Roadmap Timeline
-
2029
-
2022
-
2024
-
2025
-
2026
-
2027
-
2029
-
2030
Assessment of Complex Dynamic Systems of systems
2020-2027
Problem description
IT services are increasingly complex and dynamic, as exemplified by the DevOps paradigm. They also increasingly rely on third-party services, either transparently (such as name resolution or routing at the network level), or explicitly (such as single sign-on provided by major Internet actors to smaller entities). On the other hand, assessment and certification processes are static, long and expensive. Therefore, it becomes increasingly difficult to evaluate and certify interdependent complex systems that constantly evolve and receive new functionalities. This implies that the target of evaluation is undergoing constant evolution. The challenge is thus to 1) define and publish the appropriate cybersecurity properties, 2) assess that these properties are met by increasingly complex and dynamic systems and services, and finally 3) certify compliance with these cybersecurity properties as well as regulations, in a way that is verifiable by providers and customers alike. This must happen all along the lifecycle of these products and services, from design to retirement. It must be robust to either runtime changes or lasting modifications, ensuring that assessment (and certification) evolves at the same pace as services. The focus of this challenge is on cybersecurity for complex digital infrastructures, offering e-services. Even though these digital infrastructures might be driven by physical processes, safety and resilience aspects are treated in the second challenge of the CAPE program.
- Modelling of the properties of complex systems
- Automated assessment methods and tools
- Incremental assessment methods and tools
Industrial demand: Automation of assessment and certification, leading to better stability of systems and services, as well as non-regression.
Social aspect: Better stability of systems and services, leading to increased trust and use.
Benefits for EU: Support to the development of EU-based champions; better management of the supply chain when sourcing products and services outside of the EU, to better support European requirements and values.
Domain (JRC Taxonomy): Assurance, audit and certification
Sector (JRC Taxonomy): All sectors, with a focus on IT aspects of all these sectors.
Relation to emerging technologies: Artificial intelligence, Machine learning, Big data