• DocumentCode
    183186
  • Title

    Using integrated system theory approach to assess security for SCADA systems cyber security for critical infrastructures: A pilot study

  • Author

    Ismail, Sabir ; Sitnikova, Elena ; Slay, Jill

  • Author_Institution
    Sch. of Inf. Technol. & Math. Sci., Univ. of South Australia, Adelaide, SA, Australia
  • fYear
    2014
  • fDate
    19-21 Aug. 2014
  • Firstpage
    1000
  • Lastpage
    1006
  • Abstract
    The security of system that monitor critical infrastructure are vital. The possibility of critical infrastructure services being disrupted would have a significant impact on the wider society as it involves energy, water, gas, transport, and many more utilities. This paper examines critical infrastructure and the system that monitors and controls critical services. It also measures the information security aspects of the system by adopting Integrated System Theory which covers the importance of enforcing cyber security policies, assessing and managing risks, internal control-management, technical and process controls and information auditing. This study was initiated by preliminary interviews with experts from different countries on the themes of awareness, compliance and assessments, and measures and controls. Subsequently, a pilot study was done by conducting online surveys to practitioners from different countries, and several different critical infrastructure sectors on the existing information security practices in their organisations. We examined the constituents of existing policies, and controls implemented by the organisations. The conclusion was made the pilot study would provide a good basis for estimating and measuring the security awareness and controls implemented at the organisation level.
  • Keywords
    SCADA systems; critical infrastructures; risk management; security of data; SCADA system cyber security; critical infrastructure monitoring; critical infrastructure sectors; cyber security policies; information security aspects; integrated system theory approach; internal control-management; process controls; risk management; security awareness; Government; Information security; Interviews; Monitoring; Risk management; SCADA systems; Contingency Management; Critical Infrastructure; Cyber Security; Integrated System Theory; Internal Control; Risk Management; SCADA Systems; Security Policy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Fuzzy Systems and Knowledge Discovery (FSKD), 2014 11th International Conference on
  • Conference_Location
    Xiamen
  • Print_ISBN
    978-1-4799-5147-5
  • Type

    conf

  • DOI
    10.1109/FSKD.2014.6980976
  • Filename
    6980976