Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Cyber-Informed Engineering Principles: What’s in it for me?

Conference ·
OSTI ID:2298974

CIE is an emerging method to integrate cybersecurity considerations into the conception, design, development, and operation of any physical system that has digital connectivity, monitoring, or control. CIE complements—but does not replace—the application of cybersecurity standards or practices currently in place within an organization. Rather, it expands cybersecurity decisions into the engineering space, not by asking engineers to become cyber experts, but by calling on engineers to apply engineering tools and make engineering decisions that improve cybersecurity outcomes. CIE examines the engineering consequences that a sophisticated cyber attacker could achieve, and drives engineering changes that may provide deterministic mitigations to limit or eliminate those consequences. Engineers and technicians that design critical energy infrastructure installations can integrate the 12 principles of CIE into each phase of the engineering lifecycle, from concept to retirement. These principles are aimed at system or design engineers, operators, and technicians, rather than software engineers or operational cybersecurity practitioners, because the engineers who design, build, operate, and maintain the physical infrastructure are best positioned to leverage a system’s engineering design to diminish the severity of cyber attacks or digital technology failures. This approach creates new opportunities for engineering teams—and not just cybersecurity teams—to secure the system using the physics and mechanics of engineering controls—not just digital monitoring and controls.

Research Organization:
Idaho National Laboratory (INL), Idaho Falls, ID (United States)
Sponsoring Organization:
58
DOE Contract Number:
AC07-05ID14517
OSTI ID:
2298974
Report Number(s):
INL/CON-23-75161-Rev000
Country of Publication:
United States
Language:
English

Similar Records

Cyber-Informed Engineering Implementation Guide
Program Document · Tue Sep 05 00:00:00 EDT 2023 · OSTI ID:1995796

Cyber-Informed Engineering Implementation Guide: Version 1.0 [Slides]
Technical Report · Mon Aug 07 00:00:00 EDT 2023 · OSTI ID:2004921

On the Application of Cyber-Informed Engineering (CIE)
Conference · Fri Nov 29 23:00:00 EST 2024 · OSTI ID:2467509