YaBeSH Engineering and Technology Library

    • Journals
    • PaperQuest
    • YSE Standards
    • YaBeSH
    • Login
    View Item 
    •   YE&T Library
    • ASME
    • Journal of Nuclear Engineering and Radiation Science
    • View Item
    •   YE&T Library
    • ASME
    • Journal of Nuclear Engineering and Radiation Science
    • View Item
    • All Fields
    • Source Title
    • Year
    • Publisher
    • Title
    • Subject
    • Author
    • DOI
    • ISBN
    Advanced Search
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    Archive

    Development, Distribution, and Maintenance of Application Security Controls for Nuclear

    Source: Journal of Nuclear Engineering and Radiation Science:;2018:;volume( 004 ):;issue: 004::page 41010
    Author:
    Waedt, Karl
    ,
    Ding, Yongjian
    ,
    Ciriello, Antonio
    ,
    Lou, Xinxin
    DOI: 10.1115/1.4039970
    Publisher: The American Society of Mechanical Engineers (ASME)
    Abstract: The generic concept of security controls, as initially deployed in the information security domain, is gradually used in other business domains, including industrial security for critical infrastructure and cybersecurity of nuclear safety instrumentation & control (I&C). A security control, or less formally, a security countermeasure can be any organizational, technical, or administrative measure that helps in reducing the risk imposed by a cybersecurity threat. The new IAEA NST036 lists more than 200 such countermeasures. NIST SP800-53 Revision 4 contains about 450 pages of security countermeasure descriptions, which are graded according to three levels of stringency. In order to facilitate and formalize the process of developing, precisely describing, distributing, and maintaining more complex security controls, the application security controls (ASC) concept is introduced by the new ISO/IEC 27034 multipart standard. An ASC is an extensible semiformal representation of a security control (extensible markup language or javascript object notation-based), which contains a set of mandatory and optional parts as well as possible links to other ASCs. A set of ASCs may be developed by one company and shipped together with a product of another company. ISO/IEC 27034-6 assumes that ASCs are developed by an organization or team specialized in security and that the ASCs are forwarded to customers for direct use or for integration into their own products or services. The distribution of ASCs is supported and formalized by the organization normative frameworks (ONFs) and application normative frameworks (ANFs) deployed in the respective organizational units. The maintenance and continuous improvement of ASCs is facilitated by the ONF process and ANF process. This paper will explore the applicability of these industry standards based ASC lifecycle concepts for the nuclear domain in line with IEC 62645, IEC 62859, and the upcoming IEC 63096. It will include results from an ongoing bachelor thesis and master thesis, mentored by two of the authors, as well as nuclear-specific deployment scenarios currently being evaluated by a team of cybersecurity Ph.D. candidates.
    • Download: (1.324Mb)
    • Show Full MetaData Hide Full MetaData
    • Get RIS
    • Item Order
    • Go To Publisher
    • Price: 5000 Rial
    • Statistics

      Development, Distribution, and Maintenance of Application Security Controls for Nuclear

    URI
    http://yetl.yabesh.ir/yetl1/handle/yetl/4252623
    Collections
    • Journal of Nuclear Engineering and Radiation Science

    Show full item record

    contributor authorWaedt, Karl
    contributor authorDing, Yongjian
    contributor authorCiriello, Antonio
    contributor authorLou, Xinxin
    date accessioned2019-02-28T11:05:46Z
    date available2019-02-28T11:05:46Z
    date copyright9/10/2018 12:00:00 AM
    date issued2018
    identifier issn2332-8983
    identifier otherners_004_04_041010.pdf
    identifier urihttp://yetl.yabesh.ir/yetl1/handle/yetl/4252623
    description abstractThe generic concept of security controls, as initially deployed in the information security domain, is gradually used in other business domains, including industrial security for critical infrastructure and cybersecurity of nuclear safety instrumentation & control (I&C). A security control, or less formally, a security countermeasure can be any organizational, technical, or administrative measure that helps in reducing the risk imposed by a cybersecurity threat. The new IAEA NST036 lists more than 200 such countermeasures. NIST SP800-53 Revision 4 contains about 450 pages of security countermeasure descriptions, which are graded according to three levels of stringency. In order to facilitate and formalize the process of developing, precisely describing, distributing, and maintaining more complex security controls, the application security controls (ASC) concept is introduced by the new ISO/IEC 27034 multipart standard. An ASC is an extensible semiformal representation of a security control (extensible markup language or javascript object notation-based), which contains a set of mandatory and optional parts as well as possible links to other ASCs. A set of ASCs may be developed by one company and shipped together with a product of another company. ISO/IEC 27034-6 assumes that ASCs are developed by an organization or team specialized in security and that the ASCs are forwarded to customers for direct use or for integration into their own products or services. The distribution of ASCs is supported and formalized by the organization normative frameworks (ONFs) and application normative frameworks (ANFs) deployed in the respective organizational units. The maintenance and continuous improvement of ASCs is facilitated by the ONF process and ANF process. This paper will explore the applicability of these industry standards based ASC lifecycle concepts for the nuclear domain in line with IEC 62645, IEC 62859, and the upcoming IEC 63096. It will include results from an ongoing bachelor thesis and master thesis, mentored by two of the authors, as well as nuclear-specific deployment scenarios currently being evaluated by a team of cybersecurity Ph.D. candidates.
    publisherThe American Society of Mechanical Engineers (ASME)
    titleDevelopment, Distribution, and Maintenance of Application Security Controls for Nuclear
    typeJournal Paper
    journal volume4
    journal issue4
    journal titleJournal of Nuclear Engineering and Radiation Science
    identifier doi10.1115/1.4039970
    journal fristpage41010
    journal lastpage041010-6
    treeJournal of Nuclear Engineering and Radiation Science:;2018:;volume( 004 ):;issue: 004
    contenttypeFulltext
    DSpace software copyright © 2002-2015  DuraSpace
    نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
    yabeshDSpacePersian
     
    DSpace software copyright © 2002-2015  DuraSpace
    نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
    yabeshDSpacePersian