Planning the Selection and Assignment of Security Forensics CountermeasuresSource: Journal of Nuclear Engineering and Radiation Science:;2018:;volume( 004 ):;issue: 004::page 41008DOI: 10.1115/1.4040650Publisher: The American Society of Mechanical Engineers (ASME)
Abstract: Cybersecurity incidents are stressful, complex in nature, and are frequently not systematically considered in daily tasks. When correctly managed, operational readiness procedures ensure the availability of data required to successfully and quickly recover from a security incident, while lessening the adverse effect. Therefore, protective measures, such as implementation of data diodes, are playing an essential role in defending instrumentation and control (I&C) systems. In addition, applicability of the newest forensic and digital evidence-related standards to the nuclear domain is being evaluated. Results of such evaluation are being considered in the three-dimensional and two-dimensional modeling of cybersecurity relevant assets. The development of the new IEC 63096, downstream standard of IEC 62645, will also support the proposed evaluation and modeling. However, IEC 63096 covers not only forensic and incident management-related security controls but also a broad range of cybersecurity controls. This paper will further explore the security degree-specific selection and overall assignment of forensic-related security controls for the nuclear domain. Results from ongoing prototype developments will be used to demonstrate possible alternative selections and assignments, along with their contribution to different security metrics.
|
Show full item record
| contributor author | Bajramovic, Edita | |
| contributor author | Bochtler, Jürgen | |
| contributor author | Zid, Ines Ben | |
| contributor author | Lainer, Andreas | |
| date accessioned | 2019-02-28T11:05:19Z | |
| date available | 2019-02-28T11:05:19Z | |
| date copyright | 9/10/2018 12:00:00 AM | |
| date issued | 2018 | |
| identifier issn | 2332-8983 | |
| identifier other | ners_004_04_041008.pdf | |
| identifier uri | http://yetl.yabesh.ir/yetl1/handle/yetl/4252544 | |
| description abstract | Cybersecurity incidents are stressful, complex in nature, and are frequently not systematically considered in daily tasks. When correctly managed, operational readiness procedures ensure the availability of data required to successfully and quickly recover from a security incident, while lessening the adverse effect. Therefore, protective measures, such as implementation of data diodes, are playing an essential role in defending instrumentation and control (I&C) systems. In addition, applicability of the newest forensic and digital evidence-related standards to the nuclear domain is being evaluated. Results of such evaluation are being considered in the three-dimensional and two-dimensional modeling of cybersecurity relevant assets. The development of the new IEC 63096, downstream standard of IEC 62645, will also support the proposed evaluation and modeling. However, IEC 63096 covers not only forensic and incident management-related security controls but also a broad range of cybersecurity controls. This paper will further explore the security degree-specific selection and overall assignment of forensic-related security controls for the nuclear domain. Results from ongoing prototype developments will be used to demonstrate possible alternative selections and assignments, along with their contribution to different security metrics. | |
| publisher | The American Society of Mechanical Engineers (ASME) | |
| title | Planning the Selection and Assignment of Security Forensics Countermeasures | |
| type | Journal Paper | |
| journal volume | 4 | |
| journal issue | 4 | |
| journal title | Journal of Nuclear Engineering and Radiation Science | |
| identifier doi | 10.1115/1.4040650 | |
| journal fristpage | 41008 | |
| journal lastpage | 041008-9 | |
| tree | Journal of Nuclear Engineering and Radiation Science:;2018:;volume( 004 ):;issue: 004 | |
| contenttype | Fulltext |