FRAMICS: Functional Risk Assessment Methodology for Industrial Control Systems
摘要
Industrial control systems (ICS), essential for managing critical infrastructure like energy, water, and transportation, are increasingly vulnerable to cyber threats due to the integration of Operational Technology (OT) with Information Technology (IT). This paper introduces FRAMICS, a novel risk assessment methodology for ICS, expanding beyond traditional approaches focusing only on logical components. It integrates technical functions with operational environment, using a new functional model and a customized threat modeling technique based on the STRIDE framework. FRAMICS also enhances risk evaluation by adapting the DREAD model to incorporate empirical data, offering a more objective and rigorous assessment. As a data-driven approach, it improves current ICS risk assessment practices. A use case study of a water treatment system showed that threats to availability and integrity were the highest risks, whereas confidentiality and repudiation risks were less significant due to their limited direct impact on system operations.