Author:
Christine Izuakor
Affiliation:
University of Colorado at Colorado Springs, United States
Keyword(s):
Security, Cyber, Safety, Risk Management, Risk Assessment, Impact, Confidentiality, Integrity, Availability, Aviation.
Abstract:
To date, cyber security risk management has focused on preservation of information security through protection of confidentiality, integrity, and availability (CIA). The growing use of cyber technology in safety intensive organizations has posed a challenge for those trying to understand the impacts cyber security risks have on safety. This knowledge gap slows progress towards InfoSec maturity and puts organizations and stakeholders at greater risk. For example, e-enabled aircraft now rely heavily on cyber resources, yet cyber security analysis in aviation usually focuses on CIA of information to prevent economic loss. What happens when a malicious attacker successfully exploits cyber aircraft vulnerabilities? This can potentially downgrade critical functions and result in injury or loss of life. To better understand the impacts of cyber risk on safety, the CIA information security triad should expand beyond its current focus to also consider safety.