Direkt zum Inhalt

Owner only: item control page
Gnanasekaran, Vahiny ; Fatima, Urooj ; Glas, Magdalena ; Heegaard, Poul Einar

A Model-Based Framework for Developing Security-Safety Incident Response Plans

Gnanasekaran, Vahiny, Fatima, Urooj , Glas, Magdalena and Heegaard, Poul Einar (2025) A Model-Based Framework for Developing Security-Safety Incident Response Plans. International Journal of Information Security 24, p. 229.

Date of publication of this fulltext: 30 Apr 2026 05:27
Article
DOI to cite this document: 10.5283/epub.79371


Abstract

Cyberattacks are increasingly affecting the safe operation of critical infrastructure (e.g., energy, manufacturing) and potentially endangering production, people, equipment, and the environment. A cyber-incident with physical consequences requires personnel responsible for aggregating log information, analyzing root cause (i.e., cybersecurity), and ensuring the production and safe operation of ...

Cyberattacks are increasingly affecting the safe operation of critical infrastructure (e.g., energy, manufacturing) and potentially endangering production, people, equipment, and the environment. A cyber-incident with physical consequences requires personnel responsible for aggregating log information, analyzing root cause (i.e., cybersecurity), and ensuring the production and safe operation of safety-critical systems (i.e., safety) to collaborate. For this, they must understand their own and each other’s roles in the incident response process, as well as when and how to interact with different roles. To address this problem, this paper proposes a framework that utilizes a model-based approach to illustrate the critical roles and their interactions within a security-safety incident response plan. To demonstrate its applicability, the framework was applied in a qualitative study within the Norwegian oil and gas industry, involving two companies. This research sheds light on the relevance of applying a model-based approach to developing security and safety incident response plans for organizations. It investigates the relevance of using two modeling languages: a general-purpose software systems modeling language, the Unified Modeling Language (UML), and an enterprise process workflow modeling language, the Business Process Modeling Notation (BPMN), for visualizing the security-safety incident response plan. The findings indicate that the modeling languages are suitable and relevant for understanding and discussing the collaboration and coordination of different personnel’s roles during security-safety incident response. The distinct diagrams highlight various aspects, including roles, transmitted information, tasks, and the sequence of tasks. Future work should consider how the diagrams can be applied during the training and learning of the incident response plans.



Involved Institutions


Details

Item typeArticle
Journal or Publication TitleInternational Journal of Information Security
Publisher:Springer
Open Access Type:CC-License
Place of Publication:Berlin, Heidelberg
Volume:24
Page Range:p. 229
Date3 November 2025
InstitutionsBusiness, Economics and Information Systems > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Informatics and Data Science > Department Information Systems > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Identification Number
ValueType
10.1007/s10207-025-01147-4DOI
KeywordsModeling language, Incident response, Critical infrastructure, Roles, Cyber security, Safety
Dewey Decimal Classification000 Computer science, information & general works > 004 Computer science
StatusPublished
RefereedYes, this version has been refereed
Created at the University of RegensburgPartially
URN of the UB Regensburgurn:nbn:de:bvb:355-epub-793713
Item ID79371

Export bibliographical data

Owner only: item control page

nach oben