Papers

Search

Regulating the Cyberworthiness of Operational Technology for Safety

Presenter:

Paper Summary

The cyber domain is increasingly merging with the physical domain through the rapidly growing and widespread adoption of the Internet of Things (IoT) and more substantial Operational Technology (OT), critical to a safe and functional modern society. While the cyber domain brings significant benefits to physical systems, such as enhanced coordination, efficiency, and autonomous capabilities, these benefits can also give rise to substantial hazards to the physical domain. Large scale OT is inherently interconnected and complex, often creating dependencies, responsibilities and risks without the complete awareness of authorities. In part, this occurs because of the insidious evolution of malicious exploitation by cyber-threats and the difficulty with which capability managers ‘patch’ or mitigate such threats after market, when or if they become aware of ‘new’ or ‘exploited’ vulnerabilities. a. This paper initially considers the different types of regulation available for the regulation of OT, as well as several contemporary high-profile case studies involving poor regulation and governance of OT to highlight the difference between cybersecurity, cyber safety, and the cyberworthiness of OT. b. The analysis detailed in this paper provides insights into how maritime, aviation, and nuclear regulators from the United States of America, the European Union, and Australia allow for the broad drive to integrate cyber components into the high-hazard physical systems they regulate. This insight is gained by undertaking a systematic document review and word search analysis of the regulations, codes, standards and guidance documents published or referred to by these regulators to assess the importance that these regulators place on cybersecurity, cyber safety, and cyberworthiness. c. The analysis includes an assessment of the degree to which these regulators incorporate appropriate governance into the cyber safety aspects of their regulations, guidance documents, and regulatory initiatives, such as complex systems governance. This allows for this analysis to be used as a proxy for their consideration of the overall cyberworthiness of the systems under their regulatory control. Through discussion on the outcomes of this novel and significant analysis, including its limitations, potential cyberworthiness-based regulations are proposed for the first time, together with future directions for research into cyberworthiness regulations for the safety of high-hazard OT.