<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Regulation and Security Modelling of Essential Services in Network of Information Systems</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Christophe Ponsard</string-name>
          <email>christophe.ponsard@cetic.be</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Robert Darimont</string-name>
          <email>robert.darimont@respect-it.be</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>CETIC Research Center</institution>
          ,
          <addr-line>Charleroi</addr-line>
          ,
          <country country="BE">Belgium</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Respect-IT</institution>
          ,
          <addr-line>Louvain-la-Neuve</addr-line>
          ,
          <country country="BE">Belgium</country>
        </aff>
      </contrib-group>
      <fpage>43</fpage>
      <lpage>48</lpage>
      <abstract>
        <p>In a globally connected world, cybersecurity has become a key issue for the citizen, companies but also operators of essential services such as energy, transportation, drinking water or health. The NIS European Directive requires countries to identify such operators to ensure that adequate cybesecurity measures are in place, that impacting problems are promptly noti ed and that an European cooperation is in place. Our work shows the bene t of a global modelling approach using i* to deploy the directive from understanding the cooperation and duties of all actors/roles through a regulation model, down to its implementation in a speci c domain to support a cybersecurity risk analysis process. Our work is illustrated on the drinking water essential domain.</p>
      </abstract>
      <kwd-group>
        <kwd>Regulation modelling</kwd>
        <kwd>cybersecurity</kwd>
        <kwd>critical systems</kwd>
        <kwd>case study</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        Our world is increasingly dependent on information processing networks and
systems. Their global interconnection makes them more vulnerable to cyber attack
growing at a fast pace. In addition to protecting the citizens and companies, it
is crucial to the secure critical infrastructures of our society and economy. The
purpose of the Network of Information System directive (NIS) is precisely to
provide a global framework at the European level to secure such infrastructures
through a coordinated approach across member states (MS) [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>The main Operator of Essential Services (OES) are energy production,
various forms of transport (rail, sea, air, etc.), production and distribution of
drinking water and hospitals. It is important to ensure that such operators have rm
cybersecurity commitments in order to prevent and react to any attempt to
attack their networks and systems. As OESs depend on Digital Service Providers
(DSPs), e.g. for hosting data or services, those must also be adequately secured.
In addition, the emergence of industry 4.0 is increasing risks due to the mix
of information technologies (IT) and operation technologies (OT), e.g. through
exposing industrial SCADA control systems with few intrinsic protection.</p>
      <p>The NIS directive has de ned a clear set of objectives:
1. monitoring of critical sectors by identifying OESs and making sure they have
protective and noti cation measures against cybersecurity attacks.
Copyright © 2020 for this paper by its authors. Use permitted under
Creative Commons License Attribution 4.0 International (CC BY 4.0).
2. creation of a regulatory framework strengthening the cybersecurity of DSPs.
3. development of national cybersecurity capacities, through one or more
Computer Security Incident Response Team (CISRT, aka CERT).
4. cross-border cooperation between EU countries.</p>
      <p>Unlike the General Data Protection Regulation (GDPR), the NIS is not a
European regulation but a directive transposed at the national level in each of
the MS. This process requires to set up a complex network of actors at di erent
levels: EU level for cooperation between MS, setup of national contact points
and CSIRT and, last but not least, the organisation of each OES domain.</p>
      <p>
        The aim of this paper is to show the bene ts of a modelling approach able to
cope with organisational and prescriptive concepts in the NIS deployment. Di
erent goal modelling approaches developed in the Requirements Engineering (RE)
eld can be considered, e.g. i* [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], KAOS [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] or more specialised
regulationoriented variants such as Nomos3 [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] or LegalGRL [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. We focus here on i* [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]
but also discuss other frameworks. Our modelling covers the organisation level
and captures cybersecurity risks in the considered domain with a contribution
to extending i* for that purpose. Our target audience is the people involved in
NIS alignment: regulators, auditors, and implementors inside OESs/DSPs, in
cooperation with cybersecurity experts who can validate/re ne the models.
      </p>
      <p>This paper is structured as follows. First, Section 2 provides a global NIS
model through Strategic Dependencies across involved actors and their Strategic
Rationales to understand their motivations to engage and collaborate. Then,
Section 3 details a risk-oriented approach to address speci c OES threats using
the water domain as case. Section 4 discusses the resulting model in the light of
related work before concluding and identifying future work in Section 5.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Global Modelling of the NIS Regulation</title>
      <p>Modelling regulatory texts is the rst step in a broader process to ensure
compliance. Other logical steps are veri cation, analysis and enforcement. The resulting
model has a number of bene ts over legal texts: it enables a better
understanding through graphical notations which are easier to navigate and decode than
long and very formal legal documents in text format. In the NIS case, it is very
important to make sure all actors understand their role, responsibilities and
interactions with other actors, especially given the large scope covering many
countries and domains.</p>
      <p>In order to provide a global vision of the NIS, Figure 1 depicts the Strategic
Dependency (SD) graph gathering all agents (EU, CSIRT Network, ENISA,...)
and roles (MS, OES,...). It re ects the hierarchical structure from EU level to
national level and then sector speci c management for OESs/DSPs through
the use of "participates in" links. Various types of OESs are modelled through
"IsA" links. Complementary actors with speci c roles are also associated through
dependencies: the national cybersecurity agency is taking responsibility for the
cybersecurity management at national level and OESs depend for being granted
compliance. CSIRTs depend on OESs for noti cation and can provide support in
return. They can themselves call for assistance from the ENISA and take part in
the CSIRT EU network together with the CERT-EU. This diagram immediately
reveals that the directive relies on a delegation of speci c goals and tasks from
the EU level to MS and nally to OESs/DSPs. This global interaction structure
is far less easy to catch when reading of the 30 pages legal text.</p>
    </sec>
    <sec id="sec-3">
      <title>Domain-Level Analysis - Drinking Water Utility Case</title>
      <p>To illustrate the instantiation in a concrete domain, we use a drinking water
utility for its lesser complexity and maturity than other elds such as transport
or energy. It requires a substantial infrastructure from water supply, treatment,
Fig. 2. Strategic Rationale diagram for the NIS directive</p>
      <p>.
storage to nally reach consumers through a distribution network. The global
chain is controlled by two OESs: the supplier and the distributor. The SR
diagram in Figure 3 details how each actor is achieving its goals with milestones.</p>
      <p>
        i* can be used in this part to perform the security risk assessment using
some extensions depicted in Figure 3: an attacker agent is introduced with its
motivations captured as (anti-)goals. An attack link is expressed using
dependencies linking anti-goals to concrete actionable goals inside the attacked actor
to break its goals. For re ecting the negative thinking, all attack concepts are
coloured in red. This extension could be achieved through a minor relaxation of
i* 2.0 rules inside the piStar tool used in this paper [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. E.g. the attacker might
deliberately want to hurt people through altering the treatment, which triggers
a safety threat. It can be blocked by the QA process but the attacker might also
take control over it to fake QA results either to mask its attack or to generate
false alarms.
      </p>
      <p>
        We cross-checked the risks inferred in our model with known attacks on water
infrastructures [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] and referenced them in Figure 3. In 2000, a million litres of
water was intentionally sent down a drain in the Maroochy attack. In 2006, an
attack in Pennsylvania could have a ected disinfectant concentration. In 2016,
an insider attack caused metering alterations and incorrect billing.
Regulation modelling is an active research eld in RE. A systematic review
highlights the importance of goal-oriented methods [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. KAOS has also been used for
regulation modelling [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. A main di erence is that KAOS focuses on the goal
structure and identi es responsible agents at the leaf level. It has a weaker
support to show all agent responsibilities and interactions across agents. In the scope
of the NIS, i* SD and SR diagrams enable a better understanding. Actually, this
work is close to the i* vulnerability-centric requirements engineering framework
[
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] which provides a richer security taxonomy making explicit the vulnerability
concept and the exploit relationship. However, it tends to focus on operational
tasks while our analysis is more concerned about (anti-)goals. A general i*
framework for risk analysis also provides useful mechanisms for reasoning about risks
and likelihood, although in the context of software development [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>
        Considering the security risk analysis, others frameworks can be used, either
generic RE (e.g. KAOS) or more specialised languages (e.g. attack trees [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]).
KAOS has a more explicit notion of obstacles used as anti-goals in the security
domain [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ] and which partly inspired our modelling. However, i* is better at
gathering and reasoning about the attackers' motivations and capabilities.
Attack trees support a wider set of operators which can be used to further detail
and quantify the model produced here [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ].
      </p>
      <p>On the practical side, our model is very complementary to the long legal text
through the use of pointers from the model to speci c NIS articles. The tagging
process revealed quite easy and text coverage was used to check for completeness
or missing aspects to be discussed with domain actors.
5</p>
    </sec>
    <sec id="sec-4">
      <title>Conclusion and Perspectives</title>
      <p>
        In this paper, we demonstrated how i* can be used for modelling the NIS
directive and to support a domain speci c risk analysis. The comparison with
other frameworks such as KAOS revealed interesting bene ts. As future work,
we would like to validate various modelling approaches with OESs during the
next NIS workshops planned in Belgium. We will also deepen our analysis of
other essential domains and experiment with tooling to better support the
integration of models and legal documents (e.g. through URL support). We also
plan to align our approach with other security and risk-oriented i* extensions
[
        <xref ref-type="bibr" rid="ref2 ref5">2, 5</xref>
        ] and to investigate the translation process of a legal text to an i* model.
Acknowledgement. This work was partly funded by the SAMOBI project of
the Walloon Region (nr. 1910032).
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Akhigbe</surname>
            ,
            <given-names>O.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Amyot</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Richards</surname>
          </string-name>
          , G.:
          <article-title>A systematic literature mapping of goal and non-goal modelling methods for legal and regulatory compliance</article-title>
          .
          <source>REJ</source>
          (04
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Costal</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          , et al.:
          <article-title>Aligning business goals and risks in oss adoption</article-title>
          .
          <source>In: Conceptual Modeling</source>
          . pp.
          <volume>35</volume>
          {
          <issue>49</issue>
          (
          <year>2015</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Dalpiaz</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Franch</surname>
            ,
            <given-names>X.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Horko</surname>
          </string-name>
          ,
          <source>J.: istar 2</source>
          .
          <article-title>0 language guide</article-title>
          .
          <source>CoRR abs/1605</source>
          .07767 (
          <year>2016</year>
          ), http://arxiv.org/abs/1605.07767
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Darimont</surname>
            ,
            <given-names>R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lemoine</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          :
          <article-title>Goal-oriented analysis of regulations</article-title>
          . In: Workshop on Regulations Modelling and their V&amp;
          <article-title>V (ReMo2V), Luxemburg</article-title>
          , June 5-
          <issue>9</issue>
          (
          <year>2006</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Elahi</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yu</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Zannone</surname>
          </string-name>
          , N.:
          <article-title>A vulnerability-centric requirements engineering framework: Analyzing security attacks, countermeasures, and requirements based on vulnerabilities</article-title>
          .
          <source>Requir. Eng</source>
          .
          <volume>15</volume>
          (
          <issue>1</issue>
          ),
          <volume>41</volume>
          {62 (Mar
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6. EU:
          <article-title>Directive 2016/1148 concerning measures for a high common level of security of network and information systems across the union</article-title>
          . http://data.europa.eu/eli/dir/2016/1148/oj (
          <year>2016</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Ghanavati</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Amyot</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rifaut</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Legal Goal-Oriented Requirement Language for Modeling Regulations</article-title>
          . In: MiSE'
          <volume>14</volume>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Hassanzadeh</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , et al.:
          <article-title>A review of cybersecurity incidents in the water sector</article-title>
          .
          <source>Journal of Environmental Engineering</source>
          <volume>146</volume>
          (
          <issue>5</issue>
          ) (May
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Ingolfo</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Siena</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
          </string-name>
          , J.:
          <article-title>Nomos 3: Reasoning about regulatory compliance of requirements</article-title>
          .
          <source>In: IEEE 22nd Int. Req. Eng. Conference</source>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10. ISO: ISO/IEC 27000 Family - Information
          <source>Security Management Systems</source>
          . https://www.iso.org/isoiec-27001
          <string-name>
            <surname>-</surname>
          </string-name>
          information-security.
          <source>html</source>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>van Lamsweerde</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Requirements Engineering - From System Goals to UML Models to Software Speci cations</article-title>
          .
          <source>Wiley</source>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>van Lamsweerde</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , et al.:
          <article-title>From system goals to intruder anti-goals: Attack generation and resolution for security requirements engineering</article-title>
          . In: RHAS (
          <year>2003</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13. NIST: Cybersecurity Framework. https://www.nist.gov/cyberframework (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Pimentel</surname>
          </string-name>
          , J.:
          <article-title>pistar tool for i* 2.0</article-title>
          . https://www.cin.ufpe.br/ jhcp/pistar (
          <year>2018</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          15.
          <string-name>
            <surname>Ponsard</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Darimont</surname>
          </string-name>
          , R.:
          <article-title>Towards Quantitative Trade-O Analysis in Goal Models with Multiple Obstacles Using Constraint Programming</article-title>
          .
          <source>In: 15th Int. Conf. on Software Technologies, ICSOFT, July 7-9</source>
          (
          <year>2020</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          16.
          <string-name>
            <surname>Schneier</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <source>Attack trees 24(12)</source>
          (
          <year>1999</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          17.
          <string-name>
            <surname>Yu</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mylopoulos</surname>
          </string-name>
          , J.:
          <article-title>Enterprise modelling for business redesign: The i* framework</article-title>
          .
          <source>SIGGROUP Bull</source>
          .
          <volume>18</volume>
          (
          <issue>1</issue>
          ) (
          <year>Apr 1997</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>