Cyber Security and the Canadian Nuclear Industry a Canadian Regulatory Perspective



Similar documents
Operating Performance: Accident Management: Severe Accident Management Programs for Nuclear Reactors REGDOC-2.3.2

Seoul Communiqué 2012 Seoul Nuclear Security Summit

ROK s Assistance Programs for New comers

Cyber Security Design Methodology for Nuclear Power Control & Protection Systems. By Majed Al Breiki Senior Instrumentation & Control Manager (ENEC)

Nuclear Security Requires Cyber Security

Cyber Security for Nuclear Power Plants Matthew Bowman Director of Operations, ATC Nuclear IEEE NPEC Meeting July 2012

Security and Safeguards Considerations in Radioactive Waste Management. Canadian Nuclear Safety Commission

INDUSTRIAL CONTROL SYSTEMS CYBER SECURITY DEMONSTRATION

AN ANALYSIS OF TECHNICAL SECURITY CONTROL REQUIREMENTS FOR DIGITAL I&C SYSTEMS IN NUCLEAR POWER PLANTS

IAEA Safety Standards for Regulatory Activities

Announcement of a new IAEA Co-ordinated Research Programme (CRP)

Licensing Process for New Nuclear Power Plants in Canada. INFO-0756 (Revision 1)

Energy Cybersecurity Regulatory Brief

abstract NRC Headquarters United States Nuclear Regulatory Commission

Radiation and Environmental Protection at the CNSC

Safety Analysis Probabilistic Safety Assessment (PSA) for Nuclear Power Plants REGDOC-2.4.2

UAE Nuclear Power Programme : Status and Update

A DEVELOPMENT FRAMEWORK FOR SOFTWARE SECURITY IN NUCLEAR SAFETY SYSTEMS: INTEGRATING SECURE DEVELOPMENT AND SYSTEM SECURITY ACTIVITIES

Human Resource Management in Nuclear Safety

Cyber Security R&D (NE-1) and (NEET-4)

How To Strengthen Nuclear Security

OPC & Security Agenda

Options for Cyber Security. Reactors. April 9, 2015

Environmental Protection: Environmental Protection Policies, Programs and Procedures REGDOC-2.9.1

Technical Meeting on the Implications of the Fukushima Daiichi Accident on the Safety of Fuel Cycle Facilities. IAEA Headquarters Vienna, Austria

OPG READY TO DELIVER REFURBISHMENT OF DARLINGTON NUCLEAR STATION OPG also planning continued operation of Pickering Station

HEALTH CARE AND CYBER SECURITY:

Cyber Security Evaluation of the Wireless Communication for the Mobile Safeguard Systems in uclear Power Plants

Are you prepared to be next? Invensys Cyber Security

Ensuring Quality Going Down the Supply Chain

NSS 2014 UK NATIONAL PROGRESS REPORT. March 2014

Nuclear A Canadian Strategy for Energy, Jobs and Innovation

Cyber Security in a Nuclear Context

The State of Industrial Control Systems Security and National Critical Infrastructure Protection

Backgrounder Office of Public Affairs Telephone: 301/

Integrating Cyber Security into Nuclear Power Plant Safety Systems Design

Canadian Nuclear Safety Commission Nuclear Emergency Response Plan - Master Plan. May 2013 E-DOCS # v25

How To Write A Cyber Security Risk Analysis Model For Research Reactor

A CYBER SECURITY RISK ASSESSMENT FOR THE DESIGN OF I&C SYSTEMS IN NUCLEAR POWER PLANTS

A Regulatory Approach to Cyber Security

Regulatory Requirements and Licensing of OPG s DGR Project

CYBERSPACE SECURITY CONTINUUM

International Symposium on Nuclear Security

Deploying Firewalls Throughout Your Organization

Trends in Malware DRAFT OUTLINE. Wednesday, October 10, 12

Executive Director for Operations AUDIT OF NRC S CYBER SECURITY INSPECTION PROGRAM FOR NUCLEAR POWER PLANTS (OIG-14-A-15)

Safety Analysis for Nuclear Power Plants

Cyber Security. Protecting the UK water industry

The Role of Nuclear Knowledge Management

RENCEE SAFETY MARIES

Industrial Cyber Security Risk Manager. Proactively Monitor, Measure and Manage Cyber Security Risk

N-Dimension Solutions Cyber Security for Utilities

DeltaV System Cyber-Security

for Critical Infrastructure Protection Supervisory Control and Data Acquisition SCADA SECURITY ADVICE FOR CEOs

3 rd Review Meeting Convention on Nuclear Safety First Anniversary Report Status of Actions on Canada April 2006

Cyber Security Considerations in the Development of I&C Systems for Nuclear Power Plants

Protecting Organizations from Cyber Attack

International Safeguards Infrastructure Development

Honeywell Industrial Cyber Security Overview and Managed Industrial Cyber Security Services Honeywell Process Solutions (HPS) June 4, 2014

IBC Nuclear Energy Liability Exclusion. Explained

CYBERSECURITY EXAMINATION SWEEP SUMMARY

Spreading the Word on Nuclear Cyber Security

Presented by Evan Sylvester, CISSP

The Conceptualization and Development of Safeguards Implementation at the State Level

Institute for Science and International Security

Code of Conduct on the Safety and Security of Radioactive Sources

New Proposed Department of Energy Rules to Clarify and Update Part 810. By Shannon MacMichael and Michael Lieberman of Steptoe & Johnson, LLP 1

NRC Cyber Security Regulatory

i-pcgrid Workshop 2015 Cyber Security for Substation Automation The Jagged Line between Utility and Vendors

What is Cyber Liability

Best Practices in ICS Security for System Operators. A Wurldtech White Paper

MANAGEMENT SYSTEM FOR A NUCLEAR FACILITY

Cyber Security Implications of SIS Integration with Control Networks

Corporate Plan Summary to Operating Budget Summary Capital Budget Summary Atomic Energy of Canada Limited

Nuclear Plant Information Security A Management Overview

Unified Cyber Security Monitoring and Management Framework By Vijay Bharti Happiest Minds, Security Services Practice

Patch Management. Is it recommended to patch an Industrial Automation Control System and, if so, why? Siemens AG All Rights Reserved.

How To Protect Water Utilities From Cyber Attack

Protection from cyber threats

The State-of-the-State of Control System Cyber Security

KASPERSKY SECURITY INTELLIGENCE SERVICES. EXPERT SERVICES.

SCADA City of Raleigh. Martin Petherbridge, CPA, CIA Internal Audit Manager Shirley McFadden, CPA, CIA Senior Internal Auditor

SECURITY CONSIDERATIONS FOR LAW FIRMS

RC-17. Alejandro V. Nader National Regulatory Authority Montevideo - Uruguay

Capabilities for Cybersecurity Resilience

Beyond the Hype: Advanced Persistent Threats

Transcription:

Cyber Security and the Canadian Nuclear Industry a Canadian Regulatory Perspective Terry Jamieson Vice-President Technical Support Branch Canadian Nuclear Safety Commission August 11, 2015 www.nuclearsafety.gc.ca

Outline CNSC mission and mandate Modern cyber security threat Cyber security and modern industrial control system Regulatory approach to cyber security International perspectives Current and future challenges Closing remarks 2

Canadian Nuclear Safety Commission Regulates the use of nuclear energy and materials to protect health, safety, security and the environment, and to implement Canada s international commitments on the peaceful use of nuclear energy; and to disseminate objective scientific, technical and regulatory information to the public 3

CNSC presence Headquarters in Ottawa Five offices at nuclear power plants One site office at Chalk River Labs Four regional offices Staff: ~800 Resources: $140M (75% of costs recovered) Number of licensees: 2,500 Total number of licences: 3,300 Calgary Western Regional Office Saskatoon Uranium Mills and Mines Division Regional Office Gentilly-2 Point Lepreau Chalk River HQ Bruce Laval Eastern Regional Office Darlington Mississauga Southern Regional Office Pickering A and B 4

CNSC regulates all nuclear-related facilities and activities Imports and exports Controlled information Medical diagnostics Therapeutic Controlled material Refining Teletherapy Nuclear medicine and radiation therapy Controlled equipment Fuel fabrication Milling Brachytherapy Irradiators Mining Power reactor High power accelerators From cradle to grave Accelerators Waste Research reactors Radioisotope reactors Industrial applications Nuclear gauges Nuclear R&D test facilities Research and radioisotope production facilities 5

Nuclear power plants in Canada Darlington (4 unit station) Refurbishment of current 4-unit station scheduled to begin in 2016 Point Lepreau (single unit station) Refurbishment project completed and unit returned to service (late 2012) Gentilly-2 (single unit station) HQ permanently shut down facility in December 2012 Bruce (8 unit station) Refurbishments ongoing (2 of 8 units completed as of 2015) Pickering (6 of 8 units operating) Shutdown expected in 2020 6

In the old days Operators of process control systems (PCS) believed they were invulnerable to cyber attack for two main reasons: 1. PCS are isolated from the Internet. 2. PCS generally use proprietary protocols and specialized hardware, which are not compatible with common network protocols and the Internet. Source: The Vulnerability of Nuclear Facilities to Cyber Attack, B. Kesler, 2011 7

Cyber security and modern digital systems: the reality 2003: Slammer worm at Davis Besse Nuclear Power Plants (2003) in the US Siemens Programmable Logic Controller 2010: Stuxnet malware infiltrated Natanz (Iran) nuclear facility disabling over 1000 centrifuges 2014: Monju fast reactor (Japan) infected by malware (data integrity and compromise) Various theories as to its introduction Monju Sodium Fast Reactor Natanz Enrichment Facility, Iran And many more cyber incidents 8

And more recent incidents South Korean nuclear operator hacked amid cyber attack fears Operator begins two-day exercise after suspected hacker tweets information on Korea Hydro & Nuclear Power (KHNP) plants and staff The latest attack resulted in the leak of personal details of 10,000 KHNP workers, designs and manuals for at least two reactors, electricity flow charts and estimates of radiation exposure among local residents. There was no evidence, however, that the nuclear control systems had been hacked. 9

What do we mean by cyber security and the nuclear industry? Protect digital assets that perform the functions of systems important to nuclear safety, security, emergency preparedness and international safeguards from cyber attack Digital asset: A subcomponent of a system that consists of or contains a digital device, computer or communication system or network, and information stored in the subcomponent. 10

Scope of cyber security program nuclear facilities Industrial Control System for nuclear safety Physical protection systems Annunciation, communication systems for emergency preparedness / response and international safeguards systems 11

Cyber threats What are the CNSC and nuclear industry doing? Since 2008, the CNSC has engaged major nuclear facilities in Canada in defining requirements of and implementing programs for cyber security Regulations updated, licence conditions added, modern standards developed CSA N290.7 Cyber Security for Nuclear Power Plants and Small Reactor Facilities (published December 2014) Site cyber security inspections by CNSC staff began in January 2015 for Canadian Nuclear Power Plants 12

CSA N290.7 security controls cyber security for nuclear facilities CSA N290.7 will form the cornerstone of CNSC s regulatory framework requirements N290.7 comprises technical, operational and management control requirements: Technical - executed through non-human mechanisms Operational - executed through human mechanisms Management - risk management and general policies including procurement strategies 13

Cyber defensive architecture at NPPs Cyber security focuses on defence in depth (similar to traditional principles of safety) Data flow restricted as per diagram (i.e., typically from higher to lower security levels) Defensive architecture is implemented by establishing the logical and physical boundaries 14

State of cyber defensive architecture in Canadian NPPs Networks responsible for safety systems, process control systems, physical security systems and business systems are segregated Safety system network connected to process system network via one-way communication device (no possibility of bidirectional information flow) Administrative and mechanical controls prevent unauthorized access (portable mobile devices, etc.) to safety, process control and physical security computers Licensees have robust cyber security measures in place that have been verified by staff 15

Cyber security the importance of national/international collaboration Domestically, CNSC works with Public Safety Canada / Canadian Cyber Incident Response Centre, Natural Resources Canada, Communication Security Establishment Canada and others Internationally, bilateral work with the US Nuclear Regulatory Commission has greatly advanced knowledge CNSC contributes significantly to the work at International Atomic Energy Agency (IAEA) in developing security series documents Nuclear Security Series (NSS) 17 Computer Security at Nuclear Facilities, Conducting Cyber Security Assessments for Nuclear Facilities and many more 16

IAEA and cyber security (cont.) International Physical Protection Advisory Service (IPPAS) missions Module on computer (cyber) security Canada will host an IPPAS mission in 2015! Training Offered by international cyber experts from nuclear industry to host countries (operators, regulators, others) Production of Nuclear Security Series publications to assist IAEA member states with program implementation and improvements 17

Challenges to managing and regulating cyber security in the nuclear industry Rapid evolution of cyber threat vectors and instruments nuclear plants seen as a target of interest Challenges of regulating across global supply chain counterfeit, fraudulent, suspect items cases well publicized Increased sophistication of cyber attacks makes detection and prevention increasingly difficult Knowledge and resource limitations (cyber expertise): industry and regulator State of board/senior executive oversight on cyber security matters is still evolving 18

Conclusions Canadian nuclear power plants have robust comprehensive cyber security programs in place CNSC is evolving its regulatory approaches to meet the needs of the proponents now and in the future while ensuring high levels of safety are assured Cyber security requirements need to be embedded into every phase of the regulatory review process for I&C systems Cyber security (like physical security) is only as strong as the weakest link 19

Thank You Any Questions? nuclearsafety.gc.ca facebook.com/canadiannuclearsafetycommission twitter.com/cnsc_ccsn youtube.com/cnscccsn 20