首页> 外文会议>Annual meeting of the Institute of Nuclear Materials Management >A New Approach for the Cyber/Physical Security Evaluation of Operational Systems at a Nuclear Facility
【24h】

A New Approach for the Cyber/Physical Security Evaluation of Operational Systems at a Nuclear Facility

机译:核设施运营系统网络/物理安全评估的新方法

获取原文

摘要

An important aspect of nuclear facility operations is risk management. Until recently, risk management has not been applied in a holistic fashion to evaluate and address potential safety, security, and operational risks to nuclear facilities. The rush to integrate legacy systems and automate building operations, can often introduce potential cyber vulnerabilities in operational systems if system level interactions and interdependencies are not fully understood by cross-domain subject matter experts. To address this problem, the authors have developed and conducted a new type of cyber/physical security evaluation of the operational technology and building automation systems at a domestic nuclear facility. This evaluation involves a three phased approach. The first includes an easy-to-apply cybersecurity programmatic maturity assessment. The next phase, involves a "hands on" cybersecurity assessment of the overall network down to the component-level. This technical examination focuses on identification of control system assets and a search for undocumented vulnerabilities, exposures, and configuration issues. The last phase involves active security testing (e.g., penetration testing) to gauge the effectiveness of system defenses. Each phase of the assessment provides complementary results that support effective risk management decision making. In the first phase of the assessment, several areas for improvement were identified at the nuclear facility. This included the need to formalize an array of cyber/physical security practices, improve cybersecurity threat management and situational awareness, and expand cyber/physical security training and awareness programs. The second phase of the study identified potential network configuration issues and problems with the adequacy of some firewall rule sets. The cost to implement the identified enhancements is relatively low, and the risk reductions achieved should be substantial. With an improved approach to cyber/physical security assessments and risk management, the nuclear facility examined in this study is moving toward an appropriate and cost-effective alignment of cyber, physical, operational, and personnel security.
机译:核设施运营的一个重要方面是风险管理。直到最近,风险管理尚未以整体方式应用,以评估和解决核设施的潜在安全,安全和运营风险。急于整合遗留系统和自动化建设操作,如果跨领域主题专家跨域主题专家们没有完全理解系统级交互和相互依赖性,通常会在操作系统中引入潜在的网络漏洞。为了解决这个问题,作者已经开发并开展了一种新型网络/物理安全评估,在国内核设施的运营技术和建筑自动化系统的新型网络/物理安全评估。该评估涉及三个相位的方法。首先包括易于应用的网络安全性规划到期日评估。下一阶段,涉及将整体网络的“手”网络安全评估到组成级。本技术检查侧重于识别控制系统资产和搜索无证漏洞,曝光和配置问题。最后一段涉及活动安全测试(例如,穿透测试),以衡量系统防御的有效性。评估的每一阶段都提供了支持有效风险管理决策的互补结果。在评估的第一阶段,在核设施确定了几个改进领域。这包括需要将一系列网络/物理安全实践,提高网络安全威胁管理和情境意识的需要,以及扩大网络/物理安全培训和意识课程。该研究的第二阶段确定了一些防火墙规则集的潜在网络配置问题和问题。实施所识别的增强的成本相对较低,并且实现的风险减少应该是大幅的。随着网络/物理安全评估和风险管理的改进方法,本研究中审查的核设施正在朝着适当且经济效益的网络,身体,运营和人员安全方面进行迁移。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号