DocumentCode
2431973
Title
Risk assessment on Instrumentation and Control Network Security Management System for nuclear power plants
Author
Chen, Yu-Jen ; Liao, Gen-Yih ; Cheng, Tsung-Chieh
Author_Institution
Dept. of Inf. Manage., Chang Gung Univ., Taoyuan, Taiwan
fYear
2009
fDate
5-8 Oct. 2009
Firstpage
261
Lastpage
264
Abstract
Modern nuclear power plants have been adopting open standards in their digital networks to enhance extensibility and interoperability. This also opens another possibility for an attacker to intrude into the networks. To prevent digital networks from being attacked, the U.S. Nuclear Regulatory Commission provides guidelines regarding achieving high reliability and design quality requirements. However, quality assurance in hardware/software components is not sufficient to ensure the security of the overall network system. Security policies and sound system administration are also indispensable factors to rigid security. To enhance the level of security protection in the Taiwan nuclear power plants, this investigation aims at the scope of digital instrumentation and control networks in one of the nuclear power plants in Taiwan, takes advantages of the guidelines of RG 1.152, follows the network security standard of NUREG-0800 Appendix 7.1-D and attempts to plan and design an ISMS based on the methodology of BS7799. The result of this investigation will be able to help nuclear power plants to organize and establish the first phase of Instrumentation and Control Network Security Management System (ICNSMS), which thinks over information and network security issues in a comprehensive perspective.
Keywords
SCADA systems; nuclear power stations; power engineering computing; quality assurance; risk management; security of data; NUREG-0800 Appendix 7.1-D; Taiwan nuclear power plants; U.S. Nuclear Regulatory Commission; control network security management system; digital networks; information security management system; interoperability; network security standard; quality assurance; risk assessment; sound system administration; Control systems; Energy management; Guidelines; Information security; Instruments; Power generation; Power system management; Power system reliability; Power system security; Risk management; Information Security Management System (ISMS); Risk Assessment; Vulnerability Analysis;
fLanguage
English
Publisher
ieee
Conference_Titel
Security Technology, 2009. 43rd Annual 2009 International Carnahan Conference on
Conference_Location
Zurich
Print_ISBN
978-1-4244-4169-3
Electronic_ISBN
978-1-4244-4170-9
Type
conf
DOI
10.1109/CCST.2009.5335526
Filename
5335526
Link To Document