{"id":"https://openalex.org/W4385192315","doi":"https://doi.org/10.23919/ifipnetworking57963.2023.10186424","title":"Learning to Walk: Towards Assessing the Maturity of OT Security Control Standards and Guidelines","display_name":"Learning to Walk: Towards Assessing the Maturity of OT Security Control Standards and Guidelines","publication_year":2023,"publication_date":"2023-06-12","ids":{"openalex":"https://openalex.org/W4385192315","doi":"https://doi.org/10.23919/ifipnetworking57963.2023.10186424"},"language":"en","primary_location":{"id":"doi:10.23919/ifipnetworking57963.2023.10186424","is_oa":false,"landing_page_url":"https://doi.org/10.23919/ifipnetworking57963.2023.10186424","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IFIP Networking Conference (IFIP Networking)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5072919070","display_name":"Alexander Staves","orcid":"https://orcid.org/0000-0002-9861-0477"},"institutions":[{"id":"https://openalex.org/I67415387","display_name":"Lancaster University","ror":"https://ror.org/04f2nsd36","country_code":"GB","type":"education","lineage":["https://openalex.org/I67415387"]}],"countries":["GB"],"is_corresponding":true,"raw_author_name":"Alexander Staves","raw_affiliation_strings":["Lancaster University,Lancaster,UK","Lancaster University, Lancaster, UK"],"affiliations":[{"raw_affiliation_string":"Lancaster University,Lancaster,UK","institution_ids":["https://openalex.org/I67415387"]},{"raw_affiliation_string":"Lancaster University, Lancaster, UK","institution_ids":["https://openalex.org/I67415387"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003916789","display_name":"Sam Maesschalck","orcid":"https://orcid.org/0000-0003-4609-3487"},"institutions":[{"id":"https://openalex.org/I67415387","display_name":"Lancaster University","ror":"https://ror.org/04f2nsd36","country_code":"GB","type":"education","lineage":["https://openalex.org/I67415387"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Sam Maesschalck","raw_affiliation_strings":["Lancaster University,Lancaster,UK","Lancaster University, Lancaster, UK"],"affiliations":[{"raw_affiliation_string":"Lancaster University,Lancaster,UK","institution_ids":["https://openalex.org/I67415387"]},{"raw_affiliation_string":"Lancaster University, Lancaster, UK","institution_ids":["https://openalex.org/I67415387"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000727349","display_name":"Richard Derbyshire","orcid":"https://orcid.org/0000-0003-3902-5056"},"institutions":[{"id":"https://openalex.org/I4210137437","display_name":"Orange County Department of Education","ror":"https://ror.org/04mqvep70","country_code":"US","type":"education","lineage":["https://openalex.org/I4210137437"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Richard Derbyshire","raw_affiliation_strings":["Orange Cyberdefense,London,UK","Orange Cyberdefense, London, UK"],"affiliations":[{"raw_affiliation_string":"Orange Cyberdefense,London,UK","institution_ids":["https://openalex.org/I4210137437"]},{"raw_affiliation_string":"Orange Cyberdefense, London, UK","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100610717","display_name":"Benjamin Green","orcid":"https://orcid.org/0000-0002-1013-9933"},"institutions":[{"id":"https://openalex.org/I67415387","display_name":"Lancaster University","ror":"https://ror.org/04f2nsd36","country_code":"GB","type":"education","lineage":["https://openalex.org/I67415387"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Benjamin Green","raw_affiliation_strings":["Lancaster University,Lancaster,UK","Lancaster University, Lancaster, UK"],"affiliations":[{"raw_affiliation_string":"Lancaster University,Lancaster,UK","institution_ids":["https://openalex.org/I67415387"]},{"raw_affiliation_string":"Lancaster University, Lancaster, UK","institution_ids":["https://openalex.org/I67415387"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5030962937","display_name":"David Hutchison","orcid":"https://orcid.org/0000-0001-6052-0559"},"institutions":[{"id":"https://openalex.org/I67415387","display_name":"Lancaster University","ror":"https://ror.org/04f2nsd36","country_code":"GB","type":"education","lineage":["https://openalex.org/I67415387"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"David Hutchison","raw_affiliation_strings":["Lancaster University,Lancaster,UK","Lancaster University, Lancaster, UK"],"affiliations":[{"raw_affiliation_string":"Lancaster University,Lancaster,UK","institution_ids":["https://openalex.org/I67415387"]},{"raw_affiliation_string":"Lancaster University, Lancaster, UK","institution_ids":["https://openalex.org/I67415387"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5072919070"],"corresponding_institution_ids":["https://openalex.org/I67415387"],"apc_list":null,"apc_paid":null,"fwci":0.9979,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.77023041,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12203","display_name":"Mobile Agent-Based Network Management","score":0.9620000123977661,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12203","display_name":"Mobile Agent-Based Network Management","score":0.9620000123977661,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9383000135421753,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10917","display_name":"Smart Grid Security and Resilience","score":0.9280999898910522,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/maturity","display_name":"Maturity (psychological)","score":0.7602827548980713},{"id":"https://openalex.org/keywords/capability-maturity-model","display_name":"Capability Maturity Model","score":0.6415820121765137},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5906323194503784},{"id":"https://openalex.org/keywords/control","display_name":"Control (management)","score":0.583951473236084},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5772368311882019},{"id":"https://openalex.org/keywords/risk-analysis","display_name":"Risk analysis (engineering)","score":0.5297544598579407},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.4931561350822449},{"id":"https://openalex.org/keywords/security-controls","display_name":"Security controls","score":0.48140811920166016},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.48136430978775024},{"id":"https://openalex.org/keywords/convergence","display_name":"Convergence (economics)","score":0.4488537311553955},{"id":"https://openalex.org/keywords/information-security","display_name":"Information security","score":0.4390428364276886},{"id":"https://openalex.org/keywords/process-management","display_name":"Process management","score":0.4133307635784149},{"id":"https://openalex.org/keywords/business","display_name":"Business","score":0.3137468099594116},{"id":"https://openalex.org/keywords/software","display_name":"Software","score":0.09526386857032776},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.07544457912445068}],"concepts":[{"id":"https://openalex.org/C101433766","wikidata":"https://www.wikidata.org/wiki/Q3543263","display_name":"Maturity (psychological)","level":2,"score":0.7602827548980713},{"id":"https://openalex.org/C85890633","wikidata":"https://www.wikidata.org/wiki/Q929673","display_name":"Capability Maturity Model","level":3,"score":0.6415820121765137},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5906323194503784},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.583951473236084},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5772368311882019},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.5297544598579407},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.4931561350822449},{"id":"https://openalex.org/C178148461","wikidata":"https://www.wikidata.org/wiki/Q1632136","display_name":"Security controls","level":3,"score":0.48140811920166016},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.48136430978775024},{"id":"https://openalex.org/C2777303404","wikidata":"https://www.wikidata.org/wiki/Q759757","display_name":"Convergence (economics)","level":2,"score":0.4488537311553955},{"id":"https://openalex.org/C527648132","wikidata":"https://www.wikidata.org/wiki/Q189900","display_name":"Information security","level":2,"score":0.4390428364276886},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.4133307635784149},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.3137468099594116},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.09526386857032776},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.07544457912445068},{"id":"https://openalex.org/C50522688","wikidata":"https://www.wikidata.org/wiki/Q189833","display_name":"Economic growth","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C138496976","wikidata":"https://www.wikidata.org/wiki/Q175002","display_name":"Developmental psychology","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.23919/ifipnetworking57963.2023.10186424","is_oa":false,"landing_page_url":"https://doi.org/10.23919/ifipnetworking57963.2023.10186424","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IFIP Networking Conference (IFIP Networking)","raw_type":"proceedings-article"},{"id":"pmh:oai:eprints.lancs.ac.uk:192592","is_oa":false,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4306401916","display_name":"Lancaster EPrints (Lancaster University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I67415387","host_organization_name":"Lancaster University","host_organization_lineage":["https://openalex.org/I67415387"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"PeerReviewed"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":16,"referenced_works":["https://openalex.org/W1742813727","https://openalex.org/W1978129800","https://openalex.org/W1990067238","https://openalex.org/W2832719672","https://openalex.org/W2894085791","https://openalex.org/W2904339115","https://openalex.org/W3036745110","https://openalex.org/W3092340341","https://openalex.org/W3186345182","https://openalex.org/W3189373506","https://openalex.org/W3192615057","https://openalex.org/W4200331022","https://openalex.org/W4205700270","https://openalex.org/W4248030554","https://openalex.org/W4317931732","https://openalex.org/W7028438620"],"related_works":["https://openalex.org/W4283172224","https://openalex.org/W2992877076","https://openalex.org/W2563825355","https://openalex.org/W4382725623","https://openalex.org/W2888066950","https://openalex.org/W2889844859","https://openalex.org/W3217511980","https://openalex.org/W2806063704","https://openalex.org/W4384822944","https://openalex.org/W2912268755"],"abstract_inverted_index":{"The":[0],"convergence":[1],"of":[2,19,86],"IT":[3,75,126,146,156],"and":[4,40,44,66,90,112,121,128,139,145],"OT":[5,8,31,87,110,144,152,163],"has":[6],"presented":[7],"environments":[9],"with":[10,53],"several":[11],"challenges,":[12],"such":[13],"as":[14,71,73,148],"increasing":[15],"the":[16,84],"attack":[17],"surface":[18],"its":[20],"real":[21],"time":[22],"systems":[23],"to":[24,48,82,96,125],"include":[25],"more":[26,131],"commonplace":[27],"enterprise":[28],"vulnerabilities.":[29],"As":[30],"is":[32],"used":[33],"across":[34],"heavily":[35],"regulated":[36],"sectors,":[37,50],"including":[38],"water":[39],"nuclear,":[41],"many":[42],"standards":[43,65,89,111,127,164],"guidelines":[45,67,113,129],"are":[46,68,134,153],"available":[47],"these":[49,64,109],"providing":[51],"them":[52],"assistance":[54],"towards":[55],"continued":[56],"improvements":[57],"from":[58],"a":[59,80],"cyber":[60],"security":[61,138,149],"perspective.":[62],"However,":[63],"not":[69,115],"always":[70,116],"mature":[72,166],"their":[74],"counterparts.":[76],"This":[77],"paper":[78],"proposes":[79],"model":[81],"benchmark":[83],"maturity":[85],"focused":[88],"guidelines,":[91],"which":[92],"we":[93,106],"then":[94],"use":[95],"analyse":[97],"seven":[98],"commonly":[99],"adopted":[100],"resources.":[101],"Based":[102],"on":[103],"this":[104,161],"analysis,":[105],"find":[107],"that":[108],"do":[114],"provide":[117],"in-depth":[118],"implementation":[119],"guidance,":[120],"often":[122],"refer":[123],"instead":[124],"for":[130,142],"information.":[132],"Improvements":[133],"urgently":[135],"needed":[136],"in":[137,151],"risk":[140],"mitigation":[141],"interconnected":[143],"systems,":[147],"controls":[150],"typically":[154],"re-appropriated":[155],"controls.":[157],"To":[158],"help":[159],"achieve":[160],"goal,":[162],"must":[165],"further.":[167]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":1}],"updated_date":"2026-04-05T17:49:38.594831","created_date":"2025-10-10T00:00:00"}
