Organisational, Political and Technical Barriers to the Integration of Safety and Cyber-Security Incident Reporting Systems

被引:1
|
作者
Johnson, Chris W. [1 ]
机构
[1] Univ Glasgow, Sch Comp Sci, Glasgow G12 8RZ, Lanark, Scotland
关键词
Incident reporting; Safety; Cyber-security; Accident analysis; Organisational resilience;
D O I
10.1007/978-3-319-24255-2_29
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many companies must report cyber-incidents to regulatory organisations, including the US Securities and Exchange Commission and the European Network and Information Security Agency. Unfortunately, these security systems have not been integrated with safety reporting schemes. This leads to confusion and inconsistency when, for example a cyber-attack undermines the safe operation of critical infrastructures. The following pages explain this lack of integration. One reason is a clash of reporting cultures when safety related systems are intended to communicate lessons as widely as possible to avoid any recurrence of previous accidents. In contrast, disclosing the details of a security incident might motivate further attacks. There are political differences between the organisations that conventionally gather data on cyber-security incidents, national telecoms regulators, and those that have responsibility for the safety of application processes, including transportation and energy regulators. At a more technical level, the counterfactual arguments that identify root causes in safety-related accidents cannot easily be used to reason about the malicious causes of future security incidents. Preventing the cause of a previous attack provides little assurance that a motivated adversary will not succeed with another potential vector. The closing sections argue that we must address these political, organisational and technical barriers to integration given the growing threat that cyber-attacks pose for a host of complex, safety-critical applications.
引用
收藏
页码:400 / 409
页数:10
相关论文
共 50 条
  • [1] On Cyber-Security of Information Systems
    Sneps-Sneppe, Manfred
    Sukhomlin, Vladimir
    Namiot, Dmitry
    DISTRIBUTED COMPUTER AND COMMUNICATION NETWORKS (DCCN 2018), 2018, 919 : 201 - 211
  • [2] Envisioning a Cyber-Security Incident Managed Campus Environment
    Thorpe, Sean
    Jarrett, Julian
    Grandison, Tyrone
    2020 SECOND IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2020), 2020, : 307 - 309
  • [3] Analysis and Parsing of Unstructured Cyber-Security Incident Data
    Ochoa, Armando J.
    Finlayson, Mark A.
    PROCEEDINGS OF THE 2019 CONFERENCE ON SECURITY AND PRIVACY IN WIRELESS AND MOBILE NETWORKS (WISEC '19), 2019, : 345 - 346
  • [4] Cyber-security in robotics and autonomous systems
    Matellan, Vicente
    Bonaci, Tamara
    Sabaliauskaite, Giedre
    ROBOTICS AND AUTONOMOUS SYSTEMS, 2018, 100 : 41 - 42
  • [5] Cyber-security in substation automation systems
    Moreira, Naiara
    Molina, Elias
    Lazaro, Jesus
    Jacob, Eduardo
    Astarloa, Armando
    RENEWABLE & SUSTAINABLE ENERGY REVIEWS, 2016, 54 : 1552 - 1562
  • [6] Physical Cyber-Security of SCADA Systems
    Bichmou, Ahmed
    Chiocca, Joseph
    Hernandez, Leonarndo
    Hoffmann, R. Wade
    Horsham, Brandon
    Huy Lam
    McKinsey, Vince
    Bibyk, Steven
    PROCEEDINGS OF THE 2019 IEEE NATIONAL AEROSPACE AND ELECTRONICS CONFERENCE (NAECON), 2019, : 243 - 248
  • [7] Cyber-Security Analysis of Transactive Energy Systems
    Krishnan, V. V. G.
    Zhang, Y.
    Kaur, K.
    Hahn, A.
    Srivastava, A.
    Sindhu, S.
    2018 IEEE/PES TRANSMISSION AND DISTRIBUTION CONFERENCE AND EXPOSITION (T&D), 2018,
  • [8] A Framework of Cyber-Security Protection for Warship Systems
    Lv Yunfei
    Chen Yuanbao
    Wang Xuan
    Li Xuan
    Zhang Qi
    PROCEEDINGS 2015 SIXTH INTERNATIONAL CONFERENCE ON INTELLIGENT SYSTEMS DESIGN AND ENGINEERING APPLICATIONS ISDEA 2015, 2015, : 17 - 20
  • [9] RATING SYSTEMS FOR ENHANCED CYBER-SECURITY INVESTMENTS
    Xu, Jie
    Zhang, Yu
    van der Schaar, Mihaela
    2013 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2013, : 2915 - 2919
  • [10] A course in cyber-security, with orientations towards cyber-physical systems
    Thiriet, Jean-Marc
    Mocanu, Stephane
    2019 29TH ANNUAL CONFERENCE OF THE EUROPEAN ASSOCIATION FOR EDUCATION IN ELECTRICAL AND INFORMATION ENGINEERING (EAEEIE 2019), 2019,