The challenges and recommended steps to improve cyber security within industrial control systems
نویسنده
چکیده
“Security Protection against attack, Safety Freedom from risk and harm” End users or operators of industrial control systems (ICS) are responsible for the security of the systems. Many end users, however, find a challenge in addressing simple issues, typically: What requires protection from cyberattacks and how much protection is required? Will a critical system disruption or cyber theft cause a disruption to the business? If yes, how much? What is the recovery process? What is the recovery cost? This paper will provide insight to the challenges end users face related to cybersecurity for an ICS. It will also discuss & recommend the steps to improve the security and reliability of very critical ICS, including how maturity models can improve energy sector cybersecurity capabilities and provide options in prioritizing cybersecurity investments. Safety and security has received a lot of attention in recent years. This paper represents a compilation of benefits based on best practice; lessons learnt and author experience if functional safety and cyber Security for an ICS are integrated. Effective management of cybersecurity challenges and exposures in the ICS environment has emerged as an important and dynamic element in the operational safety, security and reliability of the oil and gas industry infrastructure. Management information systems (MIS) are not within the scope of this paper; solely their interfaces with ICSs are discussed. When considering security for businesses and industry, there are three traditional areas: physical security, personal security and cybersecurity. Cybersecurity aspects are the main focus of this paper. This paper will provide an oil and gas industry insight into cybersecurity risk management as per ISA99/IEC-62443. It will explore the similarities / differences between IT and ICS protection plus risk management, inclusive of possible ways for the integration of safety and security in an oil and gas industry ICS. What is an Industrial Control System (ICS)? An industrial control system (ICSs) designates a set of devices that directly control the manufacturing processes or operate technical installations (consisting of a set of sensors and actuators). Naturally, this covers the controlcommand systems that we find in many operating sectors – oil and gas, energy, power, water, chemicals, pipelines, military systems, medical systems, etc. Other frequently used terms for ICS, apart from slight differences in connotation, are distributed control systems (DCS), industrial automation
منابع مشابه
IEC 60870-5-104 Protocol Security Challenges and Countermeasures Identification
Industrial control systems (ICSs) which are used in critical infrastructure and other industries mostly use various communication protocols. Most of these communication protocols have various cyber security challenges and weakness that give the attackers the opportunity to gain to their malicious intentions. In this paper, we assess IEC 60870-5-104 protocols from security perspective which is u...
متن کاملAssuring Industrial Control System (ICS) Cyber Security
Industrial Control Systems (ICS) are an integral part of the industrial infrastructure providing for the national good. These systems include Distributed Control Systems (DCS) Supervisory Control and Data Acquisition systems (SCADA), Programmable Logic Controllers (PLC), and devices such as remote telemetry units (RTU), smart meters, and intelligent field instruments including remotely programm...
متن کاملApplication of Stochastic Optimal Control, Game Theory and Information Fusion for Cyber Defense Modelling
The present paper addresses an effective cyber defense model by applying information fusion based game theoretical approaches. In the present paper, we are trying to improve previous models by applying stochastic optimal control and robust optimization techniques. Jump processes are applied to model different and complex situations in cyber games. Applying jump processes we propose some m...
متن کاملPRECYSE: Cyber-attack Detection and Response for Industrial Control Systems
In this short paper, we present an integrated approach to detecting and mitigating cyber-attacks to modern interconnected industrial control systems. One of the primary goals of this approach is that it is costeffective, and thus whenever possible it builds on open-source security technologies and open standards, which are complemented with novel security solutions that address the specific cha...
متن کاملCyber Physical Security for Industrial Control Systems and IoT
Cyber-attacks and cybersecurity used to be the issues for those who use Internet and computers. The issues, however, are expanding to anyone who does not even use them directly. The society is gradually and heavily depending on networks and computers. They are not closed within a cyberspace anymore and having interaction with our real world with sensors and actuators. Such systems are known as ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2016