Cybersecurity Resiliency of Marine Renewable Energy Systems Part 2: Cybersecurity Best Practices and Risk Management

被引:0
|
作者
de Peralta, Fleurdeliza A. [1 ]
Watson, Mark D. [1 ]
Bays, Ryan M. [1 ]
Boles, Joshua R. [1 ]
Powers, Ford E. [1 ]
机构
[1] Pacific Northwest Natl Lab, POB 999, Richland, WA 99352 USA
关键词
cybersecurity; risk management; marine renewable energy; cybersecurity requirements; energy cybersecurity;
D O I
10.4031/MTSJ.55.2.4
中图分类号
P75 [海洋工程];
学科分类号
0814 ; 081505 ; 0824 ; 082401 ;
摘要
Marine renewable energy (MRE) is an emerging source of power for marine applications, marine devices, and coastal communities. This energy source relies on industrial control systems and IT to support operations and maintenance activities, which create a pathway for an adversary to gain unauthorized access to systems and data and disrupt operations. Incorporating cybersecurity risk prevention measures and mitigation capabilities from inception, development, operation, to decommissioning of the MRE system and components is paramount to the protection of energy generation and the security of network architecture and infrastructure. To improve the resilience of MRE systems as a predictable, affordable, and reliable source of energy, cybersecurity guidance was developed to enable operators to assess cybersecurity risks and implement security measures commensurate with the risk. This publication is the second of a two-part series, with Part 1 addressing a framework to determine cybersecurity risk by assessing the vulnerability of an MRE system to potential cyber threats and the consequences a cyberattack would have on the end user. This Part 2 publication describes an approach to select appropriate cybersecurity best practices commensurate with the MRE system's cybersecurity risk. The guidance includes 86 cybersecurity best practices, which are associated with 36 cybersecurity domains and grouped into nine categories. The best practices follow the core functions of the National Institute of Science and Technology Cybersecurity Framework (e.g., identify, detect, protect, respond, and and recover) and insights from both maritime and energy industry guidance documents to identify security measures effective in protecting information and operational technology assets prevalent in MRE systems.
引用
收藏
页码:104 / 116
页数:13
相关论文
共 41 条
  • [1] Cybersecurity Resiliency of Marine Renewable Energy Systems-Part 1: Identifying Cybersecurity Vulnerabilities and Determining Risk
    de Peralta, Fleurdeliza A.
    Gorton, Alicia M.
    Watson, Mark D.
    Bays, Ryan M.
    Boles, Joshua R.
    Gorton, Brandon T.
    Castleberry, Jerry E.
    Powers, Ford E.
    MARINE TECHNOLOGY SOCIETY JOURNAL, 2020, 54 (06) : 97 - 107
  • [2] Beyond the Firewall: Best Practices for Cybersecurity Risk Management
    Overton, Thomas W.
    POWER, 2016, 160 (03) : 34 - 38
  • [3] Cybersecurity in Smart Renewable Energy Systems
    Yaacoub, Jean Paul
    Noura, Hassan
    Azar, Joseph
    Salman, Ola
    Chahine, Khaled
    20TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE, IWCMC 2024, 2024, : 1534 - 1540
  • [4] Cybersecurity Best Practices for Creating Resilient Control Systems
    Smith, Jess
    Pereyda, Joshua
    Gammel, Dennis
    2016 RESILIENCE WEEK (RWS), 2016, : 62 - 66
  • [5] Measuring Stakeholders' Perceptions of Cybersecurity for Renewable Energy Systems
    Madnick, Stuart
    Jalali, Mohammad S.
    Siegel, Michael
    Lee, Yang
    Strong, Diane
    Wang, Richard
    Ang, Wee Horng
    Deng, Vicki
    Mistree, Dinsha
    DATA ANALYTICS FOR RENEWABLE ENERGY INTEGRATION (DARE 2016), 2017, 10097 : 67 - 77
  • [6] Resiliency under Strategic Foresight: The effects of Cybersecurity Management and Enterprise Risk Management Alignment
    Althonayan, Abraham
    Andronache, Alina
    2019 INTERNATIONAL CONFERENCE ON CYBER SITUATIONAL AWARENESS, DATA ANALYTICS AND ASSESSMENT (CYBER SA), 2019,
  • [7] IEC 61850-Based Renewable Energy Systems: A Survey on Cybersecurity Aspects
    Wilkerson, Celina
    El Hariri, Mohamad
    2022 IEEE INTERNATIONAL CONFERENCE ON ENVIRONMENT AND ELECTRICAL ENGINEERING AND 2022 IEEE INDUSTRIAL AND COMMERCIAL POWER SYSTEMS EUROPE (EEEIC / I&CPS EUROPE), 2022,
  • [8] Intelligent Energy Management Systems in Industry 5.0: Cybersecurity Applications in Examples
    Wyrzykowska, Barbara
    Szczepaniuk, Hubert
    Szczepaniuk, Edyta Karolina
    Rytko, Anna
    Kacprzak, Marzena
    ENERGIES, 2024, 17 (23)
  • [9] Cybersecurity Risk Management Framework for Blockchain Identity Management Systems in Health IoT
    Alamri, Bandar
    Crowley, Katie
    Richardson, Ita
    SENSORS, 2023, 23 (01)
  • [10] Integration of Cybersecurity, Usability, and Human-Computer Interaction for Securing Energy Management Systems
    Albarrak, Abdullah M.
    SUSTAINABILITY, 2024, 16 (18)