Sensors observe the physical process, computational elements interpret state or make decisions, and actuators or people can change physical conditions, often under timing, safety, and reliability constraints.
CPS examples include vehicles, medical devices, industrial machinery, building controls, robots, and energy systems. Their behavior emerges from feedback among software, communications, equipment, people, and the environment, so cybersecurity failures and ordinary engineering faults can affect one another.
Key points
Model the whole systemIdentify processes, control loops, timing, communications, environmental dependencies, people, services, and states that could produce unsafe or unavailable operation.
Protect feedback and controlAuthenticate commands where feasible, validate state information, constrain privileges and operating ranges, preserve trustworthy time, monitor anomalies, and separate safety functions.
Engineer lifecycle assuranceAnalyze hazards and threats together, verify requirements, test failure and recovery, control changes, maintain components, and preserve evidence without disruption.
Important limitationConventional information-technology controls cannot be applied to every CPS without engineering review. Uncoordinated scanning, isolation, patching, rebooting, or failover can interrupt control, invalidate certification, damage equipment, or endanger people.