DocumentCode :
146870
Title :
Information Security Incident Management: Planning for Failure
Author :
Line, Maria B. ; Tondel, Inger Anne ; Jaatun, Martin Gilje
Author_Institution :
Dept. of Telematics, Norwegian Univ. of Sci. & Technol. (NTNU), Trondheim, Norway
fYear :
2014
fDate :
12-14 May 2014
Firstpage :
47
Lastpage :
61
Abstract :
This paper reports on an interview study on information security incident management that has been conducted in organizations operating industrial control systems that are highly dependent on conventional IT systems. Six distribution service operators from the power industry have participated in the study. We have investigated current practice regarding planning and preparation activities for incident management, and identified similarities and differences between the two traditions of conventional IT systems and industrial control systems. The findings show that there are differences between the IT and ICS disciplines in how they perceive an information security incident and how they plan and prepare for responding to such. The completeness of documented plans and procedures for incident management varies. Where documentation exists, this is in general not well-established throughout the organization. Training exercises with specific focus on information security are rarely performed. There is a need to create amore unified approach to information security incident management in order for the power industry to be sufficiently prepared to meet the challenges posed by Smart Grids in the near future.
Keywords :
control engineering computing; electricity supply industry; failure analysis; industrial control; power distribution; power engineering computing; security of data; distribution service operators; documented plans; failure planning; incident management preparation activities; information security incident management; organization operating industrial control systems; power industry; smart grids; Control systems; ISO standards; Information security; Interviews; Organizations; Training; Incident management; Industrial control systems; Information security; Information technology; Power industry; Smart grids;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
IT Security Incident Management & IT Forensics (IMF), 2014 Eighth International Conference on
Conference_Location :
Munster
Print_ISBN :
978-1-4799-4330-2
Type :
conf
DOI :
10.1109/IMF.2014.10
Filename :
6824081
Link To Document :
بازگشت