Abstract

Digitalisation of the construction industry is exposing it to cybersecurity risks. All phases of construction can be affected. Particularly vulnerable are information-intensive phases such as building design and building operation. Construction is among the last industries that are discovering its cybersecurity risks and can rely on frameworks developed for other contexts. In this paper, we evaluate the cybersecurity risks of the design phase of construction using the Cyber Assessment Framework from the National Cybersecurity Centre (NCSC) of the UK. The goal of this study is twofold. First, to examine cybersecurity risks themselves, and second, to evaluate the applicability of the NCSC framework for construction to see if and how construction is specific. The analysis shows that the cybersecurity risks follow the information impact curve that has been motivating the introduction of Building Information Modelling (BIM). The framework is applicable but is weak in addressing the specifics of the construction industrial ecosystem, which involves a multitude of dynamically connected actors, their overlapping authorities, and conflicting motives. It is suggested that a specialized constructionrelated framework should be developed.

Details

Title
Cybersecurity assessment of BIM/CDE design environment using cyber assessment framework
Author
Turk, Žiga; Sonkor, Muammer Semih  VIAFID ORCID Logo  ; Klinc, Robert  VIAFID ORCID Logo 
Pages
349-364
Section
Articles
Publication year
2022
Publication date
May 2022
Publisher
Vilnius Gediminas Technical University
ISSN
13923730
e-ISSN
18223605
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
2662754489
Copyright
© 2022. This work is published under https://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.