• DocumentCode
    3780177
  • Title

    Assessing information security risks of AMI: What makes it so difficult?

  • Author

    Inger Anne T?ndel;Maria B. Line;Gorm Johansen

  • Author_Institution
    SINTEFICT, Trondheim, Norway
  • fYear
    2015
  • Firstpage
    56
  • Lastpage
    63
  • Abstract
    A rich selection of methods for information security risk assessments exist, but few studies evaluate how such methods are used, their perceived ease-of-use, and whether additional support is needed. Distribution system operators (DSOs) find it difficult to perform information security risk assessments of Advanced Metering Infrastructure (AMI). We have performed a case study in order to identify these difficulties and the reasons for them. Our findings indicate that the risk assessment method in itself is not the main challenge. The difficulties regard competence; more specifically, insight in possible information security threats and vulnerabilities, being able to foresee consequences, and making educated guesses about probability. Improved guidelines can be a valuable aid, but including information security experts as participants in the process is even more important.
  • Keywords
    "Risk management","Guidelines","Information security","IEC Standards","ISO Standards","Privacy"
  • Publisher
    ieee
  • Conference_Titel
    Information Systems Security and Privacy (ICISSP), 2015 International Conference on
  • Type

    conf

  • Filename
    7509930