{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,8]],"date-time":"2026-02-08T11:56:04Z","timestamp":1770551764141,"version":"3.49.0"},"reference-count":67,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2023,6,13]],"date-time":"2023-06-13T00:00:00Z","timestamp":1686614400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100002347","name":"Bundesministerium f\u00fcr Bildung und Forschung (German Federal Ministry of Education and Research)","doi-asserted-by":"publisher","award":["16KIS1269K"],"award-info":[{"award-number":["16KIS1269K"]}],"id":[{"id":"10.13039\/501100002347","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>\u201cSecurity by design\u201d is the term for shifting cybersecurity considerations from a system\u2019s end users to its engineers. To reduce the end users\u2019 workload for addressing security during the systems operation phase, security decisions need to be made during engineering, and in a way that is traceable for third parties. However, engineers of cyber-physical systems (CPSs) or, more specifically, industrial control systems (ICSs) typically neither have the security expertise nor time for security engineering. The security-by-design decisions method presented in this work aims to enable them to identify, make, and substantiate security decisions autonomously. Core features of the method are a set of function-based diagrams as well as libraries of typical functions and their security parameters. The method, implemented as a software demonstrator, is validated in a case study with the specialist for safety-related automation solutions HIMA, and the results show that the method enables engineers to identify and make security decisions they may not have made (consciously) otherwise, and quickly and with little security expertise. The method is also well suited to make security-decision-making knowledge available to less experienced engineers. This means that with the security-by-design decisions method, more people can contribute to a CPS\u2019s security by design in less time.<\/jats:p>","DOI":"10.3390\/s23125547","type":"journal-article","created":{"date-parts":[[2023,6,14]],"date-time":"2023-06-14T02:01:40Z","timestamp":1686708100000},"page":"5547","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Traceable Security-by-Design Decisions for Cyber-Physical Systems (CPSs) by Means of Function-Based Diagrams and Security Libraries"],"prefix":"10.3390","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4730-0126","authenticated-orcid":false,"given":"Sarah","family":"Fluchs","sequence":"first","affiliation":[{"name":"Institute of Automation, Helmut-Schmidt-University, 22043 Hamburg, Germany"},{"name":"admeritia GmbH, 40764 Langenfeld (Rheinland), Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emre","family":"Ta\u015ftan","sequence":"additional","affiliation":[{"name":"Faculty of Technology, Pforzheim University, 75175 Pforzheim, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8000-7607","authenticated-orcid":false,"given":"Tobias","family":"Trumpf","sequence":"additional","affiliation":[{"name":"HIMA Paul Hildebrandt GmbH, 68782 Br\u00fchl, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Horch","sequence":"additional","affiliation":[{"name":"HIMA Paul Hildebrandt GmbH, 68782 Br\u00fchl, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rainer","family":"Drath","sequence":"additional","affiliation":[{"name":"Faculty of Technology, Pforzheim University, 75175 Pforzheim, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1922-654X","authenticated-orcid":false,"given":"Alexander","family":"Fay","sequence":"additional","affiliation":[{"name":"Institute of Automation, Helmut-Schmidt-University, 22043 Hamburg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,6,13]]},"reference":[{"key":"ref_1","unstructured":"Easterly, J., and Goldstein, E. (2023). Stop Passing the Buck on Cybersecurity: Why Companies Must Build Safety Into Tech Products. Foreign Aff., 102, Available online: https:\/\/www.foreignaffairs.com\/united-states\/stop-passing-buck-cybersecurity."},{"key":"ref_2","unstructured":"European Parliament\/European Council (2023, April 01). Proposal for a Regulation on Horizontal Cybersecurity Requirements for Products with Digital Elements (COM\/2022\/454): Cyber Resilience Act (CRA). Available online: https:\/\/digital-strategy.ec.europa.eu\/en\/library\/cyber-resilience-act."},{"key":"ref_3","unstructured":"Biden-Harris Administration (2023, April 01). National Cybersecurity Strategy, Available online: https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2023\/03\/National-Cybersecurity-Strategy-2023.pdf."},{"key":"ref_4","unstructured":"CISA, NSA, FBI, ACSC, NCSC-UK, CCCS, BSI, NCSC-NL, CERT NZ, and NCSC-NZ (2023, April 25). Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and -Default, Available online: https:\/\/www.cisa.gov\/resources-tools\/resources\/secure-by-design-and-default."},{"key":"ref_5","unstructured":"Hollender, M. (2009). Collaborative Process Automation Systems, ISA."},{"key":"ref_6","unstructured":"NAMUR e. V (2019). NA35\u2014Engineering and Execution of PCT Projects in Process Industry, NAMUR."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Winkler, D., Biffl, S., and Bergsmann, J. (2018). Software Quality: Methods and Tools for Better Software and Systems, Springer International Publishing.","DOI":"10.1007\/978-3-319-71440-0"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Eckhart, M., Ekelhart, A., Luder, A., Biffl, S., and Weippl, E. (2019, January 14\u201317). Security Development Lifecycle for Cyber-Physical Production Systems. Proceedings of the IECON 2019-45th Annual Conference of the IEEE Industrial Electronics Society, Lisbon, Portugal.","DOI":"10.1109\/IECON.2019.8927590"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"2328","DOI":"10.1093\/comjnl\/bxu152","article-title":"An Integrated Security and Systems Engineering Process and Modelling Framework","volume":"58","author":"Ruiz","year":"2015","journal-title":"Comput. J."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Fluchs, S., Drath, R., and Fay, A. (2022, January 11\u201312). A Security Decision Base: How to Prepare Security by Design Decisions for Industrial Control Systems. Proceedings of the 17th EKA (Fachtagung \u201cEntwurf Komplexer Automatisierungssysteme\u201d), EKA 2022, Magdeburg, Germany.","DOI":"10.17560\/atp.v63i11-12.2643"},{"key":"ref_11","unstructured":"(2010). Industrial Communication Networks\u2014Network and System Security\u2014Part 2-1: Establishing an Industrial Automation and Control System Security Program (Standard No. IEC 62443-2-1)."},{"key":"ref_12","unstructured":"(2018). Security for Industrial Automation and Control Systems-Part 4-1: Secure Product Development Lifecycle Requirements (Standard No. IEC 62443-4-1)."},{"key":"ref_13","unstructured":"(2018). Security for Industrial Automation and Control Systems-Part 4-2: Technical Security Requirements for IACS Components (Standard No. IEC 62443-4-2)."},{"key":"ref_14","unstructured":"(2013). Industrial Communication Networks-Network and System Security-Part 3-3: System Security Requirements and Security Levels (Standard No. IEC 62443-3-3)."},{"key":"ref_15","unstructured":"(2022). Information Security, Cybersecurity and Privacy Protection\u2014Information Security Management Systems\u2014Requirements (Standard No. ISO\/IEC 27001:2022)."},{"key":"ref_16","unstructured":"NIST (2023, March 29). Framework for Improving Critical Infrastructure Security, Version 1.1, Available online: https:\/\/nvlpubs.nist.gov\/nistpubs\/CSWP\/NIST.CSWP.04162018.pdf."},{"key":"ref_17","unstructured":"Anderson, R. (2008). Security Engineering: A Guide to Building Dependable Distributed Systems, Wiley. [2nd ed.]."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"375","DOI":"10.1145\/162124.162127","article-title":"Information systems security design methods: Implications for information systems development","volume":"25","author":"Baskerville","year":"1993","journal-title":"ACM Comput. Surv."},{"key":"ref_19","unstructured":"Peterson, D. (2023, March 29). Explore\u2026 (S4x23 Keynote). Available online: https:\/\/dale-peterson.com\/2023\/02\/21\/explore-s4x23-intro\/."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"526","DOI":"10.1016\/j.automatica.2019.06.019","article-title":"Distributed secure state estimation for cyber\u2013physical systems under sensor attacks","volume":"107","author":"An","year":"2019","journal-title":"Automatica"},{"key":"ref_21","unstructured":"Peterson, D. (2022, May 09). Insecure by Design\/Secure by Design. Available online: https:\/\/dale-peterson.com\/2013\/11\/04\/insecure-by-design-secure-by-design\/."},{"key":"ref_22","unstructured":"(2022). Directive (EU) 2022\/2555 on Measures for a High Common Level of Cybersecurity Across the Union: NIS 2 Directive, European Union. Official Journal of the European Union L333\/80."},{"key":"ref_23","unstructured":"(2022). Directive (EU) 2022\/2557 on the Resilience of Critical Entities: RCE Directive, European Union. Official Journal of the European Union L333\/164."},{"key":"ref_24","unstructured":"(2023, April 01). Presidential Policy Directive\u2013Critical Infrastructure Security and Resilience: PPD-21, Available online: https:\/\/www.cisa.gov\/sites\/default\/files\/2023-01\/ppd-21-critical-infrastructure-and-resilience-508_0.pdf."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cose.2015.09.009","article-title":"A review of cyber security risk assessment methods for SCADA systems","volume":"56","author":"Cherdantseva","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Gro\u00dfmann, J., Felderer, M., and Seehusen, F. (2017). Risk Assessment and Risk-Driven Quality Assurance, Springer International Publishing.","DOI":"10.1007\/978-3-319-57858-3"},{"key":"ref_27","unstructured":"Fluchs, S., and Rudolph, H. (2019). Making OT security engineering deserve its name\u2014A guide to security engineering for OT engineers. CONTROL Glob., Available online: https:\/\/www.controlglobal.com\/articles\/2019\/making-ot-security-engineering-deserve-its-name."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"74","DOI":"10.17560\/atp.v61i8.2410","article-title":"Wie OT-Security-Engineering eine Ingenieurwissenschaft wird-Ein Denkmodell und ein Datenmodell [Making OT Security Engineering an Engineering Discipline-A Thought Model and a Data Model]","volume":"61","author":"Fluchs","year":"2019","journal-title":"Atp Mag."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1109\/TSE.2007.70754","article-title":"Security Requirements Engineering: A Framework for Representation and Analysis","volume":"34","author":"Haley","year":"2008","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/1082983.1083214","article-title":"Security quality requirements engineering (SQUARE) methodology","volume":"30","author":"Mead","year":"2005","journal-title":"ACM SIGSOFT Softw. Eng. Notes"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"285","DOI":"10.1142\/S0218194007003240","article-title":"Secure Tropos: A security-oriented extension of the Tropos methodology","volume":"17","author":"Mouratidis","year":"2007","journal-title":"Int. J. Softw. Eng. Knowl. Eng."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Parent, C., Schewe, K.-D., Storey, V.C., and Thalheim, B. (2007). Conceptual Modeling-ER 2007, Springer.","DOI":"10.1007\/978-3-540-75563-0"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Hatebur, D., Heisel, M., and Schmidt, H. (2007, January 3\u20137). A Security Engineering Process based on Patterns. Proceedings of the 18th International Conference on Database and Expert Systems Applications (DEXA 2007), Regensburg, Germany.","DOI":"10.1109\/DEXA.2007.36"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Vasilevskaya, M. (2013). Designing Security-Enhanced Embedded Systems: Bridging Two Islands of Expertise, Link\u00f6ping University Electronic Press.","DOI":"10.3384\/lic.diva-98213"},{"key":"ref_35","unstructured":"Goos, G., Hartmanis, J., van Leeuwen, J., Boyd, C., and Mao, W. (2003). Information Security, Springer."},{"key":"ref_36","unstructured":"Department of Information Engineering and Computer Science, University of Trento (2023, April 01). The Tropos Methodology. Available online: http:\/\/www.troposproject.eu\/node\/93."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Borgida, A.T., Chaudhri, V.K., Giorgini, P., and Yu, E.S. (2009). Conceptual Modeling: Foundations and Applications, Springer.","DOI":"10.1007\/978-3-642-02463-4"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Morkevicius, A., Bisikirskiene, L., and Bleakley, G. (2017, January 18\u201321). Using a systems of systems modeling approach for developing Industrial Internet of Things applications. Proceedings of the 2017 12th System of Systems Engineering Conference (SoSE), Waikoloa, HI, USA.","DOI":"10.1109\/SYSOSE.2017.7994942"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Lemaire, L., Lapon, J., de Decker, B., and Naessens, V. (2014, January 11\u201312). A SysML Extension for Security Analysis of Industrial Control Systems. Proceedings of the 2nd International Symposium for ICS & SCADA Cyber Security Research 2014, St. Poelten, Austria.","DOI":"10.14236\/ewic\/ics-csr2014.1"},{"key":"ref_40","unstructured":"Fluchs, S. (2023, April 01). Fluchs, S. For Security, Think Functions-Not Systems, 2020. Fluchsfriction. Available online: https:\/\/fluchsfriction.medium.com\/for-security-think-functions-not-systems-b0e08a9d89b6."},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Ruiz, J.F., Rudolph, C., Mana, A., and Arjona, M. (April, January 31). A security engineering process for systems of systems using security patterns. Proceedings of the 2014 IEEE International Systems Conference Proceedings, Ottawa, ON, Canada.","DOI":"10.1109\/SysCon.2014.6819228"},{"key":"ref_42","unstructured":"Schumacher, M. (2003). Security Engineering with Patterns: Origins, Theoretical Models, and New Applications, Springer."},{"key":"ref_43","unstructured":"Schumacher, M., Fernandez-Buglioni, E., Hybertson, D., Buschmann, F., and Sommerlad, P. (2006). Security Patterns: Integrating Security and Systems Engineering, John Wiley & Sons."},{"key":"ref_44","unstructured":"Common Criteria (2023, April 01). Common Criteria for Information Technology Security Evaluation. Version 3.1, Revision 5. Available online: https:\/\/www.commoncriteriaportal.org\/cc\/."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Glawe, M., Tebbe, C., Fay, A., and Niemann, K.-H. (2015, January 12\u201314). Knowledge-based Engineering of Automation Systems using Ontologies and Engineering Data. Proceedings of the 7th International Joint Conference on Knowledge Discovery, Knowledge Engineering and Knowledge Management, Lisbon, Portugal.","DOI":"10.5220\/0005614502910300"},{"key":"ref_46","unstructured":"Tebbe, C. (2021). Durchg\u00e4ngiges Wissensmanagement von OT-Security-Wissen im Lebensweg von Produktionsanlagen, Helmut Schmidt Universit\u00e4t\/Universit\u00e4t der Bundeswehr Hamburg."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1655","DOI":"10.1109\/TDSC.2020.3033150","article-title":"Automated Security Risk Identification Using AutomationML-based Engineering Data","volume":"19","author":"Eckhart","year":"2020","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_48","unstructured":"MITRE (2022, May 29). ATT&CK for ICS. Available online: https:\/\/attack.mitre.org\/matrices\/ics\/."},{"key":"ref_49","unstructured":"Object Management Group (2023, April 01). Unified Modeling Language (UML) Specification v2.5.1. Available online: https:\/\/www.omg.org\/spec\/UML\/2.5.1\/About-UML\/."},{"key":"ref_50","unstructured":"Bagade, P., Banerjee, A., and Gupta, S. (2017). Cyber-Physical Systems, Elsevier."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Mehmood, R., See, S., Katib, I., and Chlamtac, I. (2020). Smart Infrastructure and Applications, Springer International Publishing.","DOI":"10.1007\/978-3-030-13705-2"},{"key":"ref_52","first-page":"2920","article-title":"Engineering Security into Distributed Systems: A Survey of Methodologies","volume":"18","author":"Uzunov","year":"2012","journal-title":"J. Univers. Comput. Sci."},{"key":"ref_53","unstructured":"Crawley, E., Cameron, B., and Selva, D. (2016). System Architecture: Strategy and Product Development for Complex Systems, Pearson. Global Edition."},{"key":"ref_54","unstructured":"Walden, D.D., Roedler, G.J., Forsberg, K., Hamelin, R.D., and Shortell, T.M. (2015). INCOSE Systems Engineering Handbook: A Guide for System Life Cycle Processes and Activities, Wiley. [4th ed.]."},{"key":"ref_55","unstructured":"Bochman, A.A., and Freeman, S.G. (2021). Introducing Consequence-Driven, Cyber-Informed Engineering (CCE), Taylor & Francis Group. [1st ed.]."},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"9967","DOI":"10.1109\/ACCESS.2023.3238326","article-title":"Evaluation of Visual Notations as a Basis for ICS Security Design Decisions","volume":"11","author":"Fluchs","year":"2023","journal-title":"IEEE Access"},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"65","DOI":"10.1111\/j.1551-6708.1987.tb00863.x","article-title":"Why a Diagram is (Sometimes) Worth Ten Thousand Words","volume":"11","author":"Larkin","year":"1987","journal-title":"Cogn. Sci."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"439","DOI":"10.1080\/00221300009598596","article-title":"Pictures, words, and sounds: From which format are we best able to reason?","volume":"127","author":"Goolkasian","year":"2000","journal-title":"J. Gen. Psychol."},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"756","DOI":"10.1109\/TSE.2009.67","article-title":"The \u201cPhysics\u201d of Notations: Toward a Scientific Basis for Constructing Visual Notations in Software Engineering","volume":"35","author":"Moody","year":"2009","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_60","doi-asserted-by":"crossref","first-page":"499","DOI":"10.1080\/01621459.1985.10478147","article-title":"Graphics and Human Information Processing: A Review of Five Books","volume":"80","author":"Kosslyn","year":"1985","journal-title":"J. Am. Stat. Assoc."},{"key":"ref_61","unstructured":"Tastan, E., Fluchs, S., and Drath, R. (2022). Tagungsband zur AUTOMATION 2022 (23. Leitkongress der Mess- und Automatisierungstechnik), VDI Verlag GmbH. (In German)."},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Wieringa, R.J. (2014). Design Science Methodology for Information Systems and Software Engineering, Springer.","DOI":"10.1007\/978-3-662-43839-8"},{"key":"ref_63","unstructured":"(2020). Security for Industrial Automation and Control Systems, Part 3-2: Security Risk Assessment for System Design (Standard No. IEC 62443-3-2)."},{"key":"ref_64","doi-asserted-by":"crossref","unstructured":"Fluchs, S., Tastan, E., Mertens, M., Ritter, J., Horch, A., Drath, R., and Fay, A. (2022). Security by Design Decisions for Automation Systems. Part 2: Concept for Integrating Security Decisions into the Engineering Workflow. Atp Mag., (In German).","DOI":"10.17560\/atp.v63i9.2620"},{"key":"ref_65","doi-asserted-by":"crossref","unstructured":"Fluchs, S., Tastan, E., Mertens, M., Ritter, J., Horch, A., Drath, R., and Fay, A. (2022). Security by Design for Automation Systems. Part 1: Explanation of Terms and Analysis of Existing Approaches. Atp Mag., (In German).","DOI":"10.17560\/atp.v63i9.2620"},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Fluchs, S., Tasten, E., Mertens, M., Horch, A., Drath, R., and Fay, A. (2022, January 17\u201320). Security by Design Integration Mechanisms for Industrial Control Systems. Proceedings of the IECON 2022\u201348th Annual Conference of the IEEE Industrial Electronics Society, Brussels, Belgium.","DOI":"10.1109\/IECON49645.2022.9968406"},{"key":"ref_67","unstructured":"German Federal Ministry of Education and Research (2023, April 01). IDEAS-Integrierte Datenmodelle for the Engineering of Automation Security. Project Overview (In German). Available online: https:\/\/www.forschung-it-sicherheit-kommunikationssysteme.de\/projekte\/ideas."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/12\/5547\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:54:09Z","timestamp":1760126049000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/12\/5547"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,13]]},"references-count":67,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2023,6]]}},"alternative-id":["s23125547"],"URL":"https:\/\/doi.org\/10.3390\/s23125547","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,6,13]]}}}