Technical and administrative cyber security issues with implementation of a SCADA security upgrade

Author(s):  
B. Fulton
2015 ◽  
Vol 5 (3) ◽  
pp. 19-27
Author(s):  
Rahul Rastogi ◽  
Rossouw von Solms

SCADA (Supervisory Control and Data Acquisition System) is a cyber-physical system, wherein IT (Information Technology) components work in conjunction with field devices to control a physical process. The security of these IT components becomes crucial in view of the damaging effects that any security breach of these IT components can have on the underlying physical process. In response to this critical issue, various governments across the world have recognized the issue of SCADA security and have initiated the creation of a regulatory framework for mandating SCADA security in their respective countries. This paper provides a brief overview of the cyber-security issues of SCADA and the implications of Stuxnet for SCADA security. The paper reviews the steps taken by the governments of India and South Africa; and it provides guidance to the owners of SCADA regarding SCADA security, as mandated by the Government of India.


2022 ◽  
Author(s):  
Nitul Dutta ◽  
Nilesh Jadav ◽  
Sudeep Tanwar ◽  
Hiren Kumar Deva Sarma ◽  
Emil Pricop

2015 ◽  
Vol 16 (3) ◽  
pp. 4-14 ◽  
Author(s):  
James Burns ◽  
Georgia Bullitt ◽  
Howard Kramer ◽  
Jack Habert ◽  
James Doench

Purpose – To explain the requirements of Regulation Systems Compliance and Integrity (“Regulation SCI”) and the new responsibilities of organizations defined as “SCI entities.” Design/methodology/approach – Explains the purpose of Regulation SCI, the responsibilities of SCI entities, systems covered by the rules (“SCI systems”), and specific obligations of SCI entities, including the establishment and periodic review of policies and procedures, compliance with the Exchange Act, designation of “responsible SCI personnel,” appropriate corrective action in response to “SCI events,” notification of systems changes, annual “SCI reviews,” business continuity and disaster recovery testing, and recordkeeping and filing. Discusses future implications for SCI Entities and other market participants. Findings – Regulation SCI launches a broad and extensive overlay of rules and guidance to address systems capacity and integrity issues that have increasingly affected the securities markets. The adoption of this regulation suggests that there will continue to be increased scrutiny by the SEC, FINRA and other regulators of the automated systems and related policies and procedures of all market participants. Practical implications – SCI entities will need to devote considerable attention and resources not just to prevent incidents where possible, but also to establish systems for ensuring thorough compliance and well-documented and reasonable follow-up actions where necessary. All market professionals – including broker-dealers, investment advisers, pension funds and investment companies – should study the new regulation and consider adopting appropriate policies and procedures to address operating as well as cyber security issues with respect to their own critical operating technology. Originality/value – Practical guidance from experienced financial services lawyers.


2019 ◽  
Vol 8 (3) ◽  
pp. 331-343
Author(s):  
Renata Marcinauskaitė ◽  
Indrė Pukanasytė ◽  
Jolita Šukytė

Sign in / Sign up

Export Citation Format

Share Document