DOE OSTI · 1859678
A Cybersecurity Threat Profile for a Connected Lighting System
Abstract
In this paper we analyze a threat profile performed on a fault-detection use case for streetlights. A threat profile establishes security requirements, justifies security measures, yields actionable controls, and effectively communicates risk to stakeholders. This effort provides critical information for making threat-based decisions to increase security at a reasonable cost, and can effectively be used by development teams, software architects, and managers to make cybersecurity a part of their ongoing culture of awareness, training, and prevention. This leads to more secure systems and better-understood security. On-premise, cloud, and hybrid architectures with different authentication mechanisms were modeled and later categorized using the Microsoft STRIDE framework. An analysis of the recommended controls for each threat was performed to determine which controls could and should be put in place by manufacturers or third-party suppliers, and which controls need to be left up the end-user to implement.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Francik, Paul, Poplawski, Michael, Gourisetti, Sri Nikhil Gupta, O'Connell, Patrick, Younkin, Chance, Ashley, Travis, Seppala, Garrett. 2022-02-01. A Cybersecurity Threat Profile for a Connected Lighting System. https://doi.org/10.2172/1859678
Cite the original work for its findings. Save a collection to share your selection of sources.