Javascript must be enabled to continue!
Development, Distribution and Maintenance of Application Security Controls for Nuclear
View through CrossRef
The generic concept of Security Controls, as initially deployed in the information security domain, is gradually used in other business domains, including industrial security for critical infrastructure and cybersecurity of nuclear safety I&C. A Security Control, or less formally, a security countermeasure can be any organizational, technical or administrative measure that helps in reducing the risk imposed by a cybersecurity threat. The new IAEA NST036 lists more than 200 such countermeasures. NIST SP800-53 Rev. 4 contains about 450 pages of security countermeasure descriptions, which are graded according to three levels of stringency. In order to facilitate and formalize the process of developing, precisely describing, distributing and maintaining more complex security controls, the Application Security Controls (ASC) concept is introduced by the new ISO/IEC 27034 multipart standard. An ASC is an extensible semi-formal representation of a security control (e.g. XML or JSON-based), which contains a set of mandatory and optional parts as well as possible links to other ASCs. A set of Application Security Controls may be developed by one company and shipped together with a product of another company.
ISO/IEC 27034-6 assumes that ASCs are developed by an organization or team specialized in security and that the ASCs are forwarded to customers for direct use or for integration into their own products or services.
The distribution of ASCs is supported and formalized by the Organization Normative Frameworks (ONF) and Application Normative Frameworks (ANF) deployed in the respective organizational units.
The maintenance and continuous improvement of ASCs is facilitated by the ONF Process and ANF Process.
This paper will explore the applicability of these industry standards based ASC lifecycle concepts for the nuclear domain in line with IEC 62645, IEC 62859 and the up-coming IEC 63096. It will include results from an ongoing bachelor thesis and master thesis, mentored by two of the authors, as well as nuclear specific deployment scenarios currently being evaluated by a team of cybersecurity PhD candidates.
American Society of Mechanical Engineers
Title: Development, Distribution and Maintenance of Application Security Controls for Nuclear
Description:
The generic concept of Security Controls, as initially deployed in the information security domain, is gradually used in other business domains, including industrial security for critical infrastructure and cybersecurity of nuclear safety I&C.
A Security Control, or less formally, a security countermeasure can be any organizational, technical or administrative measure that helps in reducing the risk imposed by a cybersecurity threat.
The new IAEA NST036 lists more than 200 such countermeasures.
NIST SP800-53 Rev.
4 contains about 450 pages of security countermeasure descriptions, which are graded according to three levels of stringency.
In order to facilitate and formalize the process of developing, precisely describing, distributing and maintaining more complex security controls, the Application Security Controls (ASC) concept is introduced by the new ISO/IEC 27034 multipart standard.
An ASC is an extensible semi-formal representation of a security control (e.
g.
XML or JSON-based), which contains a set of mandatory and optional parts as well as possible links to other ASCs.
A set of Application Security Controls may be developed by one company and shipped together with a product of another company.
ISO/IEC 27034-6 assumes that ASCs are developed by an organization or team specialized in security and that the ASCs are forwarded to customers for direct use or for integration into their own products or services.
The distribution of ASCs is supported and formalized by the Organization Normative Frameworks (ONF) and Application Normative Frameworks (ANF) deployed in the respective organizational units.
The maintenance and continuous improvement of ASCs is facilitated by the ONF Process and ANF Process.
This paper will explore the applicability of these industry standards based ASC lifecycle concepts for the nuclear domain in line with IEC 62645, IEC 62859 and the up-coming IEC 63096.
It will include results from an ongoing bachelor thesis and master thesis, mentored by two of the authors, as well as nuclear specific deployment scenarios currently being evaluated by a team of cybersecurity PhD candidates.
Related Results
Maintenance optimization for marine mechanical systems
Maintenance optimization for marine mechanical systems
This article proposes a stochastic technique for determining the optimal maintenance policy for marine mechanical systems. The optimal maintenance policy output includes the averag...
Optimizing maintenance logistics on offshore platforms with AI: Current strategies and future innovations
Optimizing maintenance logistics on offshore platforms with AI: Current strategies and future innovations
Offshore platforms are vital assets for the oil and gas industry, serving as the primary facilities for exploration, extraction, and processing. Maintenance logistics plays a cruci...
Nuclear Security: A Synonym of Physical Protection or A Component of Nuclear and Radiation Safety?
Nuclear Security: A Synonym of Physical Protection or A Component of Nuclear and Radiation Safety?
The paper considers the question of implementing nuclear security into the area of nuclear energy use in Ukraine. The comparative analysis of international conventions, IAEA recomm...
Study on Nuclear Safety Management Based on Multiple Nuclear Power Plants Experience Feedback Management
Study on Nuclear Safety Management Based on Multiple Nuclear Power Plants Experience Feedback Management
Abstract
Nuclear power plant experience feedback management includes event reporting, screening, analysis, corrective action management and assessment. In the early ...
Are Cervical Ribs Indicators of Childhood Cancer? A Narrative Review
Are Cervical Ribs Indicators of Childhood Cancer? A Narrative Review
Abstract
A cervical rib (CR), also known as a supernumerary or extra rib, is an additional rib that forms above the first rib, resulting from the overgrowth of the transverse proce...
Research on Scenarios and Development Paths of China’s Commercial Closed Nuclear Fuel Cycle
Research on Scenarios and Development Paths of China’s Commercial Closed Nuclear Fuel Cycle
Abstract
China implements the established policy of closed nuclear fuel cycle for the sustainable development of nuclear power. However, there seems no feasible deve...
Public budget security administration: development of primary mechanisms
Public budget security administration: development of primary mechanisms
The current state of public administration of budget security indicates its actual absence. With the extremely important role of budget security, both in the life of the country as...
Nuclear security policy in the context of counterterrorism in Cambodia
Nuclear security policy in the context of counterterrorism in Cambodia
The risk of a nuclear or dirty bomb attack by terrorists is one of the most urgent and threatening dangers. The Cambodian national strategy to combat weapons of mass destruction (W...

