Published September 2017 | Version v1
Book

Rethinking classification of digital assets

  • 1. Nixu Oyj, Espoo (Finland)
  • 2. Fennovoima Oy, Helsinki (Finland)

Description

Historically industrial control systems (ICS, I&C systems) at nuclear facilities have been classified based on their impact to safety and emergency preparedness, but, particularly, as digital, programmable systems are becoming more and more important, information security and cyber security considerations in the classification have become relevant/necessary. This has led to classifying I&C systems based on security considerations and definition of security levels or identification of critical digital systems/critical digital assets (CDS/CDA). If implemented as two separate classification schemes, currently/traditionally, safety has precedence (the "safety overrules" principle/practice). Nuclear safety, security and safeguards/nuclear material accountancy and control (NMAC) have a joint objective: to protect people, society and the environment and future generations from harmful effects of ionizing radiation [IAEA Safety Fundamentals No.SF-1]. Safety and security measures are partly mutually supportive, while some of their means to achieve the joint objective are conflicting. In a case of conflict, such a default where safety considerations would always overrule, is outdated. In particular, where safety and emergency preparedness functions are performed by digital, programmable systems, security is imperative to ensure correct, reliable operation: integrity and availability of systems. What is the problem? If safety experts and security experts do not work together and consider both safety and security issues on equal footing, the conclusion may be to justify the lack of security features by insisting/proving that they impairs the operation of the safety function, or applying security levels to digital, programmable systems based on direct impact only, risking to miss the indirect impact to safety or the impact of unanticipated behavior due to system compromise through an intentional act. Neither approach provides a good basis for SAHARA or the fundamental safety and security objective. If a system significant to safety, security, or emergency preparedness cannot be secured, it should not be used. The determination of system significance should take into account the direct and indirect impact to safety, security, and emergency preparedness. It has taken a long time for digital, programmable technology to penetrate into the nuclear safety regime, but it has happened. New regulations have been developed but their implementation together with the old regulations has not necessarily been facilitated or the old paradigms ("safety overrides") rethought. Security is not a supporting function; nor should it be a retrofit feature. With digital, programmable systems, security is safety and safety is security, i.e. security and safety are totally interdependent. Hence, we should ensure that safety and security requirements and solutions are implemented in a consistent and balanced manner, in order to achieve the best overall result, in accordance with the fundamental safety and security objective. (author)

Part of:
International Conference on Nuclear Security: Commitments and Actions. Summary of an International Conference. Companion CD-ROM

Additional details

Publishing Information

Publisher
IAEA
Imprint Place
Vienna (International Atomic Energy Agency (IAEA))
ISBN
978-92-0-107017-3
Imprint Title
International Conference on Nuclear Security: Commitments and Actions. Summary of an International Conference. Companion CD-ROM
Imprint Pagination
[1 CD-ROM]
Series
Proceedings Series
Journal Page Range
7 p.
ISSN
0074-1884

Conference

Title
Commitments and Actions
Acronym
International Conference on Nuclear Security
Dates
5-9 Dec 2016
Place
Vienna (Austria)

INIS

Country of Publication
International Atomic Energy Agency (IAEA)
Country of Input or Organization
International Atomic Energy Agency (IAEA)
INIS RN
50017419
Subject category
S98: NUCLEAR DISARMAMENT, SAFEGUARDS AND PHYSICAL PROTECTION;
Resource subtype / Literary indicator
Conference
Descriptors DEI
CONTROL SYSTEMS; HAZARDS; IONIZING RADIATIONS; NUCLEAR FACILITIES; RADIATION PROTECTION; REGULATIONS; SAFEGUARDS; SAFETY; SECURITY
Descriptors DEC
LAWS; RADIATIONS

Optional Information

Notes
Includes PowerPoint presentation; 3 refs., 1 fig., 1 tab.
Secondary number(s)
STI/PUB--1794(Companion CD-ROM); IAEA-CN--244