Richard Smith
The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework
Smith, Richard; Janicke, Helge; He, Ying; Ferra, Fenia; Albakri, Adham
Authors
Helge Janicke
Ying He
Fenia Ferra
Adham Albakri
Abstract
Cyber incident response within Industrial Control Systems (ICS) is characterised by high levels of uncertainty and unpredictability and requires a multi-disciplined team that encompasses personnel business operations, Operational Technology (OT), IT, security operations and media engagement to be effective. Such teams require a dynamic decision framework to allow ICS operators to maintain services during the recovery of full operating capability. There is empirical evidence that static incident response playbooks do not provide enough flexibility in their definition to support situations outside of the scope of their initial definition, and that they have been ignored when cyber incidents have occurred. A thematic analysis of semi-structured interviews with ICS incident response professional identified three main areas of concern: communication, information sharing between knowledge areas, and achieving external buy-in. The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework has been developed to integrate Agile techniques into the Cyber Security domain of incident response. AIR4ICS provides a dynamic approach to improve situational awareness, information sharing, collective decision-making and response flexibility within the unique context of ICS. The techniques used in AIR4ICS were initially shaped by interviews with professionals with experience of protecting ICS, structured using the Scrum methodology, and refined through a series of Cyber Incident Response exercises with Incident Response professionals facing-off against specialist ICS Red Teams. AIR4ICS has resulted in a framework that provides a modular approach that can be adapted to fit the working practices, skillsets and priorities of individual organisations. The framework improves communication, promotes information sharing between knowledge areas, and increases external buy-in. Ultimately, AIR4ICS provides a dynamic decision framework that allows Incident Response Teams to manage uncertainty and unpredictability to reduce the time taken to restore normal operations.
Citation
Smith, R., Janicke, H., He, Y., Ferra, F., & Albakri, A. (2021). The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework. Computers and Security, 109, Article 102398. https://doi.org/10.1016/j.cose.2021.102398
Journal Article Type | Article |
---|---|
Acceptance Date | Jul 2, 2021 |
Online Publication Date | Jul 10, 2021 |
Publication Date | Oct 1, 2021 |
Deposit Date | Aug 29, 2021 |
Publicly Available Date | Jul 11, 2022 |
Journal | Computers and Security |
Print ISSN | 0167-4048 |
Electronic ISSN | 0167-4048 |
Publisher | Elsevier |
Peer Reviewed | Peer Reviewed |
Volume | 109 |
Article Number | 102398 |
DOI | https://doi.org/10.1016/j.cose.2021.102398 |
Keywords | Law; General Computer Science |
Public URL | https://nottingham-repository.worktribe.com/output/6136416 |
Publisher URL | https://www.sciencedirect.com/science/article/pii/S0167404821002224?via%3Dihub |
Additional Information | This article is maintained by: Elsevier; Article Title: The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework; Journal Title: Computers & Security; CrossRef DOI link to publisher maintained version: https://doi.org/10.1016/j.cose.2021.102398; Content Type: article; Copyright: © 2021 Elsevier Ltd. All rights reserved. |
Files
The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework
(4.6 Mb)
PDF
Downloadable Citations
About Repository@Nottingham
Administrator e-mail: discovery-access-systems@nottingham.ac.uk
This application uses the following open-source libraries:
SheetJS Community Edition
Apache License Version 2.0 (http://www.apache.org/licenses/)
PDF.js
Apache License Version 2.0 (http://www.apache.org/licenses/)
Font Awesome
SIL OFL 1.1 (http://scripts.sil.org/OFL)
MIT License (http://opensource.org/licenses/mit-license.html)
CC BY 3.0 ( http://creativecommons.org/licenses/by/3.0/)
Powered by Worktribe © 2025
Advanced Search