IAEA 2015 INTERNATIONAL CONFERENCE ON COMPUTER SECURITY IN A NUCLEAR WORLD



Similar documents
Steven A. Arndt Division of Engineering Office of Nuclear Reactor Regulation

MDEP Generic Common Position No DICWG 02

41 T Korea, Rep T Netherlands T Japan E Bulgaria T Argentina T Czech Republic T Greece 50.

Foreign Obligations Notification Process

International Training Course on Preventive and Protective Measures against Insider Threats at Nuclear Facilities PROSPECTUS

World Consumer Income and Expenditure Patterns

Announcement of a new IAEA Co-ordinated Research Programme (CRP)

Emerging Trends and The Role of Standards in Future Health Systems. Nation-wide Healthcare Standards Adoption: Working Groups and Localization

GE Grid Solutions. Providing solutions that keep the world energized Press Conference Call Presentation November 12, Imagination at work.

Appendix 1: Full Country Rankings

BT Premium Event Call and Web Rate Card

The World Nuclear Industry Status Report 2014

DSV Air & Sea, Inc. Aerospace Sector. DSV Air & Sea, Inc. Aerospace

Digital Preservation Services

The Status of Nuclear Power in the World Before and After Fukushima

Report on Government Information Requests

NUCLEAR OPERATOR LIABILITY AMOUNTS & FINANCIAL SECURITY LIMITS

Foreign Taxes Paid and Foreign Source Income INTECH Global Income Managed Volatility Fund

COST Presentation. COST Office Brussels, ESF provides the COST Office through a European Commission contract

NUCLEAR OPERATOR LIABILITY AMOUNTS & FINANCIAL SECURITY LIMITS

How many students study abroad and where do they go?

Triple-play subscriptions to rocket to 400 mil.

SunGard Best Practice Guide

The value of accredited certification

Supported Payment Methods

Accuracy counts! SENSORS WITH ANALOG OUTPUT

Higher education institutions as places to integrate individual lifelong learning strategies

ORGANISATION FOR ECONOMIC CO-OPERATION AND DEVELOPMENT

Region Country AT&T Direct Access Code(s) HelpLine Number. Telstra: Optus:

Supported Payment Methods

Reporting practices for domestic and total debt securities

Electricity Disasters and Roles of Electrical Safety Inspection Associations in Japan

International Organization for Standardization TC 215 Health Informatics. Audrey Dickerson, RN MS ISO/TC 215 Secretary

Plutonium Watch. Tracking Plutonium Inventories by David Albright and Kimberly Kramer. July 2005, Revised August 2005

The world in MDGs : ICT revolution and remaining gaps *

Customer Support. Superior Service Solutions for Your Laser and Laser Accessories. Superior Reliability & Performance

Hong Kong s Health Spending 1989 to 2033

Report on Government Information Requests

Make the invisible visible! SENSORS WITH EXCELLENT BACKGROUND SUPPRESSION

Update on ISO TC 265 Transportation and

Status of the ISO Asset Management System Standard

GfK PURCHASING POWER INTERNATIONAL

Sybase Solutions for Healthcare Adapting to an Evolving Business and Regulatory Environment

Bio-Rad Laboratories. QC data management solutions. Introduce Your Laboratory to a Whole New World of Unity Data Management Solutions

NSS 2014 UK NATIONAL PROGRESS REPORT. March 2014

UNCITRAL legislative standards on electronic communications and electronic signatures: an introduction

Audio Conferencing Service Comprehensive Telecommunications Services Group Number Award Number Contract Number PS63110

ARE ENTREPRENEURS BORN OR MADE? AMWAY GLOBAL ENTREPRENEURSHIP REPORT ITALY AND UNITED STATES IN COMPARISON

Table 1: TSQM Version 1.4 Available Translations

Fall 2015 International Student Enrollment

Global Dialing Comment. Telephone Type. AT&T Direct Number. Access Type. Dial-In Number. Country. Albania Toll-Free

TOWARDS PUBLIC PROCUREMENT KEY PERFORMANCE INDICATORS. Paulo Magina Public Sector Integrity Division

TRANSFERS FROM AN OVERSEAS PENSION SCHEME

Exhibitor Product Groups

EMEA BENEFITS BENCHMARKING OFFERING

Motion Graphic Design Census. 10 hrs. motiongraphicdesigncensus.org. 9 hrs.

Guidelines for Applicants: Advanced Training Course

Trends in Digitally-Enabled Trade in Services. by Maria Borga and Jennifer Koncz-Bruner

How To Get A New Phone System For Your Business

ISO/TC 258, ISO Technical Committee for Project, Program, and Portfolio Management, convenes in Pretoria, South Africa

Digital TV Research. Research-v3873/ Publisher Sample

Global AML Resource Map Over 2000 AML professionals

Dividends Tax: Summary of withholding tax rates per South African Double Taxation Agreements currently in force Version: 2 Updated:

2014 UXPA Salary Survey. November 2014

Visa Information 2012

Delegation in human resource management

List of tables. I. World Trade Developments

DIR Contract #DIR-TSO-2610 Amendment #1 Appendix C Price Index

When was UNCITRAL established? And why?

Agenda. Company Platform Customers Partners Competitive Analysis

Configuring DHCP for ShoreTel IP Phones

Building on +60 GW of experience. Track record as of 31 December 2013

PERMANENT AND TEMPORARY WORKERS

E-Seminar. Financial Management Internet Business Solution Seminar

Data Modeling & Bureau Scoring Experian for CreditChex

Electricity, Gas and Water: The European Market Report 2014

CMMI for SCAMPI SM Class A Appraisal Results 2011 End-Year Update

PUBLIC VS. PRIVATE HEALTH CARE IN CANADA. Norma Kozhaya, Ph.D Economist, Montreal economic Institute CPBI, Winnipeg June 15, 2007

General requirements for bodies operating assessment and certificationlregistration of quality systems (ISOIIEC Guide 6ZA996)

The forum for electrical innovation

GLOBAL EDUCATION PROGRAM (GEP)

Preventing fraud and corruption in public procurement

International Compliance

Updated development of global greenhouse gas emissions 2013

NORTHERN TRUST GLOBAL TRADE CUT OFF DEADLINES

IEC TC106. Standards for the Assessment of Human Exposure to Electric, Magnetic, and Electromagnetic Fields, 0 to 300 GHz

Pendulum Business Loan Brokers L.L.C. U.S. State Market Area

relating to household s disposable income. A Gini Coefficient of zero indicates

Cisco Smart Care Service

Schedule R Teleconferencing Service

ENTERING THE EU BORDERS & VISAS THE SCHENGEN AREA OF FREE MOVEMENT. EU Schengen States. Non-Schengen EU States. Non-EU Schengen States.

Consolidated International Banking Statistics in Japan

Good practice of dissemination and exploitation results in Latvia

Enterprise Mobility Suite (EMS) Overview

Editorial for Summer Edition

World Solution Provider

Report on Government Information Requests

Transcription:

IAEA 2015 INTERNATIONAL CONFERENCE ON COMPUTER SECURITY IN A NUCLEAR WORLD A NEW IEC STANDARD FOR CYBERSECURITY FOR NUCLEAR POWER PLANTS: IEC 62645 - REQUIREMENTS FOR SECURITY PROGRAMS FOR COMPUTER-BASED SYSTEMS Ted Quinn- Technology Resources Ludovic Pietre-Cambacedes EDF Leroy Hardin - NRC February 26, 2015

Fuqing Plant Site in China (eight units delivered total) 2

Need for international cooperation 6 The threat is common 6 Information sharing is important 6 Law enforcement/cyber systems specialist cooperation 6 The attack may not originate at the target country 6 Cooperation is needed in common areas of guidance and also standards 3 3

International Electrotechnical Commission (IEC) Leading global organization that prepares and publishes standards for: 4 Electrical and electronic products Related technologies Electricity, electronics, magnetics, electromagnetics, electro-acoustics, multimedia, telecommunication, energy production and distribution, electromagnetic compatibility, measurement and performance, dependability, safety, environmental aspects Membership is by National Committees

National Committees participating in nuclear segment Argentina Belgium Canada China Czech Republic Egypt Finland France Germany Italy Japan P Members! Korea (Rep. of)! Netherlands! Norway! Romania! Russian Fed.! South Africa! Sweden! Switzerland! U.S.A.! Ukraine! United Kingdom Observers! Belarus! Greece! Pakistan! Portugal! Spain 5 5

IEC Technical Committee 45 Nuclear Instrument Standards 6 6 Subcommittee 45A: Instrumentation and Control of Nuclear Facilities 6 Working Group 2-Sensor and measurement techniques 6 Working Group 3-Application of digital processors to safety in nuclear power plants 6 Working Group 5-Special process measurements and radiation monitoring 6 Working Group 7-Reliability of electrical equipment in reactor safety systems 6 Working Group 8-Control rooms 6 Working Group 9-Instrumentation systems 6 Working Group 10-upgrading and modernization of I&C systems 6 Working Group 11-Electrical systems

IEC SC45A WG A9 Instrumentation Systems Oct 2014 7

IEC SC45A Standards! IEC 61513 Ed 2.0 2011 -Nuclear Power Plants-I&C for Systems Important to Safety General Requirements for Systems (Similar to IEEE-603-1998)! IEC 60880 Ed 2.0 (2006) Nuclear Power Plants I&C Systems Important to Safety Software Aspects for Computer-Based systems performing Category A Functions (Similar to IEEE 7-4.3.2-2003) 8

New IEC Standard on Cyber Security Series and Standard IEC 62645 Commenced in 2008 Title; Nuclear Power Plants Instrumentation and Control Requirements for Security Programmes for I&C Systems, Many countries are participating including France, U.S., U.K., Germany, Japan, Sweden, etc. Issued in August 2014 Ed 1.0 9

Nuclear Power Plants Instrumentation and control systems Requirements for security programmes for computer-based systems 6 Scope 6 This International Standard establishes requirements and provides guidance for the development and management of effective computer-based (CB) I&C systems, possibly integrating HPD (HDL (Hardware Description Language) programmed devices, hereinafter named I&C CB&HPD systems. Inherent to these requirements and guidance is the criterion that the power plant s security programme complies with the applicable country s CB I&C CB&HPD security requirements. 10

IAEA AND OTHER REFERENCES 6 IAEA Nuclear Security Series No. 17: Reference Manual, Computer Security At Nuclear Facilities, 2011 6 ISO/IEC 27000 Series Information Technology- Security Techniques Information Security Management Systems 6 NRC Reg Guide 5.71, Cyber Security Programs for Nuclear Facilities 6 NEI 08-09 R6, Cyber Security Plan for Nuclear Power Reactors 6 ISA TR99.02.01 2009, Security for Industrial Automation and Control Systems 11

12

IEC 62645 Ed. 1 Requirements for Security Programmes for Computer- Based Systems IEC 62859 Ed. 1 Requirements for CoordinaCng Safety and Cybersecurity IEC NWIP Modeling RECOMMENDED AS TECHNICAL REPORT IEC NWIP Risk Management Technical Report - Review of Available Methods IEC NWIP on Security Controls IEC NWIP Supply Chain Cybersecurity IEC NWIP Design Basis Threat (DBT) (Leave Cme for IAEA Guideline to complete) NOT RECOMMENDED IEC NWIP Cybersecurity Monitoring IEC NWIP DemonstraCon of EffecCveness of security degrees/zones) including TESTING AND AUDITING - - ACCREDITATION 13

Schedule IEC 62645 Ed 2.0 Draft Commencing now 6 The revision of IEC 62645 shall take into account the 2013 editions structure and high-level principles of the ISO/IEC 27001 and ISO/IEC 27002. 6 A better consistency with the IEC 62443 series (on industrial control systems) should also be sought when relevant. 6 A better consistency and articulation with IEC 61513 shall be reached 6 A similar coordination work as the one mentioned in c) with IEC 61513 should be done with IEC 62138, IEC 60880, and all SC45A standards mentioning computer security. 6 The content and structure of IEC 62645 ed. 2 could be rearranged to better take into account the future second level documents with respect to IEC 62645 (IEC 62859 14 and potential future document

IEC 62645 Ed 2.0 Technical and Topical Modifications 6 The concept of security degrees and their associated attribution criteria consideration for revision:? The possibility -fourth security degree (consistent with NSS17 graded approach). 6 Confidentiality issues should be addressed 6 Consideration of electrical sys and smart electrical 6 Specific guidance, on legacy systems (e.g. first generation/outdated digital systems). 6 Additional guidance, recommendations or requirements should be considered about cybersecurity audits and risk assessment. 6 High-level security requirements and/or recommendations to specifically address wireless 15 technologies.

Cyber Security Summary Cyber security is major and growing threat that needs to be addressed by each country in both safety system and balance of plant design and design updates IAEA, IEC, IEEE and country specific Standards Organizations and Regulators are addressing this but a lot more work needs to be done The threat changes every day!! 16