{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T20:55:50Z","timestamp":1768424150913,"version":"3.49.0"},"reference-count":42,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T00:00:00Z","timestamp":1760313600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100005416","name":"the Research Council of Norway through the SFI Norwegian Centre for Cybersecurity in Critical Sectors (NORCICS) project","doi-asserted-by":"publisher","award":["310105"],"award-info":[{"award-number":["310105"]}],"id":[{"id":"10.13039\/501100005416","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NTNU Norwegian University of Science and Technology"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>Hardware systems are foundational to critical infrastructure, embedded devices, and consumer products, making robust security assurance essential. However, existing hardware security standards remain fragmented, inconsistent in scope, and difficult to integrate, creating gaps in protection and inefficiencies in assurance planning. This paper proposes a unified, standard-aligned, and threat-validated taxonomy of Security Objective Domains (SODs) for hardware security assurance. The taxonomy was inductively derived from 1287 requirements across ten internationally recognized standards using AI-assisted clustering and expert validation, resulting in 22 domains structured by the Boundary-Driven System of Interest model. Each domain was then validated against 167 documented hardware-related threats from CWE\/CVE databases, regulatory advisories, and incident reports. This threat-informed mapping enables quantitative analysis of assurance coverage, prioritization of high-risk areas, and identification of cross-domain dependencies. The framework harmonizes terminology, reduces redundancy, and addresses assurance gaps, offering a scalable basis for sector-specific profiles, automated compliance tooling, and evidence-driven risk management. Looking forward, the taxonomy can be extended with sector-specific standards, expanded threat datasets, and integration of weighted severity metrics such as CVSS to further enhance risk-based assurance.<\/jats:p>","DOI":"10.3390\/jcp5040086","type":"journal-article","created":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T14:04:02Z","timestamp":1760537042000},"page":"86","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Unified, Threat-Validated Taxonomy for Hardware Security Assurance"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6228-8367","authenticated-orcid":false,"given":"Shao-Fang","family":"Wen","sequence":"first","affiliation":[{"name":"Department of Information Security and Communication Technology, Norwegian University of Science and Technology, 2815 Gj\u00f8vik, Norway"},{"name":"Department of Business and IT, University of South-Eastern Norway, 3800 B\u00f8, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3467-9560","authenticated-orcid":false,"given":"Arvind","family":"Sharma","sequence":"additional","affiliation":[{"name":"Department of Information Security and Communication Technology, Norwegian University of Science and Technology, 2815 Gj\u00f8vik, Norway"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,10,13]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Sadeghi, A.-R., Wachsmann, C., and Waidner, M. (2015, January 7\u201311). Security and privacy challenges in industrial internet of things. Proceedings of the 52nd Annual Design Automation Conference, San Francisco, CA, USA.","DOI":"10.1145\/2744769.2747942"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1802","DOI":"10.1109\/JIOT.2017.2703172","article-title":"Cyber-physical systems security\u2014A survey","volume":"4","author":"Humayed","year":"2017","journal-title":"IEEE Internet Things J."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1010","DOI":"10.1109\/TCAD.2020.3047976","article-title":"An overview of hardware security and trust: Threats, countermeasures, and design tools","volume":"40","author":"Hu","year":"2020","journal-title":"IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1007\/s10836-013-5430-8","article-title":"Counterfeit integrated circuits: Detection, avoidance, and the challenges ahead","volume":"30","author":"Guin","year":"2014","journal-title":"J. Electron. Test."},{"key":"ref_5","unstructured":"Costin, A., Zaddach, J., Francillon, A., and Balzarotti, D. (2014, January 20\u201322). A Large-scale analysis of the security of embedded firmwares. Proceedings of the 23rd USENIX Security Symposium (USENIX Security 14), San Diego, CA, USA."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"305","DOI":"10.2147\/MDER.S50048","article-title":"Cybersecurity vulnerabilities in medical devices: A complex environment and multifaceted problem","volume":"8","author":"Williams","year":"2015","journal-title":"Med. Devices Evid. Res."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Li, F., and Paxson, V. (November, January 30). A large-scale empirical study of security patches. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3134072"},{"key":"ref_8","unstructured":"Anderson, R.J. (2010). Security Engineering: A Guide to Building Dependable Distributed Systems, John Wiley & Sons."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Genkin, D., Pachmanov, L., Pipman, I., Tromer, E., and Yarom, Y. (2016, January 24\u201328). ECDSA key extraction from mobile devices via nonintrusive physical side channels. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978353"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1109\/MSPEC.2008.4505310","article-title":"The hunt for the kill switch","volume":"45","author":"Adee","year":"2008","journal-title":"IEEE Spectr."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Cui, A., and Stolfo, S.J. (2010, January 6\u201310). A quantitative analysis of the insecurity of embedded network devices: Results of a wide-area scan. Proceedings of the 26th Annual Computer Security Applications Conference, Austin, TX, USA.","DOI":"10.1145\/1920261.1920276"},{"key":"ref_12","unstructured":"(2019). Security Requirements for Cryptographic Modules (Standard No. NIST FIPS 140-3)."},{"key":"ref_13","unstructured":"(2020). Information Security, Cybersecurity and Privacy Protection\u2014Physically Unclonable Functions (Standard No. ISO\/IEC 20897-1:2020)."},{"key":"ref_14","unstructured":"(2018). Platform Firmware Resiliency Guidelines (Standard No. NIST SP 800-193)."},{"key":"ref_15","unstructured":"(2023). Information technology\u2014Open Trusted Technology ProviderTM Standard (O-TTPS) (Standard No. ISO\/IEC 20243-2:2023)."},{"key":"ref_16","unstructured":"(2018). Series of Standards: Industrial Automation and Control Systems Security (1\u20134) (Standard No. ISA\/IEC 62443)."},{"key":"ref_17","unstructured":"(2017). Standard for Software Cybersecurity for Network-Connectable Products\u2014Part 2-1: Particular Requirements for Network Connectable Components of Healthcare Systems (Standard No. UL 2900-2-1:2017)."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"M\u00f6ller, D.P. (2023). NIST cybersecurity framework and MITRE cybersecurity criteria. Guide to Cybersecurity in Digital Transformation: Trends, Methods, Technologies, Applications and Best Practices, Springer.","DOI":"10.1007\/978-3-031-26845-8"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"95","DOI":"10.20517\/jsss.2023.50","article-title":"A taxonomy for cybersecurity standards","volume":"5","author":"Kalogeraki","year":"2024","journal-title":"J. Surveill. Secur. Saf."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"85315","DOI":"10.1109\/ACCESS.2023.3303205","article-title":"A comparative analysis of industrial cybersecurity standards","volume":"11","author":"Djebbar","year":"2023","journal-title":"IEEE Access"},{"key":"ref_21","first-page":"14","article-title":"The need for higher education in cyber supply chain security and hardware assurance","volume":"9","author":"Cohen","year":"2018","journal-title":"Int. J. Syst. Softw. Secur. Prot. (IJSSSP)"},{"key":"ref_22","unstructured":"Benson, V., Furnell, S., Masi, D., and Muller, T. (2025, July 10). Regulation, Policy and Cybersecurity. Available online: https:\/\/static1.squarespace.com\/static\/5f8ebbc01b92bb238509b354\/t\/659d51bd850d012c9eb1aaad\/1704808898551\/Discribe%2Breport%2BRegulation%2BPolicy%2Band%2BCybersecurity.pdf."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1643","DOI":"10.1111\/risa.13687","article-title":"Defining cyber security and cyber security risk within a multidisciplinary context using expert elicitation","volume":"42","author":"Cains","year":"2022","journal-title":"Risk Anal."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"103623","DOI":"10.1016\/j.im.2022.103623","article-title":"Standardizing information security\u2013a structurational analysis","volume":"59","author":"Andersson","year":"2022","journal-title":"Inf. Manag."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"103895","DOI":"10.1016\/j.cose.2024.103895","article-title":"sec-certs: Examining the security certification practice for better vulnerability mitigation","volume":"143","author":"Janovsky","year":"2024","journal-title":"Comput. Secur."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1108\/ICS-06-2023-0101","article-title":"Exploring the role of assurance context in system security assurance evaluation: A conceptual model","volume":"32","author":"Wen","year":"2024","journal-title":"Inf. Comput. Secur."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"598","DOI":"10.1016\/j.im.2013.08.004","article-title":"Theorizing the concept and role of assurance in information systems security","volume":"50","author":"Spears","year":"2013","journal-title":"Inf. Manag."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"357","DOI":"10.3390\/jcp4020018","article-title":"An integrated approach to cyber risk management with cyber threat intelligence framework to secure critical infrastructure","volume":"4","author":"Samhat","year":"2024","journal-title":"J. Cybersecur. Priv."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"e333","DOI":"10.1002\/spy2.333","article-title":"A threat-intelligence driven methodology to incorporate uncertainty in cyber risk analysis and enhance decision-making","volume":"7","author":"Dekker","year":"2024","journal-title":"Secur. Priv."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"12","DOI":"10.63180\/jcsra.thestap.2025.2.2","article-title":"Analyzing cybersecurity risks and threats in IT infrastructure based on NIST framework","volume":"2025","author":"Aljumaiah","year":"2025","journal-title":"J. Cyber Secur. Risk Audit"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"103532","DOI":"10.1016\/j.cose.2023.103532","article-title":"A quantitative security evaluation and analysis model for web applications based on OWASP application security verification standard","volume":"135","author":"Wen","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_32","unstructured":"Trusted Computing Group (TCG) (2019). Implementing Hardware Roots of Trust, TCG. Available online: https:\/\/trustedcomputinggroup.org\/resource\/implementing-hardware-roots-of-trust\/."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"(2022). Information Security, Cybersecurity and Privacy Protection\u2014Information Security Management Systems\u2014Requirements (Standard No. ISO\/IEC 27001:2022). Available online: https:\/\/www.iso.org\/standard\/27001.","DOI":"10.2307\/j.ctv30qq13d"},{"key":"ref_34","unstructured":"(2021). Road Vehicles\u2014Cybersecurity Engineering (Standard No. ISA ISA\/IEC 62443:2021)."},{"key":"ref_35","unstructured":"(2014). Airworthiness Security Process Specification (Standard No. RCTA DO-326A)."},{"key":"ref_36","first-page":"123","article-title":"spaCy: Industrial-Strength Natural Language Processing in Python (v3.5)","volume":"5","author":"Honnibal","year":"2020","journal-title":"J. Open Source Softw."},{"key":"ref_37","unstructured":"Devlin, J., Chang, M.-W., Lee, K., and Toutanova, K. (2019, January 2\u20137). Bert: Pre-training of deep bidirectional transformers for language understanding. Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Volume 1 (Long and Short Papers), Minneapolis, MN, USA."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Guo, J.L., Stegh\u00f6fer, J.-P., Vogelsang, A., and Cleland-Huang, J. (2025). Natural language processing for requirements traceability. Handbook on Natural Language Processing for Requirements Engineering, Springer.","DOI":"10.1007\/978-3-031-73143-3_4"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Reimers, N., and Gurevych, I. (2019). Sentence-bert: Sentence embeddings using siamese bert-networks. arXiv.","DOI":"10.18653\/v1\/D19-1410"},{"key":"ref_40","first-page":"2825","article-title":"Scikit-learn: Machine learning in Python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1038\/s41586-020-2649-2","article-title":"Array programming with NumPy","volume":"585","author":"Harris","year":"2020","journal-title":"Nature"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Camurati, G., Poeplau, S., Muench, M., Hayes, T., and Francillon, A. (2018, January 15\u201319). Screaming channels: When electromagnetic side channels meet radio transceivers. Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada.","DOI":"10.1145\/3243734.3243802"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/86\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T14:31:40Z","timestamp":1760538700000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/86"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,13]]},"references-count":42,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040086"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040086","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,13]]}}}