WIT Press

The role of safety risk management in the UK rail industry when dealing with cyber threats

Price

Free (open access)

Volume

Volume 8 (2018), Issue 1

Pages

10

Page Range

48 - 58

Paper DOI

10.2495/SAFE-V8-N1-48-58

Copyright

WIT Press

Author(s)

NADIM CHOUDHARY

Abstract

This study will review the literature available on cyber security strategies (generally and those specific to the railway) and compare these against safety methodologies to determine whether there are any overlaps and whether a common risk approach can be used. An assessment will be made on the evaluation of cyber threats in the absence of statistical/historical data and the merits in applying a quantitative approach including consideration of Cost Benefit Analysis (CBA). It is important to note that as the safety and security disciplines have developed independently of each other, the same words (e.g. risk, hazard, threat, likelihood, probability etc.,) have subtle different meanings. The goal of Risk Manage- ment seeks to present arguments and/or demonstrations to support assertions that the identified risks have been managed in a way which satisfies the organisation’s Risk Appetite and/or the principle of As Low as Reasonably Practicable (ALARP) and CBA.

Keywords

cost benefit, cyber, RAM, reliability, risk management, safety, security.