首页> 外文OA文献 >UNDERSTANDING INFORMATION SECURITY INCIDENT MANAGEMENT PRACTICES:A case study in the electric power industry
【2h】

UNDERSTANDING INFORMATION SECURITY INCIDENT MANAGEMENT PRACTICES:A case study in the electric power industry

机译:了解信息安全事故管理实践:以电力行业为例

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

With the implementation of smarter electric power distribution grids followsudnew technologies, which lead to increased connectivity and complexity.udTraditional IT components – hardware, firmware, software – replace proprietaryudsolutions for industrial control systems. These technological changesudintroduce threats and vulnerabilities that make the systems more susceptibleudto both accidental and deliberate information security incidents. As industrialudcontrol systems are used for controlling crucial parts of the society’s criticaludinfrastructure, incidents may have catastrophic consequences for our physicaludenvironment in addition to major costs for the organizations that are hit.udRecent attacks and threat reports show that industrial control organizationsudare attractive targets for attacks.udEmerging threats create the need for a well-established capacity for respondingudto unwanted incidents. Such a capacity is influenced by both organizational,udhuman, and technological factors. The main objective of this doctoral projectudhas been to explore information security incident management practices inudelectric power companies and understand challenges for improvements. Bothudliterature studies and empirical studies have been conducted, with the participationudof ten Distribution System Operators (DSOs) in the electric powerudindustry in Norway.udOur findings show that detection mechanisms currently in use are not sufficientudin light of current threats. As long as no major incidents are experienced,udthe perceived risk will most likely not increase significantly, and following,udthe detection mechanisms might not be improved. The risk perception isudfurther affected by the size of the organization and whether IT operations areudoutsourced. Outsourcing of IT services limits the efforts put into planningudand preparatory activities due to a strong confidence in suppliers. Finally,udsmall organizations have a lower risk perception than large ones. They do notudperceive themselves as being attractive targets for attacks, and they are ableudto operate the power grid without the control systems being available. Theseudfindings concern risk perception, organizational structure, and resources, whichudare factors that affect current practices for incident management.udFurthermore, different types of personnel, such as business managers andudtechnical personnel, have different perspectives and priorities when it comesudto information security. Besides, there is a gap in how IT staff and control system staff understand information security. Cross-functional teams needudto be created in order to ensure a holistic view during the incident responseudprocess. Training for responding to information security incidents is currentlyudgiven low priority. Evaluations after training sessions and minor incidentsudare not performed. Learning to learn would make the organizations able toudtake advantage of training sessions and evaluations and thereby improve theirudincident response practices.udThe main contributions of this thesis are knowledge on factors that affectudcurrent information security incident management practices and challenges forudimprovement, and application of organizational theory on information securityudincident management. Finally, this thesis contributes to an increased body ofudempirical knowledge of information security in industrial control organizations.
机译:随着更智能的配电网的实施,新技术将导致连接性和复杂性的提高。传统的IT组件(硬件,固件,软件)取代了工业控制系统的专有解决方案。这些技术变化说明了威胁和漏洞,使系统更容易受到 udd意外和故意的信息安全事件的影响。由于工业 udcontrol系统用于控制社会的关键 udf基础结构的关键部分,因此事件不仅会对遭受打击的组织造成重大损失,还对我们的物理 ud环境造成灾难性的后果。 ud近期的攻击和威胁报告表明,工业控制组织敢于提出有吸引力的攻击目标。 ud新兴的威胁使人们需要建立完善的能力来应对意外事件。这种能力受组织,人为和技术因素的影响。该博士项目的主要目的是探索电力公司中的信息安全事件管理实践,并了解改进的挑战。 挪威进行了文献研究和实证研究,其中十个配电系统运营商(DSO)参与了挪威的电力工业。 ud我们的发现表明,目前使用的检测机制不足 udin威胁。只要没有重大事件发生,所感知到的风险很可能不会显着增加,并且,其发现机制可能不会得到改善。风险感知进一步受到组织规模以及IT运营是否外包的影响。由于对供应商的强烈信心,IT服务的外包限制了计划,准备和准备活动的工作。最后,小型企业的风险感知度要低于大型企业。他们不会 u理解自己是攻击的有吸引力的目标,并且 u能够在没有控制系统可用的情况下操作电网。这些发现涉及风险感知,组织结构和资源,这是影响当前事件管理实践的敢于冒险的因素。 ud此外,不同类型的人员(例如业务经理和技术人员)在涉及到风险时具有不同的观点和优先级 udto信息安全。此外,IT员工和控制系统员工在理解信息安全方面存在差距。需要创建跨职能团队以确保事件响应过程中的整体视图。当前,应对信息安全事件的培训被认为是低优先级的。培训课程和小事故后的评估未执行。学习学习将使组织能够利用培训课程和评估的优势,从而改善他们的突发事件响应实践。 ud本文的主要贡献是对影响当前信息安全事件管理实践的因素和对挑战的认识。组织理论在信息安全事故管理中的改进和应用。最后,本论文有助于在工业控制组织中增加对信息安全的经验性知识。

著录项

  • 作者

    Line Maria Bartnes;

  • 作者单位
  • 年度 2015
  • 总页数
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号