1.7 Cybersecurity of Power Facilities: Past, Present, and Future
89
This is true if intruder is a human being. And in case when “violator” is a hardware
Trojan, it is difficult for the time being even set a task because it is actually impossible
to have it actuated—experts so far know nothing about such solutions.
The effects of technological audit have sufficient value “as they are” as unbiased and independent (in case of outside audit) assessment of immunity of information system but they are also essential for analyzing information security risks
and, therefore for efficient information security management at the facility under
protection.
Unfortunately the procedure of performing technological audit of IT security is
virtually not perfected and made formal. Standards are set only for some general
principles of audit stipulated, for instance, in ESEC document (EuropeanSecurityExpertiseCentreSecurityAudit(Security Audit).
Surely there exist corporate standards and special-purpose procedures applied
in some particular companies or for specific Information Systems, but for general
guidelines and instructions and practically applied multi-purpose procedures do not
exist and this is yet another vulnerability in cybersecurity systems.
Consequently nowadays the most popular approach to Technological Audit as per
generally accepted definitions is tested for intrusion of “malicious person” (exhibitive
demonstration of intruder’s actions) and “old fashioned” well-established audit of
information security (analysis of information system configuration parameters and
application of vulnerability scanner).
1.7.4 Assurance of Cybersecurity of Power Facilities
of the USA
The experts are of the opinion that the greatest progress in assurance of cybersecurity
of power facilities is attained in the USA. [7].
Energy industry is a collection of generating facilities (power plants), distributing
and transforming facilities (transforming substations), power supply lines, computerbased management and monitoring systems, equipment for electric power consumers.
As per the classification adopted in the USA oil and gas infrastructure also makes
an integral part of the energy industry.
The USA special services have accumulated abundant statistics data concerning
cyberattacks at the facilities of national infrastructure where as it turned out
energy industry was the top-priority goal disruption of the operation of the entire
infrastructure and economics of the country.
Thus annually there are 18–20 thousands of attempts detected to enter the information networks of energy industry which makes in average 35% of CYBERATTACKS AT ALL FACILITIES OF NATIONAL INFRASTRUCTURE. For instance,
in December 2007 computer hackers managed to gain access to power networks in
some areas of the USA and neighboring countries, at least in one of these cases it
resulted in black-outs in several cities.
Précédent

- 111/839

Suivant