structural organizational changes, value creation, or others (Vial 2019; Kraus et al. 2022). Consider the digital transformation of the electricity sector, which is also in the focus of this paper: digital transformation enables a variety of new business models (Niesten and Alkemade 2016; Paukstadt and Becker 2021), such as smart electric vehicles, where IT can be used to optimize charging times (Niesten and Alkemade 2016; Paukstadt and Becker 2021), or smart decentralized energy sources, where predictive maintenance may be used for example to support offshore wind turbines (Paukstadt and Becker 2021). Nevertheless, digital transformation also inherently comes with a variety of challenges. Among these are (cyber-)security concerns, both for industries in general (Vial 2019) and for the electricity sector in particular (Cozzi et al. 2017, p. 124). Digital transformation especially includes a fuller integration of the different components over the internet, leading to a greater attack surface, i.e., to more vulnerabilities and entry points that attackers can leverage (Mo ¨ller 2023). These weaknesses can devastate the different digitized units, such as organizations, industries, or regions. This had been, for example, demonstrated for the electricity sector by a wellAccepted after 1 revision by Hans-Georg Fill. S. de Kinderen (&) Information Systems Group, Eindhoven University of Technology, Groene Loper 3, 5612 AE Eindhoven, The Netherlands e-mail: [email protected] M. Kaczmarek-Heß Research Group for Information Systems and Enterprise Modeling, University of Duisburg-Essen, Universita ¨tsstraße 9, 45141 Essen, Germany S. Hacks Department of Computer and Systems Sciences, Stockholm University, Borgarfjordsgatan, 164 55 Kista, Sweden 123 Bus Inf Syst Eng 67(4):511–530 (2025) https://doi.org/10.1007/s12599-024-00899-y
orchestrated cyber-security attack on the Ukrainian electricity grid, targeting the IT infrastructure of a regional electricity distribution company, which caused power outages affecting approximately 225,000 households (Case 2016; Stellios et al. 2018). Cyber-security has often been treated as something to be accounted for or added later to existing applications and systems (Wyatt 2017). Recently, it has become clear that to keep up with the increasing frequency and sophistication of attacks on IT infrastructures, in contrast to the traditional security-by-obscurity principles, organizations need to apply a proactive approach (Abraham et al. 2019). Rather than treating cyber-security as an afterthought or a supplementary layer to be added to existing systems, it is increasingly recognized that a holistic, integrated approach is essential. This systemic perspective, often encapsulated in the concept of cyber-security by design, emphasizes the necessity of incorporating cyber-security considerations throughout the entire product lifecycle (Geismann et al. 2018). Such an approach inherently acknowledges that a system’s resilience against threats is significantly enhanced when security is embedded in every part of the system’s architecture rather than being tacked on. This paradigm shift towards viewing security as an integral, inseparable aspect of system design underscores the relevance and superiority of a systemic approach over piecemeal strategies, highlighting that the system is more than the sum of its parts. Despite various initiatives which are focused on evaluating and enhancing cyber-security by design, challenges persist in specific areas. For instance, securing SCADA systems (Cherdantseva et al. 2016) and ensuring cybersecurity within particular domains like smart grids (Darteh et al. 2022) present unique difficulties (Cherdantseva et al. 2016; de Kinderen et al. 2022). First, the approaches tend to be fragmented, and lack comprehensive coverage of life-cycle phases relevant to security by design (Geismann et al. 2018). For one, there is a focus either on top-down security requirements analysis (for example, with the NISTIR 7628) or on analyzing specific vulnerabilities, attacks, and countermeasures, but not on both. Second, the existing approaches focus on singular vulnerabilities of components, not the system which comprises these components. Third, the approaches insufficiently account for up-to-date data on security attacks, and fourthly, they often lack software tool support. To address these challenges and help organizations follow the cyber-security by design principles, we deem conceptual modeling (Mylopoulos 1992) to be a promising instrument, and therefore, we have proposed in our previous work a reference model for cyber-security by design for smart grids (de Kinderen et al. 2022), which combines the NISTIR 7628 (National Institute of Standards and Technology 2010) with a threat modeling language (Katsikeas et al. 2020). The reference model provides static support for end-to-end model-based cyber-security analysis, and as such supports security and domain experts which only have basic knowledge of the others (i.e., security or the domain under study) to design secure systems. Namely, the developed reference model provides support during all phases: starting from the identification of (security) requirements, through the identification of relevant assets, assessment of risk and identification of countermeasures, to, finally, the design of a supporting architecture. Please note that here the term ‘‘system‘‘ represents an entire organization as it comprises a combination of interacting components or applications. Thus, our approach does not address the cyber-security analysis of a single component or application. As the initial reference model itself supported a topdown security analysis (de Kinderen et al. 2022), to support the bottom-up security analysis, such as vulnerability analysis, we complemented the reference model with attack simulations (Hacks et al. 2022). To this aim, we extended the reference model by including the aspects required for the vulnerability analysis and we provided support for simulations and threats analysis based on the extended model. Both previous works focus on tooling (i.e., the reference model (de Kinderen et al. 2022) and the attack simulations (Hacks et al. 2022)). As such, they do not offer guidance on how concrete reference model instances can be created, meaning that methodical support is lacking. Accordingly, in this paper, we tackle the following research question: How can the proposed multi-level reference model be explicitly used to support comprehensive security analyses for cyber-security by design? To address this question, we provide a corresponding process model that guides the use of the multi-level reference model and supporting tools and discuss its application in the electricity sector. In addition, this paper reports on a validation of our modeling method. Our work fits squarely within design science (Hevner et al. 2004) and follows the engineering cycles as proposed by Wieringa (2014). In this paper, we cover a complete engineering cycle which is a continuation of the outcomes of two previous engineering cycles. As such, it can be characterized as follows: (1) Problem identification and treatment design: based on existing threat modeling approaches, we design a process that suits the demands of a multi-level threat model while accounting for the bi-directional top-down and bottom-up security design. For treatment design, we identify requirements based on insights from previous engineering cycles. (2) Treatment implementation: Besides the design of the new process, we have extended the earlier version of the multi-level model 123 512 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025)
to be in line with the requirements. Additionally to the extensions, we organize the multi-level model into viewpoints, each of which accompanies the process model. (3) Treatment validation: we perform a lightweight demonstration of the proposed method including our extended model and the process in interviews with three experts from the electricity sector, cyber-security domain, and modeling domain. This paper targets both researchers and practitioners who are active and/or interested in cyber-security by design and/or the electricity sector. For researchers, we discuss a multi-level reference model and a dedicated method in the context of cyber-security by design, benefiting from an integrated modeling and programming environment, as a possible solution for the existing challenges in the domain. For practitioners, we show how the reference model may be instantiated and used to guide the security analyses from the beginning of a project, and point out the benefits of such a solution, as reported by domain stakeholders. The paper is structured as follows. First, to make the paper self-consistent, in Sect. 2we provide a short overview of the main concepts, approaches, and challenges in the field of cyber-security by design and point out how conceptual modeling can contribute to resolving those challenges. Next, in Sect. 3we present our method’s goals and targeted vision, which is based on our previous research and has been further developed to reflect the identified need for a guiding process. In Sect. 4, we explain our research approach and discuss the role of domain experts. In Sect. 5, we introduce the multi-level reference model on which the method operates, which was originally presented in (de Kinderen et al. 2022) and has been updated to fit the process model, which is newly developed in this work and presented in Sect. 6. We discuss the proposed approach’s utility and position it towards other approaches in Sect. 7. The paper concludes with final remarks and an outlook on future research. 2 Background The background section serves as the bridge between the introduction and the body of the manuscript. It establishes the context for the research by discussing relevant literature and outlining the knowledge gap the research aims to fill. 2.1 Cyber-Security by Design: Concepts, Approaches, and Challenges The origins of ‘‘security by design’’ can be traced back to the 1970 s when the US Defense Science Board Task Force on Computer Security formulated that ‘‘[p]roviding satisfactory security controls in a computer system is a system design problem’’ (Ware 1970). Firstly, this was referred to as ‘‘secure design patterns’’ (Dougherty et al. 2009), but later the term ‘‘secure by design’’ was established (Santos et al. 2017). ‘‘Security by design’’ includes two key terms: a result (i.e., ‘‘security’’) that is realized by concrete actions (i.e., ‘‘design’’) (Bygrave 2022). ‘‘Security’’ refers to the ‘‘absence or limitation of vulnerabilities or threats’’ (Kahn et al. 2011) towards a referent object like privacy or safety of persons, business success, or state sovereignty (Dunn Cavelty 2014). Often, this is boiled down to the triad of Confidentiality, Integrity, and Availability (CIA) (Herrmann and Prido ¨hl 2020). ‘‘Design’’ is an ambiguous term. For instance, consider the way the term is treated in the work of Hartzog (2018). Here, the author refers at one time to the process and the results of technologies, at another time to a system’s functions and its effect on people, and finally to the creation of tools for understanding and acting under current conditions. Given the various definitions and uses of the term ‘‘design’’, see Bygrave (2022), it can be argued that the term connotes an intentional, directed activity. Design involves engineering in the sense that it brings about something (Bygrave 2022). Ensuring security in critical infrastructures is challenging because, as already mentioned, security is classically ensured ex-post. Therefore different ways to enable security by design have been proposed. For instance, Payette et al. (2015) argue that security should be a concern of IT project managers and propose to extend project management activities accordingly. They determine six security characteristics relevant to projects and extend a project maturity model to assess project security. Geismann et al. (2018) take a similar approach and integrate secure software engineering practices into the engineering process of Cyber-Physical Systems (CPS). Security requirements are defined on the system level and tracked to countermeasures. In turn, Liu et al. (2022) take a more formal position and argue that security concerns should already be considered in the mathematical-formal assessment of CPS. Using the term ‘‘secure-by-construction’’, they point to information-theoretic foundations, data-driven approaches, and security for network multi-agents as future directions for such formal assessments. 2.2 Modeling in Support of Security Analysis A wide variety of already established methods support the overarching goal of security by design. Some of them rely on an instrument to help deal with complexity, supporting understanding and enabling communication between involved stakeholders; namely, they apply conceptual modeling. Conceptual modeling may be defined as ‘‘the 123 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025) 513
activity of formally describing some aspects of the physical and social world around us for understanding and communication’’ (Mylopoulos 1992). The application of modeling to support security analyses is deemed promising as: (1) it can promote a shared understanding of, among others, the existing vulnerabilities and possible attack vectors (Jiang et al. 2023; Geismann and Bodden 2020; 2) it has the potential to relate IT issues to enterprise-level use scenarios (Jiang et al. 2023); and (3) conceptual modeling facilitates (semi-)automated reasoning, enabling, among others, simulation. In addition, please note that the application of a modeling language forces one to be concrete and specific, which makes the analysis more valuable. Moreover, various modeling languages may be used together to offer more comprehensive analyses of a system under study. Various conceptual modeling approaches have been proposed to support security analyses, such as risk assessment methods (ENISA 2022) that operate on different abstraction levels. For one, they support analysis of the entire organization as such, on a systems level, and for single software systems. For instance, on an organizational level, FAIR (Freund and Jones 2015) aims to support managers in making better decisions by understanding organizational risk. Therefore, FAIR provides tools for understanding, measuring, and analyzing information risks. The approach is covered by different areas like risk theory, risk calculation, scenario modeling, and communicating risk within the organization. Based on this information, the risk is quantified according to threat actors, vulnerabilities, and incident impact. In contrast, PASTA (Morana and Uceda Ve ´lez 2015) was designed with IT, security, compliance, and risk leaders in mind, supporting them in mitigating risks and reasoning about different threats. Accordingly, it is a riskcentric threat modeling framework. PASTA leads the risk assessor with an iterative, adaptive process focusing on business impact, threat research, and countermeasures. Similarly, TRIKE (Saitta et al. 2005) follows a process that starts with defining the system via a data flow diagram and its elements like actors, resources, intended actions, and rules. Next, threats are identified based on two categories: elevation of privilege or denial of service. Finally, the risk of certain threats is determined according to their impact on business objects and the threat’s probability. A popular and widespread method to assess different threats to a system is STRIDE (Shostack 2014). STRIDE uses data flow diagrams to represent the system and attach different threats that could impact the system. The threats are grouped into six different categories, which give STRIDE its name: Spoofing identity, Tampering with data, Repudiation, Information disclosure, Denial of service, and Elevation of privilege. STRIDE has been further developed into DREAD (Shostack 2008) to better evaluate threats while considering Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability. Therefore, each category has different values assigned and, thus, enables the calculation of an average value representing the overall system’s risk. On the more detailed level of software systems design, the software engineering community relies on model-based security analysis to support a manual security assessment (e.g., CORAS (Lund et al. 2010), secureTROPOS (Mouratidis et al. 2002), and SecDSVL (Almorsy and Grundy 2014)) or automated security assessment. The automated approaches (e.g., UMLsec (Ju ¨rjens 2002,2005), SecureUML (Basin et al. 2006,2011), SECTET (Alam et al. 2007; Hafner et al. 2006), and STS-ml (Paja et al. 2015)) allow to specify a software system’s set of components and their interactions. Security properties enrich this specification, enabling the automated analysis based on formal reasoning, thus allowing statements about the software system’s security. Besides the aforementioned approaches for security analysis, which tend to be general purpose, similar work for SCADA systems and CPS exists, which is sometimes framed in the light of the ISO 31000:2009 risk management process. Our contribution focuses on achieving security by design as a fundamental principle within modern risk management to address potential risks as early as possible rather than treating them as an afterthought. Regarding SCADA systems, Cherdantseva et al. (2016) reviewed 24 different methods to assess the cyber-security of SCADA systems and suggest a categorization scheme for such methods. They identified five challenges for future research, which also guide our work: (1) the methods either focus on a holistic assessment while neglecting SCADA-specific details or on certain parts while falling short of the big picture, (2) most methods concentrate on singular vulnerabilities, not the system itself, (3) data on security attacks on SCADA systems is missing, (4) the presented methods miss a proper validation, and finally, (5) the methods are lacking tool-support. When it comes to CPS, for instance, Tantawy et al. (2020) develop a model-based approach for the risk assessment of CPS and evaluate the approach in a test bed with real-world industrial controllers and communication protocols. The assessment is guided by identifying physical vulnerabilities, modeling the environment, and testing the vulnerabilities found in the test bed. The authors recognize within their work the benefits of automatizing the analysis itself. Finally, Jiang et al. (2023) employ conceptual modeling in general and multi-level modeling in particular for security analysis focusing on the electricity sector. Jiang et al. (2023) aim at specific vulnerabilities, attacks, 123 514 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025)
and failure propagation. This approach is reactive, focusing on vulnerabilities and attacks of existing infrastructure. 3 Vision and Motivating Scenario Our solution is designed for organizations that value security as an inherent part of the design of new solutions, and is demonstrated for organizations active in the smart grid domain, both to ensure their processes’ functionality and protect their customers’ sensitive data. To illustrate our goals and targeted outcomes, consider the following exemplary scenario. A utility company, ACM-e, wishes to digitalize its processes. They have deployed traditional analog meters to their customers, which are supposed to be exchanged with modern smart meters to enable, inter alia, a fully digitalized billing process. Simultaneously, ACM-e is aware that security aspects are important for the new architecture to ensure their processes’ functionality and protect their customers’ sensitive data. Considering the above, the scenario of interest refers to the billing in smart grids, which relate to the capturing and processing of time-based energy consumption data from customers’ smart meters (Brown et al. 2008). The automated data collection enables ACM-e to transform their billing processes and offer time-based rates to their customers. Further, they can remotely initiate or terminate services without sending a technician. Finally, the more detailed available data can ease the optimal planning, design, maintenance, and development of tailored services. Moreover, ACM-e desires to reduce its costs associated with meter readings and increase its billing accuracy and distribution planning. The billing process relies on smart meters, a customer gateway, and a metering data management system, which uses a Home Area Network (HAN) and Wide Area Network (WAN) for communication. As this digitalization enables attackers to penetrate the infrastructure, there is a need to account for cyber-security aspects. Therefore, a project team must be established to address security issues from the very beginning of the project. Although the project members are familiar with the basic security-related concepts and smart grid-specific aspects, they do not consider themselves security experts. Therefore, they decided to use a method based on existing reference models to ensure that security and domainspecific aspects were addressed. Based on this scenario, as well as on the analysis conducted of existing body of knowledge, we identify the following requirements which the method of choice should meet: Requirement 1 Guide throughout the entire life-cycle of the system. Rationale: In line with the core ideas of cyber-security by design, e.g., see (Geismann et al. 2018), the guiding process model should account for the entire life-cycle of the system under design to cover both proactive design steps during early activities such as the identification of requirements, to more reactive design steps, like assessment of the system. Requirement 2 Provide an integrated conceptual coverage of a system’s life-cycle phases. Rationale: As we intend to cover all steps throughout a system’s life-cycle, in line with Geismann and Bodden (2020), it naturally follows that the envisioned modeling method should provide an integrated conceptual coverage for associated domains and organizational perspectives. For instance, for identifying security requirements, concepts such as use case and security requirement are necessary (National Institute of Standards and Technology 2010); on the other hand, for security assessment, concepts such as assets, their associations, threats, and vulnerabilities would need to be accounted for (Hacks et al. 2020). Requirement 3 Accounting for both high-level and specific aspects. Rationale: Different types of analysis require information on different granularity levels (Atkinson and Ku ¨hne 2001). For example, one can conceptualize generic dependencies between the concept of asset and attack, and make these dependencies more specific for concrete threats for a particular asset, such as different threats that might exist for a particular meter. Requirement 4 Support for analysis, documentation, and communication. Rationale: In line with some of the key aims of conceptual modeling (Thalheim 2011), the models created should (1) provide information for the needs of targeted analyses, but also (2) serve as documentation for the performed steps and results achieved (e.g., uncovered vulnerabilities and risks), as well as (3) support communication among involved stakeholders. Regarding the latter, we require domain-specific concepts close to the professional terminology the involved domain stakeholders use. Requirement 5 Accounting for existing up-to-date domain information. Rationale: The approach shall enable security and domain experts to conduct security-related analysis. Therefore, it is important to integrate the model with external data sources that provide operational-level information and up-to-date information on vulnerabilities (Hamlet and Keliiaa 2010; Rosa et al. 2017). 123 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025) 515
Requirement 6 Reflect standards and current practices on cyber-security. Rationale: In order to not reinvent the wheel and to also offer a modeling method that is in line with notions (presumably) familiar to end users (Frank 2014), the conceptual underpinnings of our modeling method shall reflect the state of the art in cyber-security, as reflected in standards and current practices. On the one hand, reflecting on the fulfillment of the requirements by the relevant approaches discussed by Shevchenko et al. (2018) (e.g., not considering LINDDUN as it is privacy focused), and on the other hand also considering the NIST cyber-security framework (National Institute of Standards and Technology 2024), and (Jiang et al. 2023) as additionally relevant approaches, we can see that the methods cope well with achieving conceptual coverage and support the analysis, documentation, and communication (cf. Table 1). Regarding the analysis, the automation support is limited, even if the approaches allow some automation in the form of spreadsheets. Moreover, most approaches struggle to address a high-level assessment of the entire organization while accounting for specific aspects. This is also reflected in the fact that solely the approach of Jiang et al. (2023) accounts for domainspecific aspects. Finally, standards and current practices are of minor importance and are only reflected if the used method is itself a de-facto standard. Due to, on the one hand, the importance of cyber-security and the challenges of cyber-security by design analysis, and on the other hand, a lack of a comprehensive modeling solution to support organizations through different stages of creating secure systems (cf. Sect. 2), we aim to provide organizations with a multi-level modeling method offering the required support. 4 Research Approach As discussed in the introduction, our work fits squarely within design science (Hevner et al. 2004) and follows engineering cycles as defined by Wieringa (2014), cf. Table 2. The targeted modeling method, i.e., the artifact we design, encompasses (1) a multi-level (reference) model (cf. Sect. 5), (2) a corresponding process model guiding the usage of the multi-level model (cf. Sect. 6), as well as (3) supporting tools and mechanisms. In the first engineering cycle, see de Kinderen et al. (2022), we proposed a reference model for cyber-security by design for smart grids, which combines the NISTIR 7628 (National Institute of Standards and Technology 2010) emphasizing security requirements, use cases and assets, with a modeling language for vulnerabilities, attacks, and countermeasures (Katsikeas et al. 2020). The proposed reference model supported top-down security analysis and received positive feedback from domain experts. In the second engineering cycle (Hacks et al. 2022), we (1) extended the reference model with the aspects required for the vulnerability analysis, such as assets’ vulnerabilities or defenses; (2) enabled simulations and threats analysis, based on the extended model; and (3) provided initial support to analyze the business impact of the identified threats. We perform this extension because identifying vulnerabilities through security testing is widely applied to assess and improve the security of systems (Xiong and Lagerstro ¨m2019). Also, by conducting attack simulations one can detect threats and evaluate alternative security designs enabling proactive identification of threats (Ekstedt et al. 2015). In the third engineering cycle we aim to design a process model which is guided by the created reference model. Table 1 Related work fulfillment of requirements National Institute of Standards and Technology (2024) Morana and Uceda Ve ´lez (2015) Saitta et al. (2005) Shostack (2014) Shostack (2008) Jiang et al. (2023) R1 Account for entire life-cycle X X O X R2 Integrated conceptual coverage OXXXXX R3 Accounting for high-level and specific aspects OX R4 Support analysis, documentation, communication XXXXXX R5 Up-to-date, domain information X R6 Standards and current practices XO Legend: X – Requirement fulfilled; O – Requirement partially fulfilled 123 516 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025)
Moreover, we present an adaptation of the reference model based on the received feedback from domain experts. Finally, the three domain experts were asked to evaluate the newly developed process model. In line with the research approach followed, we have ensured the involvement of domain experts at different stages of our work. This involvement of domain stakeholders was aimed to assess the potential benefits of our work. During the first engineering cycle, we employed semi-structured interviews with two experts from the security and electricity sector respectively, and one expert for security in the electricity sector (cf. Table 3, Participants 1-3). During these interviews we gained feedback on the first version of our multi-level reference model as well as on the overall goals and vision of our project. During the third engineering cycle, we engaged with three domain experts to evaluate the created modeling method (cf. Table 3, Participants 4-6). Note that the second engineering cycle did not involve domain experts, as it focused on developing a software tool chain. 5 Multi-level Security By Design Method: Multi-level Reference Model 5.1 Language Architecture and Rationale for Selection Considering the requirements discussed in Sect. 3, it follows that the language architecture used to design the targeted reference model shall (1) allow for the natural modeling of domain hierarchies and allow for expressing both generic and specific knowledge; it should also (2) allow for incorporating domain knowledge (among others, current knowledge about requirements, possible threats, countermeasures, effects, as well as assets) into the reference model. In addition, (3) the language architecture used to create any reference model should also support expressing variability while avoiding redundancy. This means that a reference model should distinguish between those parts of the system that are invariant within the group of intended users, and other parts that may need individual adaptation, see also (de Kinderen and Kaczmarek-Heß Table 2 Performed engineering cycles 1st Engineering cycle 2nd Engineering cycle 3rd Engineering cycle Main outcome A multi-level reference model, support for top-down approach An extended multi-level model, support for bottom-up analysis, tool support A process model guiding usage of the (extended) multi-level model Problem Identification Utilizing conceptual argumentative exploration and confrontation of our vision and goals to the state of the art, we identify a research gap to which our reference model is a response Whereas the provided reference model supports the top-down analysis, the capability to support vulnerability analysis is still missing A process model that suits the demands of a multi-level threat model while accounting for bi-directional top-down and bottom-up security design is missing Treatment design Based on driving goals and an illustrative scenario, we identify a set of requirements that our reference model should fulfill A set of requirements pointing to the required extensions to the multi-level model; based on the related work, we decide to build on the simulation capabilities of a selected attack modeling language, icsLang A set of requirements stemming from insights generated by previous engineering cycles Treatment implementation We provide a first sketch of a multilevel reference model and implement it in a supporting tool We extend the earlier version of the multi-level model in line with the requirements and the selected modeling language, and, to capitalize upon the simulation capabilities of icsLang, we realize a toolchain between (Hacks et al. 2022) The design of the new process model, together with the set of supporting artifacts, an extended version of the multi-level model, in line with the requirements. The process is based on: current processes for security by design expert feedback from the first engineering cycle (especially taking into consideration the IT infrastructure present at an organization, next to the reference model) Treatment validation An evaluation using a confrontation to the requirements, as well as feedback gathered from expert interviews A lightweight evaluation of our extended model and toolchain in terms of a realistic attack scenario to check the applicability and utility of the proposed solution A lightweight demonstration of our extended model and the process by applying them in workshops with three domain experts 123 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025) 517
2021). Moreover, (4) while supporting adaptation (and extensions of a model), compliance and integrity of the system should be ensured. Finally, (5) in order to support different types of (also automated) analysis, the reference model and its underlying language architecture shall support not only a static perspective on the domain at hand, but also a functional one. Considering the above requirements towards the language architecture, for the needs of the modeling method, we develop a reference model using a selected multi-level modeling approach, namely the Flexible Meta Modeling and Execution Language (FMML x ) (Frank 2014). We adopt multi-level modeling (Atkinson and Ku ¨hne 2001)as in opposition to conventional meta-modeling (1) one can define an arbitrary number of classification levels in the same body of a model. Accordingly, one can employ as many classification levels as needed for expressing the domain knowledge at hand (Atkinson and Ku ¨hne 2008), and not only two (M 2 and M 1 ) as in conventional metamodeling. Please note that by employing an arbitrary number of classification levels one may account for both high-level information (e.g., generic types of threats, generic types of assets), as well as more specific ones (typically accounted for on lower classification levels, e.g., a specific threat to a specific asset), see Requirement 3; (2) one can defer instantiation, meaning that one can constrain the instantiation to a model element at a specific classification level (Frank 2014). This is opposed to shallow instantiation for conventional meta-modeling, whereby one can instantiate only to the directly proceeding level; (3) one can relax the strict separation between type and instance (Atkinson and Ku ¨hne 2001), allowing one to populate and use a model with instance-level data, and thus, incorporate relevant information into the model (see Requirements 5 and 6). Although a number of multi-level modeling approaches have been proposed, to the best of our knowledge only the FMML x comes with an integrated modeling and execution engine (Frank 2014), which we need in order to account for both static and functional view. Thus we select the FMML x together with the XModeler to create our multi-level reference model. Table 4provides a summarized comparison between using conventional meta modeling (on the example of UML) and multi-level modeling (on the example of FMML x ) to create a reference model, considering three aspects: possibility to account for generic and specific aspects, a support for variability, as well as support for consistency-preserving adaptation. As can be observed, UML offers several mechanisms which at least partly may address our requirements. Especially, the combined use of Table 3 Background of the six interview participants Participant 1 Participant 2 Participant 3 Participant 4 Participant 5 Participant 6 Job and responsibilities Cyber-security expert; advising, analyzing, project management Engineer for telecommunication; consultancy for and operations of cybersecurity Visiting assistant professor, working on smart infrastructure Senior software architect; managing projects for cyber-security, hosting platforms, and data management in the power domain Senior software engineer, working on cyber security related aspects PhD student with a focus on enterprise modeling Years of job experience and educational background 10 years in a job with a focus on security, studied computer science 5 years experience in cyber-security and power grids, studied electrical engineering 10 years of experience in the electricity sector, studied computer science 7 years of experience in power and working with security before, PhD in software engineering PhD in cyber security, masters in network and systems engineering Masters in Linguistics and Computer and System Sciences with focus on risk analysis Organization character and size EU institution, not for profit, about 950 personnel European Transmission System Operator (TSO), more than 2000 personnel Private university, not for profit, around 250 personnel European Transmission System Operator (TSO), more than 1000 personnel Internet technology organization, more than 150000 employees internationally University, more than 5000 employees Modeling experience Formal ontologies, UML, enterprise architecture modeling UML, BPMN, ARIS Process modeling, enterprise (architecture) modeling, UML UML, DSLs, enterprise architecture modeling Experience with enterprise modeling Experience with enterprise modeling 123 518 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025)
Subsequently, we identify the order in which these attack steps occur. This is so since attack steps often occur in sequence (Hacks et al. 2022), with one attack step (e.g., smart meter intrusion) often taking place before another attack step (e.g., data theft of a smart meter, after its intrusion). Once attack steps have been identified, for each attack step, we identify corresponding countermeasures as they are encoded in the reference model. Note that in the reference model, we identify attack steps, their relations, and countermeasures per abstraction level in the multi-level model (as expressed in the micro process in Fig. 8). Furthermore, we proceed with said identification in a top-down manner. This means that we start with identifying attack steps for assets residing at higher abstraction levels (for example, a smart meter) and proceed to identify potential attack steps for assets at lower levels of abstraction (e.g., SM 230 as a particular smart meter, cf. Figure 7). Please note that any additional attack steps identified while moving down the abstraction hierarchy are added by monotonic extension, in the sense that attack steps for more specific assets do not modify or replace attack steps for assets residing on a higher level of abstraction. After analyzing the existing multi-level model, our method offers the possibility for a simulation of attack steps. The basic idea of this simulation is to employ Fig. 7 The systems design and analysis view: an excerpt Fig. 8 The security analysis micro process 123 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025) 525
multiple simulation runs to identify key vulnerabilities along a path of attack steps to support the prioritization of countermeasures. A detailed explanation of said simulation capabilities can be found in Katsikeas et al. (2020). Finally, we can prioritize countermeasures. This prioritization can happen according to (1) the security requirements identified in Step 1, (2) the location of the attack step in the overall sequence of attack steps so identified, and (3) the results of the simulation of attack steps. The output of this step is a set of prioritized countermeasures, as they are relevant to attack steps for particular assets. EXAMPLE: From our security analysis view (Fig. 7), we firstly find that, for the combination of the assets Communication Network, Smart Meter, and Metering Data Management System (together forming a direct communication architecture, cf. (Shokry et al. 2022, p. 361)), Impersonation can be performed as an attack step. This attack step exploits the bidirectional communication vulnerability in which an attacker can impersonate the metering data management system to gain access to the smart meter (Shokry et al. 2022, p. 361). Once gaining access to the Smart Meter through Impersonation, the attacker can perform the next attack step to instigate a remote shutdown of the Smart Meter. To counter the two mentioned attack steps ACMe can employ the following countermeasures. Firstly, conforming to the security analysis view, authentication can be employed as a countermeasure to safeguard the identity of the metering data management system and thus counter the attack step of impersonation. Secondly, one can disable the remote shutdown of the smart meter as a countermeasure so that in case of intrusion, the attacker’s options are limited. Moving down the abstraction hierarchy, we also discover more specific attack steps relevant to more specific assets. Specifically, for a wireless area network being a specific type of communication network, a potential jamming attack can become relevant (Aravinthan et al. 2011; Shokry et al. 2022). With jamming, an attacker disrupts the wireless communication by sending out signals on a shared medium (Aravinthan et al. 2011), thus disrupting communication needed for, e.g., monitoring and estimation functions (Zhang et al. 2019). While a jamming attack is generally difficult to defend against, a potential countermeasure encoded in our reference model, as proposed by Aravinthan et al. (2011), is to move through a list of predefined channels to prevent an attacker from attacking jamming one particular signal. Finally, we prioritize countermeasures and select authentication based upon (1) the security requirement identified during the step security requirements analysis. Recall that, according to NISTIR Interface 13, integrity and confidentiality were prioritized over availability. This fits well with authentication since the needed extra computational capability might run counter to availability; authentication does fit nicely to achieving the prioritized integrity and confidentiality requirements; (2) the location of the attack steps. Here again, authentication seems to fit well since it aims to make smart meter access more difficult, thus preventing attack steps that can be carried out once smart meter access has been gained. 7 Evaluation and Discussion We now reflect on the extent to which our modeling method fulfills the requirements discussed in Sect. 3,as well as its utility, as pointed out by the domain experts. 7.1 Requirements Fulfillment In line with the cyber-security by design philosophy, our method provides comprehensive coverage of a system’s design, both proactively during early stages, like security requirements analysis, and in later phases, such as security analysis, where the focus is on attacks and countermeasures for given assets. This comprehensive coverage is catered for in terms of the stages covered (Requirement 1) and the used concepts (Requirement 2). Additionally, by adopting FMML x as a multi-level modeling approach, we enable the expression of information at a high level of abstraction and the expression of specific information (Requirement 3). The flexibility in selecting a level of abstraction, combined with the domain-specific nature of the (security, electricity sector) concepts in our reference model, also allows the use of terminology familiar to end users, thus supporting communication and documentation (Requirement 4). Nevertheless, as visualization and model management are still known research issues for multi-level modeling in general and for FMML x specifically, the active use of our reference model for documentation and communication purposes is still a point for further research. Additionally, by benefiting from the relaxed type-instance dichotomy of FMML x (again, see Sect. 5) we can keep the model up to date concerning domain information (Requirement 5). Finally, by adopting well-established concepts from NISTIR 7628, powerLang, and from modeling approaches for cyber security by design (Geismann and Bodden 2020), our modeling method is based on stateof-the-art standards and practices in (cyber-) security by design (Requirement 6). 123 526 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025)
7.2 Feedback from Domain Experts and Expected Utility of the Method From the conducted interviews (cf. Sect. 4), we mainly gained feedback on the utility of the designed artifacts, the coverage, and understandability, and also observed a need for a clear return-on-modeling-effort (Guizzardi and Proper 2022). Regarding utility, the reference model is perceived as a useful knowledge base for non-domain experts. For example, Participant 3 (see Table 3) mentions how the reference model could help identify security concerns for a currently running project on developing a platform for sourcing inverters for solar panels. In fact, while the electricity sector has the expertise to develop this platform, the related security concerns are less well understood. However, the utility must provide concrete and up-to-date coverage of assets, threats, and their mitigation. When it comes to the utility of our method’s basis in standards, the participants mentioned using the ISO 2700X series (Participant 1) and NISTIR 7628 (Participant 4) as typical sources of information. Therefore, they positively assessed the coverage of the reference model. Nevertheless, other standards such as MODBUS and IEC 61850 were also mentioned (by Participant 3) and recommended for inclusion in the reference model. The participants also mentioned the need to adjust the standards to local needs, supported by the reference model. Finally, Participant 5 remarked that choosing an appropriate level of abstraction is a pertinent issue in the security domain. Therefore this participant appreciated our modeling method’s inherent flexibility, allowing one to choose an abstraction level as needed. Nevertheless, it was recommended that the modeling efforts should start from the abstract view of an organization, created by people with a good overview of the system, and then let stakeholders complete the details with detailed knowledge about single parts of the system. In terms of understandability, participants indicated that they could understand the concepts within the multi-level model after explanation, even those concepts that were not from their domain (see the participant backgrounds Table 3). However, the idea of multi-level modeling needed further explanation to the participants, as it is not easy to grasp initially, even for those familiar with conceptual modeling. Participant 3 initially interpreted the different levels in a multi-level model as reflecting their importance. For example, for Participant 3, a requirement would be more important than a use case because a requirement resides on level L3, whereas a use case resides on level L2. Only after explanation did the domain expert understand that the levels pertain to the organization of classification levels. Additionally, Participant 5 remarked on the complexity of the multi level hierarchies. He pointed out that a filtering mechanism to hide unnecessary information would be and add to the understandability of our multi-level models. Finally, Participant 4 pointed out a potential language barrier in the inherent reliance of our modeling method on English, since on a day-to-day basis, potential users of the method may be more likely to use their native language. Regarding the process model, the provided steps were overall assessed as reasonable and logical by the participants of the third design science cycle, in particular by Participants 4 and 6. The feedback of domain stakeholders points to the need for a clear Return-on-Modeling-Effort (RoME). Such a RoME involves, on the one hand, that the application of the method should provide non-trivial information to end users so that the invested effort (e.g., the effort invested in creating models and using them in the analysis process) is perceived as justified by the users. On the other hand, for a clear RoME, additional mechanisms and incentives are needed. Regarding the latter, we gained feedback from the third engineering cycle interview mainly on four aspects, discussed subsequently. (1) Automated model creation: Due to the considerable complexity of the systems, it is vital to support modelers in their work where possible. This includes the automated generation of the model based on existing information or automatized scans of the infrastructure. However, it was pointed out that this might be challenging in cyber-physical environments as automatized scans could crash those. (2) Accounting for changing security requirements: The threat landscape is continuously changing. Therefore, the multi-level model must address the latest vulnerabilities by, e.g., including up-to-date databases like the National Vulnerability Database (NVD). Moreover, it was stressed that the derived recommendations to address these vulnerabilities must go beyond the obvious, such as keeping the latest patch level. (3) Multi-level model management: The multi-level model covers different levels of abstraction and domains in the organization. None of this information is available from a single person in an organization. Accordingly, it is necessary to provide different views to stakeholders in both capacities: to analyze and maintain the model. (4) Incentives for modelers: Not all model creation aspects can be automated. Therefore, it is important to continuously motivate the related stakeholders to share their knowledge of the multi-level model. This could be achieved by easing the provision of the related information and creating directly perceived added value to the stakeholders. Thus, to ensure the practical adoption of the modeling method, we run into the classical issues of (1) modeling for the masses (Sandkuhl et al. 2018), which reflects on establishing a bridge between ‘‘model like’’ artifacts like 123 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025) 527
spreadsheets which contain valuable domain knowledge, and a conceptual (enterprise) model, as well as (2) the Return on Modeling Effort (Guizzardi and Proper 2022), the highlight of which is that the effort put into domain modeling should be met by benefits that one can reap from it. 7.3 Positioning Towards Related Work As already mentioned in Sect. 3, no comprehensive solution exists that addresses all requirements. Closest to our method comes the work of Jiang et al. (2023). Similar to our work, Jiang et al. (2023) employ conceptual modeling in general and multi-level modeling in particular for security analysis focusing on the electricity sector. Besides these similarities, substantial differences exist. First, there exist differences regarding the main goals and scenarios supported. Especially, Jiang et al. (2023) aim at specific vulnerabilities, attacks, and failure propagation. Their model is thus reactive, focusing on vulnerabilities and attacks in existing infrastructure. In contrast, our modeling method targets a security-by-design approach and thus is proactive by explicitly considering security as part of the design process. The second difference lies in the ability to keep the model up to date with data from the running organization. FMML x , the language on which our reference model is built, inherently can keep a model synchronized with data from, e.g., the running organization. To the best of our knowledge, while Jiang et al. (2023) certainly benefit from tool support (through ConceptBase), compared to our approach, there is a less natural capability to keep model and data in synchronization; Third, the level of provided guidance differs. Jiang et al. (2023) introduce three artifacts: a general taxonomy for systems modeling (both information technology and operational technology, the latter touching on the cyber-physical systems side, cf. Jiang et al. (2023)), an artifact for teasing out functional dependence, and an instantiation of the two mentioned artifacts for the power domain. However, user guidance for the presented artifacts is missing. Our modeling method offers a multi-level model process, accompanied by typical method elements such as relevant stakeholders, inputs, outputs, and more (see Table 6). 8 Conclusions In this paper, we present a modeling method for cybersecurity by design. As a continuation of earlier work, we particularly focused on the procedural guidance of our modeling method, as well as its comprehensive presentation in terms of three views that complement the procedural guidance. In addition to an extra round of validation (the third design science cycle), we also conducted a comprehensive validation of the method. For future work, we intend to, first, address the usability of our multi-level model. As stated in Sect. 7, while conceptually appealing, we still need to address the lack of visualization and model management inherent in the use of multi-level modeling. As a first step, the use of viewpoints with relevant information tailored to specific roles would be promising. Second, in terms of validation, a further evaluation in a real-life setting may be useful to learn from. In line with the further evaluation, third, we also intend to make simulation capabilities an inherent part of our modeling method. In earlier work, we have already achieved encouraging results by relating the multi-level reference models to attack graph-based reasoning, but due to scoping and space constraints we could not fully utilize these results for the present paper. Open Access This article is licensed under a Creative Commons Attribution 4.0 International License, which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons. org/licenses/by/4.0/. References Abraham C, Chatterjee D, Sims RR (2019) Muddling through cybersecurity: insights from the US healthcare industry. Bus Horiz 62(4):539–548 Alam M, Breu R, Hafner M (2007) Model-driven security engineering for trust management in SECTET. J Softw 2(1):47–59 Almorsy M, Grundy J (2014) Secdsvl: a domain-specific visual language to support enterprise security modelling. In: 23rd Australian software engineering conference (ASWEC), pp 152–161 Aravinthan V, Namboodiri V, Sunku S, Jewell W (2011) Wireless AMI application and security for controlled home area networks. In: 2011 IEEE power and energy society general meeting. IEEE, pp 1–8 Atkinson C, Ku ¨hne T (2001) The essence of multilevel metamodeling. In: Proceedings of the 4th international conference on the unified modeling language, modeling languages, concepts, and tools. Springer, Heidelberg, pp 19–33 Atkinson C, Ku ¨hne T (2008) Reducing accidental complexity in domain models. SoSyM 7(3):345–359 Basin D, Doser J, Lodderstedt T (2006) Model driven security: from UML models to access control infrastructures. ACM Transact Softw Eng Method (TOSEM) 15(1):39–91 Basin D, Clavel M, Egea M (2011) A decade of model-driven security. In: Proceedings of the 16th ACM symposium on Access control models and technologies, pp 1–10 123 528 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025)
Brown B, Singletary B, Willke B, Bennett C, Highfill D, Houseman D, Cleveland F, Lipson H, Ivers J, Gooding J et al (2008) AMI system security requirements. AMI-SEC TF Bygrave LA (2022) Security by design: aspirations and realities in a regulatory context. Oslo Law Rev 3:126–177 Case DU (2016) Analysis of the cyber attack on the Ukrainian power grid. In: Electricity information sharing and analysis center (EISAC), vol 388, pp 1–29 Chan ACF, Zhou J (2013) On smart grid cybersecurity standardization: issues of designing with NISTIR 7628. IEEE Commun Mag 51(1):58–65 Cherdantseva Y, Burnap P, Blyth A, Eden P, Jones K, Soulsby H, Stoddart K (2016) A review of cyber security risk assessment methods for SCADA systems. Comput Secur 56:1–27. https:// doi.org/10.1016/j.cose.2015.09.009 Cozzi L, Turk D, Abergel T, Bartos J, Bellevrat E, Bennett S, Berly T, Bouckaert S, Dulac J, Alvarez CF et al (2017) Digitalization and Energy. OECD Darteh OF, Liu Q, Liu X, Bah I, Nakoty FM, Acakpovi A (2022) Emerging simulation frameworks for analyzing smart grid cyberattack: a literature review. In: 2022 IEEE Intl conf on dependable, autonomic and secure computing, intl conf on pervasive intelligence and computing, intl conf on cloud and big data computing, intl conf on cyber science and technology congress (DASC/PiCom/CBDCom/CyberSciTech), pp 1–7. https://doi.org/10.1109/DASC/PiCom/CBDCom/Cy55231.2022. 9927892 de Kinderen S, Kaczmarek-Heß M (2021) Making a case for multilevel reference modeling – a comparison of conventional and multi-level language architectures for reference modeling challenges. In: Wirtschaftsinformatik 2021, aisnet de Kinderen S, Kaczmarek-Heß M, Hacks S (2022) Towards cybersecurity by design: a multi-level reference model for requirements-driven smart grid cybersecurity. In: 30th European conference on information systems, ECIS 2022, Timisoara Dougherty C, Sayre K, Seacord RC, Svoboda D, Togashi K (2009) Secure design patterns. Carnergie-Mellon University Pittsburgh PA Software Engineering Institute, Technical report Dunn Cavelty M (2014) Breaking the cyber-security dilemma: aligning security needs and removing vulnerabilities. Sci Eng Ethic 20:701–715 Ekstedt M, Johnson P, Lagerstro ¨m R, Gorton D, Nydre ´n J, Shahzad K (2015) securiCAD by foreseeti: a CAD tool for enterprise cyber security management. In: Enterprise distributed object computing workshop. IEEE, pp 152–155 ENISA (2022) Compendium of risk management frameworks with potential interoperability. Technical report, European Union Agency for Cybersecurity Frank U (2014) Multilevel modeling—toward a new paradigm of conceptual modeling and information systems design. Bus Inf Syst Eng 6(6):319–337 Frank U (2018) The flexible multi-level modelling and execution language (FMMLx). version 2.0: Analysis of requirements and technical terminology. Technical Report 66, ICB-Research Report Freund J, Jones J (2015) Measuring and managing information risk. Butterworth-Heinemann, Waltham. https://doi.org/10.1016/ C2013-0-09966-5 Geismann J, Bodden E (2020) A systematic literature review of model-driven security engineering for cyber-physical systems. J Syst Softw 169:110697. https://doi.org/10.1016/j.jss.2020. 110697 Geismann J, Gerking C, Bodden E (2018) Towards ensuring security by design in cyber-physical systems engineering processes. In: Proceedings of the 2018 international conference on software and system process, pp 123–127 Gottschalk M, Uslar M, Delfs C (2017) The use case and smart grid architecture model approach: the IEC 62559–2 use case template and the SGAM applied in various domains, 1st edn. Springer, Berlin Guizzardi G, Proper HA (2022) On understanding the value of domain modeling. EMISA Hacks S, Katsikeas S, Ling E, Lagerstro ¨m R, Ekstedt M (2020) powerLang: a probabilistic attack simulation language for the power domain. Energy Inform 3:1–17 Hacks S, Kaczmarek-Heß M, de Kinderen S, To ¨pel D (2022) A multilevel cyber-security reference model in support of vulnerability analysis. In: Almeida JPA, Karastoyanova D, Guizzardi G, Montali M, Maggi FM, Fonseca CM (eds) Enterprise design, operations, and computing. Springer, Cham, pp 19–35 Hafner M, Breu R, Agreiter B, Nowak A (2006) SECTET: an extensible framework for the realization of secure inter-organizational workflows. Internet Res 16(5):491–506 Hamlet JR, Keliiaa CM (2010) Assessment of current cybersecurity practices in the public domain: cyber indications and warnings domain. Technical report. https://doi.org/10.2172/992337, https://www.osti.gov/biblio/992337. Accessed 29 July 2024 Hartzog W (2018) Privacy’s blueprint: the battle to control the design of new technologies. Harvard University Press, Cambridge Herrmann D, Prido ¨hl H (2020) Basic concepts and models of cybersecurity. Springer, Cham, pp 11–44. https://doi.org/10. 1007/978-3-030-29053-5_2 Hevner AR, March ST, Park J et al (2004) Design science in information systems research. MIS Q 28(1):75–105 Jiang Y, Jeusfeld MA, Ding J, Sandahl E (2023) Model-based cybersecurity analysis: extending enterprise modeling to critical infrastructure cybersecurity. Bus Inf Syst Eng 1–34 Johnson P, Lagerstro ¨m R, Ekstedt M (2018) A meta language for threat modeling and attack simulations. In: Proceedings of the 13th international conference on availability, reliability and security, pp 1–8 Ju ¨rjens J (2002) UMLsec: extending UML for secure systems development. In: Je ´ze ´quel J, Hußmann H, Cook S (eds) UML 2002-the unified modeling language, 5th international conference, Dresden, Germany, 2002, proceedings, Springer, Heidelberg, LNCS, vol 2460, pp 412–425 Ju ¨rjens J (2005) Secure systems development with UML. Springer, Heidelberg Kahn RE, McConnell M, Nye JS, Schwartz P, Daly NJ, Fick N, Finnemore M, Fontaine R, Geer DE, Gross DA, Healey J, Lewis JA, Lucarelli ME, Mahnken TG, McGraw G, Miksad RH, Rattray GJ, Rogers W, Schroeder CM (2011) America’s cyber future: security and prosperity in the information age. Technical report, Center for a New American Security. http://www.jstor. org/stable/resrep06319.7. Accessed 24 May 2023 Katsikeas S, Hacks S, Johnson P, Ekstedt M, Lagerstro ¨mR, Jacobsson J, Wa ¨llstedt M, Eliasson P (2020) An attack simulation language for the IT domain. In: Eades H III, Gadyatskaya O (eds) GraMSec. Springer, Heidelberg, pp 67–86 Kraus S, Durst S, Ferreira JJ, Veiga P, Kailer N, Weinmann A (2022) Digital transformation in business and management research: an overview of the current status quo. Int J Inf Manag 63:102466. https://doi.org/10.1016/j.ijinfomgt.2021.102466 Liu S, Trivedi A, Yin X, Zamani M (2022) Secure-by-construction synthesis of cyber-physical systems. Ann Rev Control 53:30–50. https://doi.org/10.1016/j.arcontrol.2022.03.004 Lund MS, Solhaug B, Stølen K (2010) Model-driven risk analysis: the CORAS approach. Springer, Heidelberg Mo ¨ller DPF (2023) Cybersecurity in digital transformation. Springer, Cham, pp 1–70. https://doi.org/10.1007/978-3-031-26845-8_1 123 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025) 529
Morana MM, Uceda Ve ´lez T (2015) Risk centric threat modeling: process for attack simulation and threat analysis. Wiley, Hoboken Mouratidis H, Giorgini P, Manson G, Philp I et al (2002) A natural extension of tropos methodology for modelling security. In: Proceedings agent oriented methodologies workshop, annual ACM conference on object oriented programming, systems, languages (OOPSLA), Seattle Mylopoulos J (1992) Conceptual modelling and Telos. Conceptual modelling, databases, and CASE: an integrated view of information system development. Wiley, Hoboken, pp 49–68 National Institute of Standards and Technology (2010) NISTIR 7628-guidelines for smart grid cyber security vol. 1-3. Technical Report NISTIR 7628, National Institute of Standards and Technology (NIST), Gaithersburg, MD, USA. https://nvlpubs. nist.gov/nistpubs/ir/2010/NIST.IR.7628.pdf. Accessed 29 July 2024 National Institute of Standards and Technology (2024) The NIST cybersecurity framework 2.0 Niesten E, Alkemade F (2016) How is value created and captured in smart grids? a review of the literature and an analysis of pilot projects. Renew Sustain Energy Rev 53:629–638 Paja E, Dalpiaz F, Giorgini P (2015) Modelling and reasoning about security requirements in socio-technical systems. Data Knowl Eng 98:123–143 Paukstadt U, Becker J (2021) Uncovering the business value of the internet of things in the energy domain—a review of smart energy business models. Electron Market 31:51–66 Payette J, Anegbe E, Caceres E, Muegge S (2015) Secure by design: cybersecurity extensions to project management maturity models for critical infrastructure projects. Technol Innov Manag Rev 5:26–34 Rosa F, Bonacin R, Jino M (2017) The security assessment domain: a survey of taxonomies and ontologies. ArXiv. https://doi.org/10. 13140/RG.2.2.12437.73441 Saitta P, Larcom B, Eddington M (2005) Trike v1 methodology document. https://www.octotrike.org/papers/Trike_v1_Methodol ogy_Document-draft.pdf. Accessed 09 Oct 2023 Sandkuhl K, Fill HG, Hoppenbrouwers S, Krogstie J, Matthes F, Opdahl A, Schwabe G, Uludag O ¨, Winter R (2018) From expert discipline to common practice: a vision and research agenda for extending the reach of enterprise modeling. Bus Inf Syst Eng 60:69–80 Santos JC, Tarrit K, Mirakhorli M (2017) A catalog of security architecture weaknesses. In: 2017 IEEE international conference on software architecture workshops (ICSAW). IEEE, pp 220–223 SGAM (2012) Smart grid reference architecture. Technical report, CEN-CENELEC-ETSI Smart Grid Coordination Group. https:// www.cencenelec.eu/media/CEN-CENELEC/AreasOfWork/ CEN-CENELEC_Topics/Smart%20Grids%20and%20Meters/ Smart%20Grids/reference_architecture_smartgrids.pdf. Accessed 09 Oct 2023 Shevchenko N, Chick TA, O’Riordan P, Scanlon TP, Woody C (2018) Threat modeling: a summary of available methods. Carnegie Mellon University Software Engineering Institute Pittsburgh, Technical report Shokry M, Awad AI, Abd-Ellah MK, Khalaf AA (2022) Systematic survey of advanced metering infrastructure security: vulnerabilities, attacks, countermeasures, and future vision. Futur Gen Comput Syst 136:358–377. https://doi.org/10.1016/j.future.2022. 06.013 Shostack A (2008) Experiences threat modeling at Microsoft. Technical report, Microsoft Shostack A (2014) Threat modeling: designing for security. Wiley, Hoboken Stellios I, Kotzanikolaou P, Psarakis M, Alcaraz C, Lopez J (2018) A survey of IoT-enabled cyberattacks: assessing attack paths to critical infrastructures and services. IEEE Commun Surv Tutor 20(4):3453–3495 Strom BE, Applebaum A, Miller DP, Nickels KC, Pennington AG, Thomas CB (2018) Mitre ATT &CK: design and philosophy. Technical report, The MITRE Corporation Tantawy A, Abdelwahed S, Erradi A, Shaban K (2020) Model-based risk assessment for cyber physical systems security. Comput Secur 96:101864. https://doi.org/10.1016/j.cose.2020.101864 Thalheim B (2011) The theory of conceptual models, the theory of conceptual modelling and foundations of conceptual modelling. Handbook of conceptual modeling: theory, practice, and research challenges. Springer, Heidelberg, pp 543–577 Vial G (2019) Understanding digital transformation: a review and a research agenda. J Strateg Inf Syst 28(2):118–144. https://doi. org/10.1016/j.jsis.2019.01.003 Ware W (1970) Security controls for computer systems: report of defense science board task force on computer security. Technical report, Rand Corporation. https://www.rand.org/pubs/reports/ R609-1.html#ix-research-needed. Accessed 09 Oct 2023 Wieringa RJ (2014) Design science methodology for information systems and software engineering. Springer, Heidelberg Wyatt M (2017) Cybersecurity systems: acquisition. Development, and maintenance, vol 23. Wiley, Hoboken, pp 335–346. https:// doi.org/10.1002/9781119309741.ch23 Xiong W, Lagerstro ¨m R (2019) Threat modeling—a systematic literature review. Comput Secur 84:53–69 Zhang T, Ji X, Zhuang Z, Xu W (2019) JamCatcher: a mobile jammer localization scheme for advanced metering infrastructure in smart grid. Sens 19(4):909 123 530 S. de Kinderen et al.: A Multi-Level Reference Model..., Bus Inf Syst Eng 67(4):511–530 (2025)