A Cyber Incident Response and Recovery Framework to Support Operators of Industrial Control Systems

被引:13
|
作者
Staves, Alexander [1 ]
Anderson, Tom [1 ]
Balderstone, Harry [1 ]
Green, Benjamin [1 ]
Gouglidis, Antonios [1 ]
Hutchison, David [1 ]
机构
[1] Univ Lancaster, Sch Comp & Commun, Lancaster LA1 4WA, England
基金
英国工程与自然科学研究理事会;
关键词
ICS; CNI; OT; Cyber Security; Cyber Incident; Response and Recovery; SECURITY; MANAGEMENT;
D O I
10.1016/j.ijcip.2021.100505
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the last decade, we have seen a shift in the focus of cyber attacks, moving from traditional IT systems to include more specialised Industrial Control Systems (ICS), often found within Critical National Infrastructure (CNI). Despite a push from governments to introduce appropriate legislation and guidance for such systems, operators of ICS and CNI still face multiple challenges in their cyber incident response and recovery capabilities, a theme that is often viewed as a last line of defence in minimising the impact of cyber attacks. This paper provides the following contributions: Firstly, we analyse existing standards and guidelines within cyber incident response and recovery. This analysis provides a structure on key response and recovery phases, a foundational understanding of associated requirements for these, and identifies challenges that could affect the quality of in-practice response and recovery capabilities. Using this analysis as a baseline, we examine how response and recovery processes are currently undertaken in practice through engagement with UK-based CNI operators and regulators. Secondly, as a starting point towards improving identified challenges in existing standards and guidelines and their use in practice, we propose a framework, built using the outputs identified from the document analysis and the stakeholder engagement, for use by operators to support them in assessing and improving their response and recovery capabilities.
引用
收藏
页数:24
相关论文
共 50 条
  • [41] Digital Twin-Enhanced Incident Response for Cyber-Physical Systems
    Allison, David
    Smith, Paul
    McLaughlin, Kieran
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [42] A Connective Framework to Support the Lifecycle of Cyber-Physical Production Systems
    Harrison, Robert
    Vera, Daniel A.
    Ahmad, Bilal
    PROCEEDINGS OF THE IEEE, 2021, 109 (04) : 568 - 581
  • [43] Perceptual control architecture for cyber-physical systems in traffic incident management
    Wang, Yaodong
    Tan, Guozhen
    Wang, Yuan
    Yin, Yong
    JOURNAL OF SYSTEMS ARCHITECTURE, 2012, 58 (10) : 398 - 411
  • [44] A Threat Hunting Framework for Industrial Control Systems
    Jadidi, Zahra
    Lu, Yi
    IEEE ACCESS, 2021, 9 : 164118 - 164130
  • [45] A methodological support for designing industrial control systems
    Alvarez, M. L.
    Sarachaga, I.
    Burgos, A.
    Estevez, E.
    Marcos, M.
    2012 IEEE 17TH CONFERENCE ON EMERGING TECHNOLOGIES & FACTORY AUTOMATION (ETFA), 2012,
  • [46] A Mathematical Framework for the Analysis of Cyber-Resilient Control Systems
    Melin, Alexander M.
    Ferragut, Erik M.
    Laska, Jason A.
    Fugate, David L.
    Kisner, Roger
    2013 6TH INTERNATIONAL SYMPOSIUM ON RESILIENT CONTROL SYSTEMS (ISRCS), 2013, : 13 - 18
  • [47] Situation awareness framework for industrial control system based on cyber kill chain
    Wang, Yufei
    Zhang, Tengbiao
    Ye, Qian
    2020 2ND INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE COMMUNICATION AND NETWORK SECURITY (CSCNS2020), 2021, 336
  • [48] Autonomic Intelligent Cyber-Sensor to Support Industrial Control Network Awareness
    Vollmer, Todd
    Manic, Milos
    Linda, Ondrej
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2014, 10 (02) : 1647 - 1658
  • [49] Cyber Risks to Critical Smart Grid Assets of Industrial Control Systems
    Liu, Chenyang
    Alrowaili, Yazeed
    Saxena, Neetesh
    Konstantinou, Charalambos
    ENERGIES, 2021, 14 (17)
  • [50] Cyber risk to transportation, industrial control systems, and traffic signal controllers
    Ezell B.C.
    Michael Robinson R.
    Foytik P.
    Jordan C.
    Flanagan D.
    Environment Systems and Decisions, 2013, 33 (4) : 508 - 516