Abstract
Information Security is a topic of growing concern within the space community. In particular ground control systems and space-link communications are required to ensure a minimum level of security and robustness. Security requirements are usually established using information risk assessment which evaluates the target systems' vulnerabilities and establishes the identification of potential threats. From this point, the risk assessment evaluates the likelihood of a threat against the severity of identified vulnerabilities and determines a quantifiable risk for each of these combinations. Many risk assessment methodologies such as ISO27005, NIST SP 800-30, or EBIOS exist, but they all face similar problems in practice. The risk assessment process looks easy on paper - but experience within ESA has shown that it can turn into a complex nightmare with unusable results if it is not done right especially when applied to complex systems. In our paper, we address the main pitfalls of risk assessment and how to avoid them. Our contribution is the result of the analysis of a number of ESA risk assessment exercises lessons learned. Some of these risk assessments were very successful while others were not. We elaborate on the following central buzzwords of successful risk assessment: Know your system, Know what is important for your system, Keep it simple, Don't believe you are done after the first round. © 2012 by European Space Agency.
Cite
CITATION STYLE
Fischer, D. (2012). Information risk assessment - How to get it right. In SpaceOps 2012 Conference. https://doi.org/10.2514/6.2012-1279153
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.