Information Security Standards in Critical Infrastructure Protection
نویسنده
چکیده
The standards applicable to Information Security are legion, from the purely technical, low-level specification of crypto protocols to the high-level organisational management frameworks. Industrial Control Systems among them the Information Systems in Critical Infrastructure still present their own set of challenges and quirks, despite the convergence trend towards mainstream information technologies and networking. Among these challenges we can recognise the still widespread use of legacy and proprietary systems with a long life and often poor documentation, the geographical spread, the fact that ICSs control physical equipment with all the related consequences (safety risk, difficulty of testing), the lack of IT and especially security training among the personnel, the legal and regulatory environment. The paper analyses the application of standards in Critical Infrastructure Information Protection, both from an organisational and technical perspective, their choice, their implementation and economic cost and benefits, in the context of the existing legal landscape, in particular in the European Union context. A brief theoretical excursus will examine a cost-benefit model for policymakers called to formulate the best policy in mandating or not the use of standards.
منابع مشابه
Automated Assessment Of Compliance With Security Best Practices
Several standards and best practices have been proposed for critical infrastructure protection. However, the scale and complexity of critical infrastructure assets renders manual compliance checking difficult, if not impossible. This paper focuses on the automated assessment of security compliance of electrical power grid assets. A security model based on predicate calculus is used to express i...
متن کاملCyber Security of Safety-critical Infrastructures: a Case Study for Nuclear Facilities
Computers have become crucial to the operations of government and business. Critical infrastructure protection policy has evolved since the mid-1990’s. Since 11 September 2001, the critical link between cyberspace and physical space has been increasingly recognized. Presently, critical infrastructure sectors face various cyber threats. In particular, the electrical power infrastructure is the m...
متن کاملCritical Information Infrastructure Protection (CIIP) Policies in Selected Countries: Findings of the CIIP Handbook
The International Critical Information Infrastructure Protection Handbook addresses the subject of critical information infrastructure protection (CIIP), a growingly important topic on the security policy agenda. The CIIP Handbook focuses on aspects of CIIP related to security policy and methodology. The security policy perspective evaluates policy efforts for the protection of critical informa...
متن کاملOn the Importance of Protecting Critical Infrastructure related Engineering Descriptor Information (CIEDI)
The international security situation has lead to increased concern regarding malicious attacks against critical infrastructure (CI). CI encompasses a number of essential services some of which are water, electricity, and gas supply. For all such service-based assets there exists engineering information that includes architectural blueprints, structural composition data, and layout schema of key...
متن کاملSCIT-DNS: Critical infrastructure protection through secure DNS server dynamic updates
Domain Name Systems (DNS) provide the mapping between easily remembered host names and their IP addresses. While domain name information is typically created and updated off-line, dynamic DNS updates allow clients to manage domain names online, in real time. The current secure DNS standards (DNSSEC) require private keys to be kept online to sign dynamic updates, leaving private keys subject to ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015