The convergence of Information Technologies and Operational Technology systems in industrial networks presents many challenges related to availability, integrity, and confidentiality. In this paper, we evaluate the various cybersecurity risks in industrial control systems and how they may affect these areas of concern, with a particular focus on energy-sector Operational Technology systems. There are multiple threats and countermeasures that Operational Technology and Information Technology systems share. Since Information Technology cybersecurity is a relatively mature field, this paper emphasizes on threats with particular applicability to Operational Technology and their respective countermeasures. We identify regulations, standards, frameworks and typical system architectures associated with this domain. We review relevant challenges, threats, and countermeasures, as well as critical differences in priorities between Information and Operational Technology cybersecurity efforts and implications. These results are then examined against the recommended National Institute of Standards and Technology framework for gap analysis to provide a complete approach to energy sector cybersecurity. We provide analysis of countermeasure implementation to align with the continuous functions recommended for a sound cybersecurity framework.
Boeding, Matthew, et al. "Survey of Cybersecurity Governance, Threats, and Countermeasures for the Power Grid." Energies, vol. 15, no. 22, Nov. 2022. https://doi.org/10.3390/en15228692
Boeding, Matthew, Boswell, Kelly, Hempel, Michael, et al., "Survey of Cybersecurity Governance, Threats, and Countermeasures for the Power Grid," Energies 15, no. 22 (2022), https://doi.org/10.3390/en15228692
@article{osti_1899213,
author = {Boeding, Matthew and Boswell, Kelly and Hempel, Michael and Sharif, Hamid and Lopez, Jr., Juan and Perumalla, Kalyan},
title = {Survey of Cybersecurity Governance, Threats, and Countermeasures for the Power Grid},
annote = {The convergence of Information Technologies and Operational Technology systems in industrial networks presents many challenges related to availability, integrity, and confidentiality. In this paper, we evaluate the various cybersecurity risks in industrial control systems and how they may affect these areas of concern, with a particular focus on energy-sector Operational Technology systems. There are multiple threats and countermeasures that Operational Technology and Information Technology systems share. Since Information Technology cybersecurity is a relatively mature field, this paper emphasizes on threats with particular applicability to Operational Technology and their respective countermeasures. We identify regulations, standards, frameworks and typical system architectures associated with this domain. We review relevant challenges, threats, and countermeasures, as well as critical differences in priorities between Information and Operational Technology cybersecurity efforts and implications. These results are then examined against the recommended National Institute of Standards and Technology framework for gap analysis to provide a complete approach to energy sector cybersecurity. We provide analysis of countermeasure implementation to align with the continuous functions recommended for a sound cybersecurity framework.},
doi = {10.3390/en15228692},
url = {https://www.osti.gov/biblio/1899213},
journal = {Energies},
issn = {ISSN ENERGA},
number = {22},
volume = {15},
place = {Switzerland},
publisher = {MDPI AG},
year = {2022},
month = {11}}
ICC 2014 - 2014 IEEE International Conference on Communications, 2014 IEEE International Conference on Communications (ICC)https://doi.org/10.1109/ICC.2014.6883456
Winter Meeting of the Power Engineering Society, 2002 IEEE Power Engineering Society Winter Meeting. Conference Proceedings (Cat. No.02CH37309)https://doi.org/10.1109/PESW.2002.985003