Current practices and challenges in industrial control organizations regarding information security incident management – Does size matter? Information security incident management in large and small industrial control organizations
Maria Bartnes Line,
Inger Anne Tøndel and
Martin G. Jaatun
International Journal of Critical Infrastructure Protection, 2016, vol. 12, issue C, 12-26
Abstract:
This paper reports on the results of an interview study that surveyed current practices regarding information security incident management in small and large distribution system operators (DSOs) in the Norwegian electric power industry. The findings indicate that current risk perception and preparedness are low, especially among small electricity distribution system operators. Further, small distribution system operators rely heavily on their suppliers should incidents occur. At the same time, small distribution system operators are confident that they can handle the worst-case scenarios. This paper documents current perceptions and discusses the extent to which they are likely to hold given the transition towards smart electric grids. Several recommendations are provided based on the findings and the accompanying discussion. In particular, small distribution system operators should strengthen the collaboration with their information technology (IT) suppliers and other small distribution system operators. Furthermore, distribution system operators in general should establish written documentation of procedures, perform preparedness exercises and improve detection capabilities in control systems.
Keywords: Industrial control systems; Electric power distribution; Norway; Information security; Incident management; Incident response (search for similar items in EconPapers)
Date: 2016
References: View references in EconPapers View complete reference list from CitEc
Citations: View citations in EconPapers (2)
Downloads: (external link)
http://www.sciencedirect.com/science/article/pii/S1874548215000815
Full text for ScienceDirect subscribers only
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:eee:ijocip:v:12:y:2016:i:c:p:12-26
DOI: 10.1016/j.ijcip.2015.12.003
Access Statistics for this article
International Journal of Critical Infrastructure Protection is currently edited by Leon Strous
More articles in International Journal of Critical Infrastructure Protection from Elsevier
Bibliographic data for series maintained by Catherine Liu ().