Cyber-security and IEC International Standards

Slides:



Advertisements
Similar presentations
Khammar Mrabit Director Office of Nuclear Security
Advertisements

Supporting National e-Health Roadmaps WHO-ITU-WB joint effort WSIS C7 e-Health Facilitation Meeting 13 th May 2010 Hani Eskandar ICT Applications, ITU.
Smart Grid - Cyber Security Small Rural Electric George Gamble Black & Veatch
INSAG DEVELOPMENT OF A DOCUMENT ON HIGH LEVEL SAFETY RECOMMENDATIONS FOR NUCLEAR POWER Milestone Issues: Group C. Nuclear Safety. A. Alonso (INSAG Member)
IAEA International Atomic Energy Agency Human Resources Development for Nuclear Safety J. Bastos NSNI/RAS.
Challenges of a Harmonized Global Safety Regime Jacques Repussard Director General IRSN IAEA 2007 Scientific Forum.
LEGAL FRAMEWORK & REGULATORY SYSTEM f or introduction of NPP into Vietnam Le Chi Dung (VARANS, Vietnam) Vienna, December 2008.
Anita Nilsson Director, Office of Nuclear Security
IAEA International Atomic Energy Agency IAEA Nuclear Security Programme Enhancing cybersecurity in nuclear infrastructure TWG-NPPIC – IAEA May 09 – A.
Standards and innovation What is a standard? How do standards promote innovation? What is the role of governments and the UN?
IAEA - Department of Nuclear Safety & Security
© 2011 Underwriters Laboratories Inc. All rights reserved. This document may not be reproduced or distributed without authorization. ASSET Safety Management.
Conformity assessment – Standards and CEOC’s involvement Annual Conference 31 of May 2010 in Vienna Dipl.-Ing. Gerd-Hinrich Schaub CEOC International.
Committed to Connecting the World International Telecommunication Union Presentation Brief about ICTs Applications activities Telecommunication Development.
IAEA International Atomic Energy Agency Education & Training in Nuclear Installation Safety web: goto.iaea.org/nis-traininggoto.iaea.org/nis-training contact:
IAEA 52 nd General Conference Senior Regulators’ Meeting 3 October, 2008 HISTORY AND CURRENT STATUS OF THE IAEA SAFETY STANDARDS K. Mrabit Head, Safety.
Standards Certification Education & Training Publishing Conferences & Exhibits 1Copyright © 2006 ISA ISA-SP99: Security for Industrial Automation and Control.
IAEA International Atomic Energy Agency School of Drafting Regulations – November 2014 Government and Regulatory Body Functions and Responsibilities IAEA.
International Standards and Regional Regulations.
GSC-19 Meeting, July 2015, Geneva Guest Presentation by ISO and IEC Henry Cuschieri, ISO Gilles Thonet, IEC Jim MacFie, JTC 1 Document No:GSC-19_009.
IAEA International Atomic Energy Agency Methodology and Responsibilities for Periodic Safety Review for Research Reactors William Kennedy Research Reactor.
National Nuclear Regulatory Portal (NNRP) (Concept, Development and Experience) FNRBA Training Course on Knowledge Safety Networks, 14–18 October 2013,
Length Mass Prepackages Health Environment Safety Trade Volumes Flow Energy Pressure Concentration Enforcement R. Schwartz, 46. CIML Acceptance.
ISA99 - Industrial Automation and Controls Systems Security
IAEA International Atomic Energy Agency. IAEA Outline LEARNING OBJECTIVES REVIEW TEAM AMD COUNTERPARTS Team Composition Qualification PREPARATORY PHASE.
Telecommunications Industry Association (TIA) ADVANCING GLOBAL COMMUNICATIONS.
LEARNINGS FROM PASC WORK SHOP 2015 “SERVICE STANDARDIZATION ”
IAEA International Atomic Energy Agency IAEA Training Course on Conducting Computer Security Assessments Presented by: Donald D. Dudenhoeffer.
Standards Certification Education & Training Publishing Conferences & Exhibits 1 Copyright © ISA, All Rights reserved ISA99 - Industrial Automation and.
BSI Standardisation Efforts in RAS Stephen Cameron Chair, BSI AMT/2 Committee on Robotics University of Oxford JWG5: MedicalWG2: Personal careWG3: Industrial.
ISO’s standardization approach to security, privacy and trust
ISO/IEC JTC 1 SWG Smart Grid
Governmental, Legal and Regulatory Framework in Azerbaijan Republic
Occupational Radiation Protection during High Exposure Operations
ISO/IEC JTC 1/SC 7 Working Group 42 - Architecture Johan Bendz
ISO/IEC Joint Technical Committee 1 ISO/IEC JTC 1
John Drengenberg Consumer Affairs Manager
IAEA Regional Activities Related to Transport Safety Module 2.2
General Secretary & CEO
ISO Update and Priorities
AAEA Role in Improving EPR Coordination Interventions among Arab Countries Abdelmajid Mahjoub Arab Atomic Energy Agency
IEEE CS SAB, Mar 2009 IEEE Computer Society Category A Liaison to ISO/IEC JTC 1/SC 40: Status Report Annette Reilly IEEE Computer Society
Roadmap to Enhanced Technical Regulations of WMO
Assist. Prof. Magy Mohamed Kandil
NRC Cyber Security Regulatory Overview
The Role of European Standards in Support of the Cybersecurity Act
Business cases on standardization
Multimodality Year 2018 Platform of Railway Infrastructure Managers in Europe (PRIME) 11th Plenary Meeting, 16 November 2017 DG MOVE.
The International Electrotechnical Commission
The Role of IEC Standards in Knowledge Management
IEC and Information Technology
ISO/IEC Joint Technical Committee 1 ISO/IEC JTC 1
Communication and Consultation with Interested Parties by the RB
RCF Plenary Session 21 September 2018
General Secretary & CEO
ISO Update and Priorities
General Secretary & CEO
Importance of Standardization James Hammond, Standards Division
SMR Regulators’ Forum Pilot Project Report
Community of Users.
SMR Regulators’ Forum Mr. Stewart Magruder
Elements of an Electronics NTBs Initiative
ISO and ISO/TC22 Overview March 2019
Frans Vreeswijk IEC General Secretary & CEO GSS16 24 October 2016
Malcolm Johnson, Director, Telecommunication Standardization Bureau
ISO and TR Update for FDA Regulated Industries
Recent Standardization Activities on Cloud Computing
CIRM Presentation Raytheon Anschütz Distributor Meeting 2016
Nuclear Safety Standards Committee 35th Meeting 24 – 28 June 2013
John Drengenberg Consumer Affairs Manager
Presentation transcript:

Cyber-security and IEC International Standards Frans Vreeswijk IEC General Secretary & CEO IAEA Conference 1 June 2015 Vienna, Austrîa

digital dependence – increased vulnerability Ladies and Gentlemen,   Our dependency on computers, digital information collection and data transmission systems is growing daily. And while malicious acts in cyber space are deeply annoying at the level of the individual, the exploitation of cyber vulnerabilities of infrastructure systems is becoming an increasing threat to our overall security.

Nuclear energy production plants rely on computer networks for most internal processes. Many plants are connected to external networks and increasingly sophisticated malware can target such systems. Recent events have raised global concerns of cyber-attacks and the impact they could have on nuclear security.   Cyber threats are fundamentally different to other safety hazards. While safety concepts are based on the probabilities of random failure, security concepts must assume that an informed actor intentionally tampers with digital systems.

IEC International Standards Standards are a fundamental ally in assessing and managing risks and can significantly help increase the safety and security of nuclear environments. IEC safety publications provide specific directives related to nuclear energy facilities with an all-encompassing approach to risk assessment, safety and security.

scope of the IEC Energy generation and the millions of devices and systems that use or produce electricity and contain electronics. Interoperability, safety, security, performance, EMC and more. The IEC is one of the three global Standards bodies. We publish the large majority of the technical rules that guide the design, manufacturing, installation, overhaul and end-of-life management of the millions of devices and systems that produce or use electricity and contain electronics. IEC work covers topics such as interoperability, safety, security and much more.   IEC International Standards are voluntary, consensus based and developed according to the criteria laid down by the World Trade Organization.

global reach: 166 countries 98% of world population 96% of energy generation The IEC brings together 166 countries that represent 98% of global population and 96% of energy generation. Nearly all countries in the world accept products built according to IEC International Standards.

IEC + IAEA The IEC works closely with IAEA since nearly four decades. Experts from both organizations collaborate on joint Safety Standards. They enjoy observer status in each organization. since 1977

electric, electronic devices & techniques IEC International Standards cover the majority of electric and electronic instrumentation, equipment and systems used in the nuclear industry. IEC scope of work also includes emerging electronic techniques in information processing and control, including artificial intelligence.   In mid-2014, the IEC has published the first International Standard that establishes the requirements for security programmes for information and communication digital systems used in nuclear power plants. And IEC and IAEA Division of Nuclear Security have agreed to further develop the collaboration on security related activities.

new and revised IEC Standards The IEC is now in the process of revising one of its Standards to take into account the fast-evolving nature of the cybersecurity landscape, in terms of threats, practices and regulatory frameworks.   Furthermore, a new, soon to be published IEC International Standard will help coordinate the safety and cyber security provisions for information and communication digital systems and architecture.

generic to specialized ISO ITU IAEA In this context it is important to note, that the IEC never works in isolation. In addition to its close collaboration with IAEA, the IEC also actively coordinates pertinent work with ISO and ITU. The IEC has several active liaisons with relevant technical committees. The aim is to avoid duplicative work and take advantage wherever possible of existing know-how. For example, the IEC helps complement existing generic safety and security Standards to bring them to the high level of safety and regulatory requirements in nuclear environments.   As a general rule, whenever new work on an International Standard is started, the IEC makes certain that relevant know-how in existing Standards is taken in to account. For example, the IEC has close working liaisons with ISO/IEC JTC1 SC 27, which prepares generic cyber-security Standards. This approach is an integral part of the ISO/IEC Directives and helps increase the coherence of International Standards. It also helps reduce technical barriers to trade in line with the WTO TBT agreement.

maintain universal safety and security terminology The IEC also helps maintain consistency between IAEA and IEC documents by reviewing and commenting drafts of IAEA safety and security documents, and by enforcing the consistent use of a unique safety and security terminology by both organizations. An additional benefit of this approach is that it helps the IEC to identify detailed technical aspects for new work it should cover.

Cyber-security and IEC International Standards Ladies and Gentlemen. I believe this international conference will play a crucial role in reviewing and identifying global expertise in cyber-security and will ultimately help strengthen the computer and overall security of the nuclear infrastructure.   Frans Vreeswijk IEC General Secretary & CEO IAEA Conference 1 June 2015 Vienna, Austrîa