Validation and Verification (V&V): Safety vs Security.
When conducting Verification & Validation activities to ensure cybersecurity compliance for Railway products or systems, companies often mistakenly assign Safety Engineers/Validators to execute the associated tasks. This incorrect approach is typically driven by the fact that the Product Development Lifecycle for cybersecurity and RAMS appears quite similar. Of course, Safety Engineers are familiar with the V&V process defined by EN50126, and when it comes to cybersecurity, the assumption is that there should be no difference. Consequently, some believe there is no need to hire or develop cybersecurity experts for these "similar" activities.??
But is this really the case? Let me expline.
The devil is in the details...
Typically, a Railway product (component or system) must comply with cybersecurity requirements from IEC 62443, as well as national regulations (like CRA, the NIS2 Directive or others) and contractual obligations. These requirements differ from those found in safety standards such as EN 50126, which outlines RAMS requirements.?
While the System Development Lifecycles for RAMS and cybersecurity are indeed similar, and cybersecurity borrows a lot from EN 50126, the activities conducted in each phase are very different, requiring distinct levels of knowledge, expertise, and awareness in the cybersecurity domain. Yes, even the methodologies are very close, but there’s a crucial difference: cybersecurity addresses different types of threats, threat sources, vectors, and, as a result, requires other countermeasures. For example, preventing network intrusion requires more than just applying physical security measures or avoiding equipment misconfiguration. Reading, by a System Engineer, of the IEC 62443-3-3 alone is not enough (especially since it can be cryptic sometimes ??). Similarly, a Cybersecurity Engineer cannot address safety threats as a Safety Engineer does. These two domains, safety and cybersecurity, have differences that, as always, are hidden in the details, and one cannot replace the other.
Let people do their work!
Assign Safety Engineers to do RAMS and Cybersecurity Engineers to do cybersecurity. These two roles cannot replace each other but need to work together to improve the overall quality, safety, and security of your system!?
If you still believe that safety and cybersecurity V&V are similar after reading the above, let's dive deeper ??.?
The main objectives of cybersecurity testing conducted during V&V activities are to ensure:?
Based on these, IEC 62443 (and TS 50701 for Railways) require four specific types of security testing activities:?
领英推荐
Typically, for penetration testing activities, which require a high level of independence according to IEC 62443, external companies specialized in cybersecurity are contracted to ensure the correctness and quality. For other testing activities, it is common for internal employees to be involved. However, when Safety Engineers are assigned to perform cybersecurity V&V, how can they ensure the effectiveness and correctness? This, of course, is written not to downplay the importance of Safety Engineers, but to emphasize that cybersecurity work requires cybersecurity experts, just as a neurologist cannot perform heart surgery.?
We hope this quick overview helps explain why it is crucial to separate safety and cybersecurity activities for your systems. At the same time, there is no safety on the track without cybersecurity, so both domains should work closely together without any doubts!?
So, what is next?
To conclude, what is the right strategy to execute your V&V activities correctly with respect to cybersecurity? As a minimum, we recommend the following:?
We hope the time you spent reading this article was worth it, and that the brief insights have helped you navigate the complex tapestry of cybersecurity validation. If you would like to discuss this in more detail, the experts at CYBERSHIELD are just a click away!?
If you would like to discuss in details, let's have a quick talk: https://outlook.office365.com/book/[email protected]/
For direct connection mail us on [email protected]
Senior OT/ICS/IT & Cybersecurity Consultant
5 个月This excellent article distinguishes between Safety and Cybersecurity V&V roles in railway systems. Often, companies mistakenly assign Safety Engineers to handle cybersecurity V&V due to lifecycle similarities, yet each domain requires unique expertise for different threats, responses, and goals. A few added insights: 1. Collaboration: While assigning roles correctly is key, fostering collaboration between Safety and Cybersecurity teams can identify critical overlaps, strengthening both areas. 2. Baseline Cybersecurity Training: A basic cybersecurity awareness program for Safety Engineers can bridge minor gaps and accelerate team collaboration on overlapping requirements. 3. Continuous, Contextual Testing: Since railway systems have long lifespans, ongoing cybersecurity testing should be aligned with system updates to stay resilient against evolving threats. 4. Shared Resilience Goals: Developing a joint framework to align on resilience testing enhances how systems respond to both safety and security challenges in real-time. These strategies not only reinforce cybersecurity but create a proactive, cross-functional approach for critical infrastructure.