1. Application of EBIOS for the risk assessment of ICT use in electrical distribution sub-stations
- Author
-
Artur Hecker, Armaud Puccetti, John Mcdonald, Nouha Oualha, Frederic Planchon, Mesures et Systèmes d’info des Réseaux électriques (EDF R&D MIRE), EDF R&D (EDF R&D), EDF (EDF)-EDF (EDF), Département Intelligence Ambiante et Systèmes Interactifs (DIASI), Laboratoire d'Intégration des Systèmes et des Technologies (LIST (CEA)), Direction de Recherche Technologique (CEA) (DRT (CEA)), Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Direction de Recherche Technologique (CEA) (DRT (CEA)), Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Commissariat à l'énergie atomique et aux énergies alternatives (CEA)-Université Paris-Saclay, Télécom ParisTech, The work presented in this paper has been funded in part by the French National Research Agency (ANR – Agence National de Recherche), and Laboratoire d'Intégration des Systèmes et des Technologies (LIST)
- Subjects
Engineering ,Context (language use) ,Electrical distribution networks ,security ,Information technology ,02 engineering and technology ,[SPI]Engineering Sciences [physics] ,Risk profile ,0502 economics and business ,0202 electrical engineering, electronic engineering, information engineering ,Information system ,Industrial control systems ,System risk assessment ,Risk management ,EBIOS ,Risk assessment ,Distribution substations ,Electric power distribution ,business.industry ,05 social sciences ,Electrical distribution ,020207 software engineering ,Industrial control system ,Information and Communication Technologies ,Risk analysis (engineering) ,Information and Communications Technology ,Telecommunication ,Systems engineering ,050211 marketing ,business - Abstract
Conference of 2013 IEEE Grenoble Conference PowerTech, POWERTECH 2013 ; Conference Date: 16 June 2013 Through 20 June 2013; Conference Code:101578; International audience; This paper addresses the challenge of applying an Information System risk assessment technique in the context of an Industrial Control System, specifically the electrical distribution network. This paper describes the application of the technique EBIOS (Expression des Besoins et Identification des Objectifs de Sécurité) to evaluate the risk associated with use of supporting Information and Communication Technologies (ICT) within distribution substations operation. The paper highlights the detailed and rigorous nature of the approach in addition to identifying some limitations of the approach notably the difficulties of representing both the interdependency between the electrical distribution network and its supporting ICT and the evolving risk profile of dynamic system. Consequently, the paper will also highlight ongoing work aimed at addressing these limitations.
- Published
- 2013