A Cyber Incident Response and Recovery Framework to Support Operators of Industrial Control Systems

被引:8
|
作者
Staves, Alexander [1 ]
Anderson, Tom [1 ]
Balderstone, Harry [1 ]
Green, Benjamin [1 ]
Gouglidis, Antonios [1 ]
Hutchison, David [1 ]
机构
[1] Univ Lancaster, Sch Comp & Commun, Lancaster LA1 4WA, England
基金
英国工程与自然科学研究理事会;
关键词
ICS; CNI; OT; Cyber Security; Cyber Incident; Response and Recovery; SECURITY; MANAGEMENT;
D O I
10.1016/j.ijcip.2021.100505
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the last decade, we have seen a shift in the focus of cyber attacks, moving from traditional IT systems to include more specialised Industrial Control Systems (ICS), often found within Critical National Infrastructure (CNI). Despite a push from governments to introduce appropriate legislation and guidance for such systems, operators of ICS and CNI still face multiple challenges in their cyber incident response and recovery capabilities, a theme that is often viewed as a last line of defence in minimising the impact of cyber attacks. This paper provides the following contributions: Firstly, we analyse existing standards and guidelines within cyber incident response and recovery. This analysis provides a structure on key response and recovery phases, a foundational understanding of associated requirements for these, and identifies challenges that could affect the quality of in-practice response and recovery capabilities. Using this analysis as a baseline, we examine how response and recovery processes are currently undertaken in practice through engagement with UK-based CNI operators and regulators. Secondly, as a starting point towards improving identified challenges in existing standards and guidelines and their use in practice, we propose a framework, built using the outputs identified from the document analysis and the stakeholder engagement, for use by operators to support them in assessing and improving their response and recovery capabilities.
引用
收藏
页数:24
相关论文
共 50 条
  • [1] A Framework for Incident Response in Industrial Control Systems
    Schlegel, Roman
    Hristova, Ana
    Obermeier, Sebastian
    2015 12TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS (ICETE), VOL 4, 2015, : 178 - 185
  • [2] An Industrial Control Systems Incident Response Decision Framework
    He, Ying
    Maglaras, Leandros A.
    Janicke, Helge
    Jones, Kevin
    2015 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2015, : 761 - 762
  • [3] The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework
    Smith, Richard
    Janicke, Helge
    He, Ying
    Ferra, Fenia
    Albakri, Adham
    COMPUTERS & SECURITY, 2021, 109
  • [4] A hybrid cyber defense framework for reconnaissance attack in industrial control systems
    Qin, Xingsheng
    Jiang, Frank
    Dong, Chengzu
    Doss, Robin
    COMPUTERS & SECURITY, 2024, 136
  • [5] Cyber Resilience Framework for Industrial Control Systems: Concepts, Metrics, and Insights
    Haque, Md Ariful
    De Teyou, Gael Kamdem
    Shetty, Sachin
    Krishnappa, Bheshaj
    2018 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS (ISI), 2018, : 25 - 30
  • [6] A comparative framework for cyber threat modelling: case of healthcare and industrial control systems
    Balogun, Taofeek Mobolarinwa
    Bahsi, Hayretdin
    Keskin, Omer F.
    Tatar, Unal
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2023, 19 (05) : 405 - 431
  • [7] Cyber Security for Industrial Control Systems
    Cunningham, Steve
    POWER ENGINEERING, 2011, 115 (11) : 142 - +
  • [8] Cyber Trends in Industrial Control Systems
    Trifonov, Roumen
    Tsochev, Georgi
    Manolov, Slavcho
    Yoshinov, Radoslav
    Pavlova, Galya
    25TH INTERNATIONAL CONFERENCE ON CIRCUITS, SYSTEMS, COMMUNICATIONS AND COMPUTERS (CSCC 2021), 2021, : 41 - 45
  • [9] A Prototype Forensic Toolkit for Industrial-Control-Systems Incident Response
    Carr, Nicholas B.
    Rowe, Neil C.
    CYBER SENSING 2015, 2015, 9458
  • [10] An evaluation framework for industrial control system cyber incidents
    Firoozjaei, Mandi Daghmehchi
    Mahmoudyar, Nastaran
    Baseri, Yaser
    Ghorbani, Ali A.
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURE PROTECTION, 2022, 36