Threat modeling is a structured process for identifying potential system threats and defining risk mitigation strategies, traditionally conducted manually. While automation accelerates processes, reduces human errors, and enhances scalability, it can overlook nuanced or emerging threats due to data quality or system design limitations. Fully excluding human involvement risks leaving significant gaps in threat identification. Conversely, fostering a security-aware culture and involving human expertise in the process can significantly strengthen cyber resilience. This paper explores how balancing automation and human expertise can optimize cyber resilience in cyber-physical systems (CPS) and industrial control systems (ICS). By examining the impact of this balance on resilience factors such as robustness, redundancy, resourcefulness, and rapidity, we propose actionable recommendations for leveraging both approaches, to improve security outcomes and operational stability across threat modeling stages.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Balancing Automation and Human Involvement in Threat Modeling for Optimal Cyber Resilience

  • Gizem Erceylan,
  • Aida Akbarzadeh,
  • Vasileios Gkioulos

摘要

Threat modeling is a structured process for identifying potential system threats and defining risk mitigation strategies, traditionally conducted manually. While automation accelerates processes, reduces human errors, and enhances scalability, it can overlook nuanced or emerging threats due to data quality or system design limitations. Fully excluding human involvement risks leaving significant gaps in threat identification. Conversely, fostering a security-aware culture and involving human expertise in the process can significantly strengthen cyber resilience. This paper explores how balancing automation and human expertise can optimize cyber resilience in cyber-physical systems (CPS) and industrial control systems (ICS). By examining the impact of this balance on resilience factors such as robustness, redundancy, resourcefulness, and rapidity, we propose actionable recommendations for leveraging both approaches, to improve security outcomes and operational stability across threat modeling stages.