Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

Integrating Cyber-Informed Engineering into Process Automation

Technical Report ·
DOI:https://doi.org/10.2172/3006948· OSTI ID:3006948
 [1];  [1]
  1. Idaho National Laboratory (INL), Idaho Falls, ID (United States)

As organizations increasingly automate their core missions and essential functions to address business risks and enhance efficiency, process automation becomes pivotal. This shift, involving minimal or no manual intervention, significantly impacts an organization's cyber-risk landscape. While automation drives efficiencies, it also introduces new cyber risks if not properly managed. Cyber-Informed Engineering (CIE) provides a proactive framework for managing these digital risks, enhancing cyber-resilience in process automation. This document supports organizations in applying CIE principles to mitigate the cyber risks associated with automation. The outlined approach can be independently implemented to improve any organization’s cyber-resilience, ensuring that the advantages of automation do not result in unaddressed or unmanaged digital risks. It serves as a starting point, offering considerations for integrating CIE principles and practices into organizational processes. CIE is presented as an iterative process, fostering continuous improvement and reinforcing the engineering and operational cultures to manage digital risks effectively. The document is structured as follows: Section 1 provides background on CIE and process automation, and their integration. Section 2 explores the twelve CIE principles in the context of process automation, highlighting key questions, engineering considerations, and implications for digital risk management. Section 3 synthesizes the findings and offers recommendations to advance resilience by design.

Research Organization:
Idaho National Laboratory (INL), Idaho Falls, ID (United States); National Laboratory of the Rockies (NLR), Golden, CO (United States)
Sponsoring Organization:
USDOE Office of Nuclear Energy (NE); USDOE Office of Cybersecurity, Energy Security, and Emergency Response (CESER)
DOE Contract Number:
AC07-05ID14517
OSTI ID:
3006948
Report Number(s):
INL/CON--25-88262
Country of Publication:
United States
Language:
English