Case reference
SafSec (săf´sek)
Challenge
The
SafSec project was funded by the Ministry of Defence Procurement Agency’s Future Business Group who wished to:
"reduce the cost and effort of safety certification and security accreditation for future military avionics systems".
particularly for new developments (advanced avionics architecture, open source architecture, integrated modular avionics, commercial off-the-shelf software) and in-service upgrades.
Praxis used its extensive knowledge of both
safety and security to define a single methodology that was acceptable to all stakeholders, for addressing certification of both Safety and Security on Avionics systems. The stakeholders consulted by Praxis included:
- BAE Systems
- General Dynamics UK Ltd
- Smiths Aerospace
- QinetiQ Boscombe Down, Malvern, Farnborough
- CESG
- MOD Accreditors
- Logica CLEF
- CAA
- University of York
Outcome
The SafSec project demonstrated that there are strong parallels between safety and security certification, and trials on two avionics systems showed that accreditations can be cheaper and faster if these parallels are exploited. The SafSec methodology has since been used to inform various security engineering projects.