{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,19]],"date-time":"2026-03-19T21:34:26Z","timestamp":1773956066912,"version":"3.50.1"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"name":"Knowledge Economy Skills Scholarships (KESS2)\u2014a major Pan Wales Operation by European Social Funds (ESF) through the Welsh Government"},{"name":"Thales Ltd., U.K"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/access.2023.3263671","type":"journal-article","created":{"date-parts":[[2023,3,31]],"date-time":"2023-03-31T17:49:10Z","timestamp":1680284950000},"page":"37229-37242","source":"Crossref","is-referenced-by-count":5,"title":["Extended Dependency Modeling Technique for Cyber Risk Identification in ICS"],"prefix":"10.1109","volume":"11","author":[{"given":"Ayodeji O.","family":"Rotibi","sequence":"first","affiliation":[{"name":"School of Computer Science, Cardiff University, Cardiff, U.K"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Neetesh","family":"Saxena","sequence":"additional","affiliation":[{"name":"School of Computer Science, Cardiff University, Cardiff, U.K"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0396-633X","authenticated-orcid":false,"given":"Pete","family":"Burnap","sequence":"additional","affiliation":[{"name":"School of Computer Science, Cardiff University, Cardiff, U.K"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alex","family":"Tarter","sequence":"additional","affiliation":[{"name":"Thales Ltd., Berkshire, U.K"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.108"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.3390\/app12104880"},{"key":"ref15","first-page":"73","article-title":"Evaluating industrial control system (ICS) security vulnerability through functional dependency analysis","volume":"25","author":"ani","year":"2018","journal-title":"Journal of Applied Computer Science"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CRISIS.2009.5411969"},{"key":"ref53","author":"filkins","year":"2019","journal-title":"Sans 2019 state of ot\/ics cybersecurity survey"},{"key":"ref52","author":"bodeau","year":"2015","journal-title":"Cyber Resiliency Engineering Aid &#x2013; The Updated Cyber Resiliency Engineering Framework and Guidance on Applying Cyber Resiliency Techniques"},{"key":"ref11","article-title":"Open group standard dependency modelling (O-DM)","author":"slater","year":"2016"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.3233\/JIFS-201126"},{"key":"ref54","year":"2016","journal-title":"Dr Harper&#x2019;s Classroom Statistical Bayesian Analysis With Excel"},{"key":"ref17","article-title":"The risk-to-mission assessment process (RiskMAP): A sensitivity analysis and an extension to treat confidentiality issues","author":"watters","year":"2009"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-022-00608-4"},{"key":"ref19","year":"2017","journal-title":"Crown Jewels Analysis"},{"key":"ref18","first-page":"1","article-title":"Using an enterprise architecture for IT risk management","author":"innerhofer-oberperfler","year":"2006","journal-title":"Proc ISSSA"},{"key":"ref51","year":"2021","journal-title":"ICS Cybersecurity Year in Review 2020"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1111\/risa.12230"},{"key":"ref46","author":"slater","year":"2016","journal-title":"A dependency modelling manual"},{"key":"ref45","first-page":"65","article-title":"System-theoretic process analysis for security (STPA-SEC): Cyber security and STPA","author":"young","year":"2017","journal-title":"Proc STAMP Conf"},{"key":"ref48","author":"ankan","year":"2015","journal-title":"Mastering Probabilistic Graphical Models Using Python"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2015.09.009"},{"key":"ref42","first-page":"3","author":"ingoldsby","year":"2010","journal-title":"Attack Tree-based Threat Risk Analysis"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICSMC.1995.537904"},{"key":"ref44","year":"2020","journal-title":"How to be Prepared for Cyber Attacks"},{"key":"ref43","author":"carlson","year":"2021","journal-title":"Using Bow Tie Risk Modelling for Industrial Cybersecurity"},{"key":"ref49","author":"stone","year":"0","journal-title":"Bayes&#x2019; Rule A Tutorial Introduction to Bayesian Analysis"},{"key":"ref8","year":"2017","journal-title":"Risk Management Guidance"},{"key":"ref7","year":"2021","journal-title":"The Role of Cybersecurity in Enterprise Risk Management (ERM)"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1155\/2016\/4147251"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICGS3.2019.8688327"},{"key":"ref3","author":"ginter","year":"2017","journal-title":"The top 20 cyberattacks on industrial control systems"},{"key":"ref6","author":"constantin","year":"2020","journal-title":"Solarwinds attack explained And why it was so hardto detect"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2021.100464"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.ress.2009.02.001"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/HICSS.2006.405"},{"key":"ref34","year":"2020","journal-title":"Data Security"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2010.05.069"},{"key":"ref36","volume":"2009","author":"sherwood","year":"1995","journal-title":"Enterprise Security Architecture"},{"key":"ref31","author":"lee","year":"2016","journal-title":"Analysis of the Cyber Attack on the Ukrainian Power Grid"},{"key":"ref30","author":"giles","year":"2019","journal-title":"Triton is the world's most murderous malware and it's spreading"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/2556938"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14236\/ewic\/ICSCSR2013.3"},{"key":"ref2","author":"mattioli","year":"2015","journal-title":"Analysis of ICS-SCADA Cyber-security Maturity Levels in Critical Sectors"},{"key":"ref1","first-page":"15","article-title":"Cybersecurity&#x2019;s pearl harbor moment: Lessons learned from the colonial pipeline ransomware attack","volume":"6","author":"reeder","year":"2021","journal-title":"Cyber Defense Rev"},{"key":"ref39","first-page":"150","article-title":"A digraph model for risk identification and management in SCADA systems","author":"guan","year":"2011","journal-title":"Proc IEEE Int Conf Intell Secur Inform"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/11880240_40"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1111\/j.1539-6924.1981.tb01350.x"},{"key":"ref23","year":"2020","journal-title":"Quick Start Guide An Overview of ISA\/IEC 62443 Standards"},{"key":"ref26","doi-asserted-by":"crossref","first-page":"497","DOI":"10.1111\/j.1539-6924.2008.01030.x","article-title":"What&#x2019;s wrong with risk matrices?","volume":"28","author":"cox","year":"2008","journal-title":"Risk Anal Int J"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1002\/9781119162315"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2015.03.001"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.09.004"},{"key":"ref21","author":"kordy","year":"2012","journal-title":"ADTool manual"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.4324\/9780367491161"},{"key":"ref27","author":"christopher","year":"2021","journal-title":"Industrial cyber risk management"},{"key":"ref29","author":"morse","year":"2017","journal-title":"Investigation Wannacry Cyber Attack and the NHS (Summary)"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/10005208\/10089436.pdf?arnumber=10089436","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,5,15]],"date-time":"2023-05-15T18:52:18Z","timestamp":1684176738000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10089436\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":54,"URL":"https:\/\/doi.org\/10.1109\/access.2023.3263671","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}