• DocumentCode
    2431973
  • Title

    Risk assessment on Instrumentation and Control Network Security Management System for nuclear power plants

  • Author

    Chen, Yu-Jen ; Liao, Gen-Yih ; Cheng, Tsung-Chieh

  • Author_Institution
    Dept. of Inf. Manage., Chang Gung Univ., Taoyuan, Taiwan
  • fYear
    2009
  • fDate
    5-8 Oct. 2009
  • Firstpage
    261
  • Lastpage
    264
  • Abstract
    Modern nuclear power plants have been adopting open standards in their digital networks to enhance extensibility and interoperability. This also opens another possibility for an attacker to intrude into the networks. To prevent digital networks from being attacked, the U.S. Nuclear Regulatory Commission provides guidelines regarding achieving high reliability and design quality requirements. However, quality assurance in hardware/software components is not sufficient to ensure the security of the overall network system. Security policies and sound system administration are also indispensable factors to rigid security. To enhance the level of security protection in the Taiwan nuclear power plants, this investigation aims at the scope of digital instrumentation and control networks in one of the nuclear power plants in Taiwan, takes advantages of the guidelines of RG 1.152, follows the network security standard of NUREG-0800 Appendix 7.1-D and attempts to plan and design an ISMS based on the methodology of BS7799. The result of this investigation will be able to help nuclear power plants to organize and establish the first phase of Instrumentation and Control Network Security Management System (ICNSMS), which thinks over information and network security issues in a comprehensive perspective.
  • Keywords
    SCADA systems; nuclear power stations; power engineering computing; quality assurance; risk management; security of data; NUREG-0800 Appendix 7.1-D; Taiwan nuclear power plants; U.S. Nuclear Regulatory Commission; control network security management system; digital networks; information security management system; interoperability; network security standard; quality assurance; risk assessment; sound system administration; Control systems; Energy management; Guidelines; Information security; Instruments; Power generation; Power system management; Power system reliability; Power system security; Risk management; Information Security Management System (ISMS); Risk Assessment; Vulnerability Analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security Technology, 2009. 43rd Annual 2009 International Carnahan Conference on
  • Conference_Location
    Zurich
  • Print_ISBN
    978-1-4244-4169-3
  • Electronic_ISBN
    978-1-4244-4170-9
  • Type

    conf

  • DOI
    10.1109/CCST.2009.5335526
  • Filename
    5335526