SearcharxivSearch

arXiv subjects

Christophe Ponsard

Publications and source records attributed to Christophe Ponsard.

7 recordsLinked to original sources

Evolution and Perspectives of the Keep IT Secure Ecosystem:A Six-Year Analysis of Cybersecurity Experts Supporting Belgian SMEs

The importance of cybersecurity for Small and Medium Enterprises (SMEs) has never been greater, especially given the rise of AI-driven threats. Supporting SMEs requires a sustained effort to ensure they have access to resources and expertise covering awareness, protection, auditing, and incident response. Since 2019, our work with the Keep It Secure initiative has focused on helping Belgian (Walloon) SMEs strengthen their cybersecurity posture through access to a network of labelled cybersecurity experts. In this process, we interviewed over 120 professionals from around 90 companies and gathered rich insights about the nature, strengths and weaknesses of our regional ecosystem. While our initiative primarily targets the labelling of cybersecurity experts, we demonstrate increasing alignment with the broader Cyber Fundamentals framework deployed at the federal level in Belgium, which supports official certification. This paper reports on the progress and lessons learned from this long-term effort, highlighting how expert validation, based on a structured evaluation approach, can help improve SME cybersecurity.

cs.CR

Industrial Survey on Robustness Testing In Cyber Physical Systems

Cyber-Physical Systems (CPS) play a critical role in modern industrial domains, including manufacturing, energy, transportation, and healthcare, where they enable automation, optimization, and real-time decision-making. Ensuring the robustness of these systems is paramount, as failures can have significant economic, operational, and safety consequences. This paper present findings from an industrial survey conducted in Wallonia, covering a wide range of sectors, to assess the current state of practice in CPS robustness. It investigates robustness from how it is understood and applied in relationship with requirements engineering, system design, test execution, failure modes, and available tools. It identifies key challenges and gaps between industry practices and state-of-the-art methodologies. Additionally, it compares our findings with similar industrial surveys from the literature.

cs.SE

Model-based Elaboration of a Requirements and Design Pattern Catalogue for Sustainable Systems

Designing sustainable systems involves complex interactions between environmental resources, social impact/adoption, and financial costs/benefits. In a constrained world, achieving a balanced design across those dimensions has become challenging. However a number of strategies have emerged to tackle specific aspects such as preserving resources, improving the circularity in product lifecycles and ensuring global fairness. This paper explores how to capture constitutive elements of those strategies using a modelling approach based on a reference sustainability meta-model and pattern template. After proposing an extension to the meta-modelling to enable the structuring of a pattern catalogue, we highlight how it can be populated on two case studies respectively covering fairness and circularity.

cs.SE

Modelling and Classification of Fairness Patterns for Designing Sustainable Information Systems

Designing sustainable systems involves complex interactions between environmental resources, social impacts, and economic issues. In a constrained world, the challenge is to achieve a balanced design across those dimensions while avoiding several barriers to adoption. This paper explores the concept of fairness in sociotechnical system design, including its information system component. It is based on a reference sustainability meta-model capturing the concepts of value, assumption, regulation, metric and task. Starting from a set of published cases, different fairness patterns were identified and structured in a library enabling the application of strategies for adoption, anticipation, distributive justice, and transparency. They were generalised and documented using an existing sustainability template. An extension to the initial meta-model is also proposed to identify and reason on assumptions and barriers to reach the desired values. Finally, the validation of our work is discussed using two case studies, respectively addressing the fairness to manage the COVID-19 crisis and the medico-social follow-up of childhood.

cs.SE

Challenges in Comparing Code Maintainability across Different Programming Languages

Comparing the quality of software written in different computer languages is required in a variety of scenarios, e.g. multi-language projects or application selection process among candidates in different languages. We focus on the challenges related to comparing the maintainability quality typically through a maintainability index or technical debt approaches. We identify and discuss how to manage a number of challenges to produce comparable maintainability assessments across languages related to the programming paradigm (purely procedural vs OO vs multi-paradigm), the coverage of key quality dimensions, and the use of generic metrics vs more languages specific rules. Our work is based on a set of code analysis carried out in Wallonia over the past 15 years.

cs.SE

Building a Cybersecurity Risk Metamodel for Improved Method and Tool Integration

Nowadays, companies are highly exposed to cyber security threats. In many industrial domains, protective measures are being deployed and actively supported by standards. However the global process remains largely dependent on document driven approach or partial modelling which impacts both the efficiency and effectiveness of the cybersecurity process from the risk analysis step. In this paper, we report on our experience in applying a model-driven approach on the initial risk analysis step in connection with a later security testing. Our work rely on a common metamodel which is used to map, synchronise and ensure information traceability across different tools. We validate our approach using different scenarios relying domain modelling, system modelling, risk assessment and security testing tools.

cs.CR

Assessing IT Architecture Evolution using Enriched Enterprise Architecture Models

Enterprise Architecture (EA) help companies to keep the evolution of their IT architecture aligned with their business evolution using a set of complementary models ranging from vision to infrastructure. In this paper, we explore how such models can be exploited to best drive this co-evolution by helping in validating different change management strategies. Considering state of the art techniques in service oriented and Cloud architecture, we propose to enrich and improve the quality of the information about the applications and software components on various qualities (e.g. performance, scalability, security, technical debt) in order to include them in the assessment process already at the Enterprise Architecture level rather than discovering them later in the change implementation phase. Our work is experimented on the LabNaf EA framework and is illustrated on a partial case study taken from an industrial project.

cs.SE