skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Cyber-Informed Engineering Implementation Guide

Program Document ·
OSTI ID:1995796
ORCiD logo [1];  [1];  [1];  [1];  [1];  [1]; ORCiD logo [1]; ORCiD logo [1]; ORCiD logo [1]; ORCiD logo [1];  [1]; ORCiD logo [1];  [1];  [1];  [1]; ORCiD logo [1];  [2];  [2];  [3];  [4] more »;  [5];  [2];  [2];  [6];  [7];  [3];  [8];  [9];  [8];  [8];  [2];  [6];  [10];  [8];  [8];  [8] « less
  1. Idaho National Laboratory
  2. 1898 & Co
  3. Nexight
  4. University of Texas, San Antonio
  5. West Yost Associates
  6. West Yost
  7. Department of Energy
  8. National Renewable Energy Laboratory
  9. Boise State University
  10. Auburn University

This Implementation Guide describes the principles of Cyber-Informed Engineering (CIE) and outlines questions that engineering teams should consider during each phase of a system’s lifecycle to effectively employ these principles. It describes what it means to engineer systems in a cyber-informed way, rather than offering a comprehensive, step-by-step process or procedure for CIE implementation. This guide complements—but does not replace—the application of cybersecurity standards or practices currently in place within an organization. Engineers and technicians that design critical energy infrastructure installations can use this Implementation Guide to integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. The guide is aimed at system or design engineers, rather than software engineers or operational cybersecurity practitioners. The engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system’s engineering design to diminish the severity of cyber attacks or digital technology failures. CIE expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences.

Research Organization:
Idaho National Laboratory (INL), Idaho Falls, ID (United States)
Sponsoring Organization:
58
DOE Contract Number:
DE-AC07-05ID14517
OSTI ID:
1995796
Report Number(s):
INL/RPT-23-74072-Rev000
Country of Publication:
United States
Language:
English