首页> 外文会议>Annual Joint ISA POWID/EPRI Controls and Instrumentation Conference >RAISING AWARENESS OF CYBER-SECURITY ISSUES IN SYSTEM OWNERS
【24h】

RAISING AWARENESS OF CYBER-SECURITY ISSUES IN SYSTEM OWNERS

机译:提高系统所有者中网络安全问题的认识

获取原文

摘要

Digital control systems and devices are increasingly making their way into process protection, control, and monitoring systems at nuclear power plants. These devices have operating systems and connectivity that allow benefits such as predictive and preventative maintenance, as well as improved transient control capability. Cyber-security awareness by the system "owners" is critical to keeping these devices secure. This can be complicated by the fact that these systems are sometimes "owned" by engineers or operators with little or no digital system experience. The normal maintenance problems these owners tend to deal with concern the mechanical portions of their systems. For many of these owners, the digital control system is nothing more than a "black box" located in a control panel. This paper will explore some of the key gaps in awareness and describe methods and guidelines to address and close these gaps. The paper focuses primarily on nuclear significant digital systems that are within the scope of the approved security plans for nuclear plants; however, the discussions also apply to fossil and hydro power plant digital control systems. Topics covered include limitations and control of digital connectivity, recovery planning, physical and logical access controls, and identification and remediation of cyber-vulnerabilities. The relative importance of confidentiality, integrity, and availability when considering digital security design principles will be explored as well as the tradeoffs of employing a Defense-in-Depth design strategy.
机译:数字控制系统和设备越来越多地进入核电厂的过程保护,控制和监控系统。这些设备具有操作系统和连接,允许诸如预测性和预防性维护等益处,以及改善的瞬态控制能力。系统“所有者”的网络安全意识对于保持这些设备安全的是至关重要的。这可能是由工程师或操作员有时是“拥有”的,这可能是具有很少或没有数字系统体验的工程师或运营商的事实。这些业主正常维护问题倾向于关注其系统的机械部分。对于许多这些所有者来说,数字控制系统只不过是位于控制面板中的“黑匣子”。本文将探讨意识的一些关键差距,并描述解决和关闭这些差距的方法和指导方针。该文件主要集中在核电站批准的安全计划范围内的核显着数字系统;但是,讨论也适用于化石和水力发电厂数字控制系统。涵盖的主题包括数字连接,恢复计划,物理和逻辑访问控制的限制和控制,以及网络漏洞的识别和修复。考虑数字安全设计原则时,保密,完整性和可用性的相对重要性将被探索以及采用防御深度设计策略的权衡。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号