Information Security for Electric Power Utilities (EPUs)-CIGRE Developments on Frameworks, Risk Assessment, and Technology

被引:30
作者
Ericsson, Goeran N. [1 ]
机构
[1] Svenska Kraftnat Swedish Natl Grid, S-16215 Vallingby, Sweden
关键词
Communication systems; control systems; cyber security; information security; ISO/IEC standard; IT security; power system communications; power system control; power systems; risk assessment; SCADA; security framework; security technology; substation automation;
D O I
10.1109/TPWRD.2008.2008470
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper deals with the important issue of proper treatment of information security for electric power utilities. It is based on the efforts of CIGRE Working Group (WG) D2.22 on "Treatment of Information Security for Electric Power Utilities (EPUs)" carried out between 2006 and 2008/2009. The WG produces a Technical Brochure (TB), where the purpose is to emphasize three main issues: Security Frameworks, Risk Assessment, and Security Technology. Here, guidance is given on different Security Frameworks based on an Information Security Domain Model. Also, baseline controls are treated. For Risk Assessment, a survey has been carried out. Only few commonalities, but several differences, have been found. Here, a methodology must be developed together with practical recommendations. For Security Technologies, guidance is given for deployment of different solutions, based on a logical diagram using different controls. Last, proposal on further work is given.
引用
收藏
页码:1174 / 1181
页数:8
相关论文
共 43 条
[1]  
*AGA, SER AGA12 REP CRYPT
[2]  
[Anonymous], 2002, 21 STEPS IMPR CYB SE
[3]  
[Anonymous], SECURITY INFORM SYST
[4]  
[Anonymous], 2009, COMMON VULNERABILITI
[5]  
[Anonymous], 2005, 27002 ISOIEC
[6]  
[Anonymous], 65 IEC TC
[7]  
[Anonymous], 2000022005 ISOIEC
[8]  
[Anonymous], NIST SPEC PUBL
[9]  
BARTELS A, 2008, ELECTRA UNPUB
[10]  
*BRIT STAND I, 2002, 3002 PD