Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

АДАПТАЦИЯ МЕТОДИКИ ФСТЭК РОССИИ ДЛЯ КОЛИЧЕСТВЕННОЙ ОЦЕНКИ ЗАЩИЩЁННОСТИ НЕФТЕГАЗОВОГО ПРЕДПРИЯТИЯ

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

The article presents an approach to adapting the methodology for assessing the security status of information systems, approved by the FSTEC of Russia on May 2, 2024, for oil and gas enterprises. The analysis showed that the basic set of indicators proposed by the regulator does not fully reflect the industry specifics related to the continuity of production processes and the criticality of Industrial Control Systems (ICS). The author propose an expanded system of quantitative and qualitative indicators that take into account not only the technical characteristics of security systems, but also organizational aspects of information security management, such as the level of training and involvement of personnel, timely software updates, relative downtime of critical facilities due to cyber incidents, as well as the completeness of planned measures. The developed indicators allow for a comprehensive and objective assessment of the current state of security, timely identification of problem areas and prioritization of resources in the most vulnerable areas. The paper provides recommendations for the practical implementation and development of the proposed system of indicators, including the formation of an integrated data collection infrastructure, automation of the calculation of indicators and the use of modern monitoring tools. The application of the proposed approach will allow oil and gas industry enterprises to move from formal verification of regulatory requirements to effective information security management based on objective and measurable criteria, minimize the risks of cyber incidents and reduce possible economic damage from production shutdowns.

Similar Papers
  • Conference Article
  • Cite Count Icon 11
  • 10.1109/intercon.2017.8079672
Integration of IT frameworks for the management of information security within industrial control systems providing metrics and indicators
  • Aug 1, 2017
  • Fabian Bustamante + 3 more

As an extension of a previous methodological proposal to provide management of information security in Industrial Control Systems (ICS), this study aims to adapt IT frameworks to protect industrial and manufacturing enterprises against Information and Communication Technology disruptions and malicious activity. In order to accomplish this purpose, the integration of traditional IT standards and good practices such as COBIT, PMI-PMBOK, ITIL and NIST have been merged. Hereby, COBIT has been applied to align management with the enterprise strategy, PMI-PMBOK for project management, and ITIL for the support and maintenance of ICS services. In this respect, NIST-SP 800-82 has been used as a Guide to ICS Security. Prior to its implementation, we performed an evaluation and selection of a group of tools of these frameworks. Furthermore, they have been used effectively in the operational management of the information security in real cases. Among the main obtained benefits, we were able to reduce incidents and accomplished a holistic management. The achieved results and indicators demonstrate that the management tools comply with the control of the information security in the ICS in the contexts of technology, processes, and people aligned with the strategic objectives.

  • Conference Article
  • Cite Count Icon 8
  • 10.1109/etcm.2016.7750821
A methodological proposal concerning to the management of information security in Industrial Control Systems
  • Oct 1, 2016
  • Fabian Bustamante + 3 more

The most recent international reports of security issues documented a growing number of cybernetic attacks to Industrial Control Systems. Therefore, an increase of information technology implementations in manufacturing processes arose offering solutions in Information Security of the involved manufacturers and professionals. In this respect, a notable tendency emerges in which information security has been particularly intended to be used in businesses' administrative areas, where ISO-27000 is the most favored standard. Nonetheless, it has been determined that ISO is not yet an ideal standard for an industrial approach, due to the fact that it has not been created for these systems. We designed and implemented a methodology for the management of information security of the Industrial Control Systems of industrial businesses, based on standards issued by NIST. Such methodology presents the development of a series of phases, which provide two main contributions: firstly a group of strategies to reduce risks and secondly a Guide for standards-based instructions as well as security policies for the effective management of information security.

  • Research Article
  • Cite Count Icon 15
  • 10.1016/j.cose.2021.102398
The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework
  • Jul 10, 2021
  • Computers & Security
  • Richard Smith + 4 more

The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework

  • Research Article
  • 10.17485/ijst/2016/v9is(1)/109905
Multiple Profiles based Ensemble Model for Analytical Classification of Cyber Incident
  • Jan 20, 2016
  • Indian Journal of Science and Technology
  • Hyung-Jin Mun

Background/Objectives: Cyber incidents collected from security information & event management system are growing rapidly due to expanding malicious code and companies got to collect more data and to use a variety of information with the advent of big data. Methods/Statistical Analysis: It is difficult for cyber incident analysts to extract and classify similar features due to Cyber Attacks. To solve these problems, the analytical classification of cyber incidentis formerly generated for one of the profiles from the features of cyber incidentsand cyber observable, and by evaluating the degree of similarity based on this profile, similar cyber incident is identified. Findings: Analytical classification from big data of cyber incident requires various features of cyber observables that compose the cyber incident. Therefore, it is necessary to improve classification accuracy of the similarity by using multi-profile which is classified asthe same features of cyber observables. When utilizing an ensemble algorithm and grouping similar features, we calculate the similarity, it shows higher accuracy of the classification than it is calculated based on the same criteria. Improvements/Applications: We propose a multiprofile ensemble model performed similarity analysis on cyber incident based on both attack type and cyber observable that can enhance the accuracy of the classification. Keywords: Classification, Cyber Incident, Cyber Observable, Ensemble Model, Intrusion, Profiles

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 2
  • 10.1051/shsconf/20208403003
Digital technologies in the industry: application of immersive training technologies in the oil and gas complex
  • Jan 1, 2020
  • SHS Web of Conferences
  • Anna Smirnova + 3 more

The article substantiates the need to apply training and retraining programs for personnel for permanent work in the Arctic using digital technologies, namely VR / AR / MR technologies. The geopolitical features of the Arctic zone, difficult climatic conditions do not allow directly practicing the development of professional competencies and, therefore, require the introduction of a multi-stage system of personnel training using technologies of approximate reality. Such requirements for the personnel training system predetermine the need to search for relevant digital technologies that can create conditions that are as close as possible to the conditions of professional activity in hard-to-reach Arctic regions. When forming a personnel training / retraining system for oil and gas enterprises, in addition to the specified specific working conditions, it is also necessary to take into account the sectoral features of oil and gas enterprises, which also forms a number of functional requirements for the selection of relevant digital tools, the main of which for personnel training can be considered immersive technologies. Based on the above, the paper analyzes the use of immersive technologies by oil and gas enterprises, a comparative analysis of the directions of using immersive technologies in personnel training at oil and gas enterprises, identifies the positive and negative aspects of using VR / MR / AR technologies.

  • Research Article
  • Cite Count Icon 2
  • 10.1186/s40537-025-01241-3
A deep learning-based adaptive cyber disaster management framework
  • Jul 19, 2025
  • Journal of Big Data
  • Nataliia Neshenko + 3 more

The prevalence of cybersecurity incidents targeting Industrial Control Systems (ICS) in critical national infrastructure sectors has alarmingly risen. Given ICS’s cyber-physical nature, cyber incidents, directly and indirectly, affect public health, social stability, environmental quality, and national security, introducing a new type of humanitarian threat: cyber disaster. It is generally accepted that novel data-driven methodologies must address diverse physical and societal challenges from man-made hazards to protect human well-being and social welfare. We argue that evolving cyber threats in the context of critical infrastructure require a novel approach that treats cyber incidents as disasters and leverages advances in deep learning techniques, fully integrating them into the disaster management cycle. Our argument adds to the ongoing conversation about improving disaster management practices to address contemporary challenges. In this study, we offer a deep learning-based approach to cyber disaster management. We draw upon disaster management cycles, deep learning, and new cyber threat detection instantiation. Our study offers both practical and methodological contributions to the knowledge base for scholars seeking to leverage deep learning to design deep learning-based approaches needed to thwart increasingly sophisticated cyber incidents.

  • Research Article
  • Cite Count Icon 52
  • 10.1016/j.ijcip.2021.100487
An evaluation framework for industrial control system cyber incidents
  • Oct 4, 2021
  • International Journal of Critical Infrastructure Protection
  • Mahdi Daghmehchi Firoozjaei + 3 more

An evaluation framework for industrial control system cyber incidents

  • Book Chapter
  • Cite Count Icon 3
  • 10.1016/b978-0-444-64241-7.50273-1
Development of the Cyber Exercise for Critical Infrastructures Focusing on Inter-Organization Communication
  • Jan 1, 2018
  • Computer Aided Chemical Engineering
  • Hidekazu Hirai + 4 more

Development of the Cyber Exercise for Critical Infrastructures Focusing on Inter-Organization Communication

  • Research Article
  • 10.17485/ijst/2016/v9is1/109905
Multiple Profiles based Ensemble Model for Analytical Classification of Cyber Incident
  • Dec 30, 2016
  • Indian Journal of Science and Technology
  • Hyung-Jin Mun + 1 more

Background/Objectives: Cyber incidents collected from security information & event management system are growing rapidly due to expanding malicious code and companies got to collect more data and to use a variety of information with the advent of big data. Methods/Statistical Analysis: It is difficult for cyber incident analysts to extract and classify similar features due to Cyber Attacks. To solve these problems, the analytical classification of cyber incidentis formerly generated for one of the profiles from the features of cyber incidentsand cyber observable, and by evaluating the degree of similarity based on this profile, similar cyber incident is identified. Findings: Analytical classification from big data of cyber incident requires various features of cyber observables that compose the cyber incident. Therefore, it is necessary to improve classification accuracy of the similarity by using multi-profile which is classified asthe same features of cyber observables. When utilizing an ensemble algorithm and grouping similar features, we calculate the similarity, it shows higher accuracy of the classification than it is calculated based on the same criteria. Improvements/Applications: We propose a multiprofile ensemble model performed similarity analysis on cyber incident based on both attack type and cyber observable that can enhance the accuracy of the classification.

  • Research Article
  • 10.29019/enfoqueute.1152
Challenges of information security managementin the industrial sector: A systematic review
  • Oct 1, 2025
  • Enfoque UTE
  • Shonerly Bustamante Garcia + 2 more

Currently, in the industrial sector, technology can significantly increase productivity and efficiency. However, this advancement also generates multiple challenges related to information security that must be addressed. This systematic review aimed to analyze these challenges in information security management, focusing on three specific aspects: protection models and methodologies, factors that generate vulnerabilities in industrial control systems (ICS), and cyber risks that affect the supply chain. To this end, 45 articles published in journals indexed in databases such as Scopus, EBSCO and ScienceDirect over the last four years were examined. The results indicate that approaches based on Zero Trust, Shapley Additive Explanations (SHAP), Evolutionary Multi-Objective Optimization (EMO) algorithms, and the use of the Industrial Internet of Things (IIoT) offer greater effectiveness in protecting information. In addition, the following were identified as the main vulnerability factors in ICS: excessive connectivity, the use of obsolete operating systems, uncontrolled physical access, incorrect configurations, poor maintenance, cyberattacks, and human error. With regard to the industrial supply chain, the most relevant risks include successful cyberattacks, ransomware, and industrial espionage. In conclusion, security challenges range from interoperability between systems to a shortage of specialized personnel, requiring continuous monitoring and a multidisciplinary strategic approach.

  • Conference Article
  • Cite Count Icon 7
  • 10.1109/ths.2008.4534497
Control System Cyber Incident Reporting Protocol
  • May 1, 2008
  • Simon Hennin

Information sharing about cyber incidents that affect the normal, safe operation of industrial control systems is not well coordinated or standardized across critical infrastructure sectors of the economy. Consequently there is little situational awareness about the frequency, type and extent of control system cyber incidents - a deficiency with potential national security implications. Control system disruption due to cyber rather than physical means is increasingly a concern of industry and government. More and more control systems utilize commercial off-the-shelf computer technology, and are inter-connected with business enterprise systems and the Internet. Not only are control systems in different sectors interdependent but the commonality of technology means that all sectors face a common cyber threat. These common cyber threats and vulnerabilities present the opportunity for common solutions to be adopted across industry sectors. The solutions include the elimination of vulnerabilities in control system designs and implementations. But with constantly evolving technology and the ever-present threat of cyber attack, tools are needed to support the early detection and timely reporting of control system cyber incidents. A Raytheon-led team is working in consultation with industry and government to define a standard protocol and data schema for the timely reporting of actual and potential cyber attacks on industrial control systems. Previous efforts to share cyber incident information have encountered barriers, including data confidentiality and detection of novel cyber attack methods. Potential solutions to these barriers and deployment approaches for information sharing tools based on the protocol standard are described.

  • PDF Download Icon
  • Conference Article
  • Cite Count Icon 6
  • 10.14236/ewic/ics2018.10
On the Edge Realtime Intrusion Prevention System for DoS Attack
  • Aug 1, 2018
  • Electronic workshops in computing
  • Rishabh Das + 2 more

Industrial control systems manage critical infrastructures that are immensely diverse and complicated. These highly linked critical infrastructures are made up of networks of industrial control system (ICS) each responsible for controlling critical processes. During its nascent stages the controllers in the ICS were built for robust operation in extreme industrial conditions, but little to no emphasis was placed on safeguarding the system against potential cyberthreats. The industrial networks having legacy controllers are air gapped from the enterprise network hence a centrally deployed NIDS in the same network of the trusted nodes is often used as the last line of defence against intrusions such as malicious activity or policy violation. Most cyber incidents in industrial control systems have witnessed the breach of the air gap and compromised trusted nodes. Hence this paper proposes an on-the-edge Intrusion Prevention System (IPS) that can detect and prevent Denial of Service (DoS) attack on the Programmable Logic Controllers (PLCs) from trusted nodes at real time. A novel attribute of our proposed framework is that it is generic in nature and can be used on any PLC irrespective of the critical infrastructure being controlled by it. A wide range of experimentation has been performed to validate the performance of our proposed IPS.

  • Research Article
  • 10.1080/23335777.2024.2373388
System-level operational cyber risks identification in industrial control systems
  • Jul 15, 2024
  • Cyber-Physical Systems
  • Ayodeji O Rotibi + 3 more

In Industrial Control Systems (ICS), where complex interdependencies abound, cyber incidents can have far-reaching consequences. Dependency modelling, a valuable technique for assessing cyber risks, aims to decipher relationships among variables. However, its effectiveness is often hampered by limited data exposure, hindering the analysis of direct and indirect impacts. We present a unique method that transforms dependency modelling data into a Bayesian Network (BN) structure and leverages causality and reasoning to extract inferences from seemingly unrelated events. Using operational ICS data, we confirm our method enables stakeholders to make better decisions about system security, stability, and reliability.

  • Single Report
  • Cite Count Icon 192
  • 10.2172/1505628
History of Industrial Control System Cyber Incidents
  • Dec 31, 2018
  • Kevin E Hemsley + 1 more

For many years malicious cyber actors have been targeting the industrial control systems (ICS) that manage our critical infrastructures. Most of these events are not reported to the public, and the threats and incidents to ICS are not as well-known as enterprise cyber threats and incidents. This paper is a brief study of publically reported cyber threats to critical infrastructure that sheds light on the growing cyber threats to ICS devices. It is important to note that this list is not all inclusive. The events selected in this study highlight the significant threats and incidents to industrial control systems and demonstrate that significant cyber incidents to ICS devices are growing and becoming more complex.

  • Book Chapter
  • Cite Count Icon 42
  • 10.1007/978-3-030-04537-1_12
A History of Cyber Incidents and Threats Involving Industrial Control Systems
  • Jan 1, 2018
  • Kevin Hemsley + 1 more

For many years, malicious cyber actors have been targeting the industrial control systems that manage critical infrastructure assets. Most of these events are not reported to the public and their details along with their associated threats are not as well-known as those involving enterprise (information technology) systems. This chapter presents an analysis of publicly-reported cyber incidents involving critical infrastructure assets. The list of incidents is by no means comprehensive. Nevertheless, the analysis provides valuable insights into industrial control system threats and vulnerabilities, and demonstrates the increasing trends in the number and complexity of cyber attacks.

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant