2017Unpublished venueRequires access

Integration of IT frameworks for the management of information security within industrial control systems providing metrics and indicators

Fabián E. Bustamante, Walter Fuertes, Paúl Díaz, Theofilos Toulkeridis

Open publisher page 11 citations

Abstract

As an extension of a previous methodological proposal to provide management of information security in Industrial Control Systems (ICS), this study aims to adapt IT frameworks to protect industrial and manufacturing enterprises against Information and Communication Technology disruptions and malicious activity. In order to accomplish this purpose, the integration of traditional IT standards and good practices such as COBIT, PMI-PMBOK, ITIL and NIST have been merged. Hereby, COBIT has been applied to align management with the enterprise strategy, PMI-PMBOK for project management, and ITIL for the support and maintenance of ICS services. In this respect, NIST-SP 800-82 has been used as a Guide to ICS Security. Prior to its implementation, we performed an evaluation and selection of a group of tools of these frameworks. Furthermore, they have been used effectively in the operational management of the information security in real cases. Among the main obtained benefits, we were able to reduce incidents and accomplished a holistic management. The achieved results and indicators demonstrate that the management tools comply with the control of the information security in the ICS in the contexts of technology, processes, and people aligned with the strategic objectives.

About this research paper

What this paper is about

As an extension of a previous methodological proposal to provide management of information security in Industrial Control Systems (ICS), this study aims to adapt IT frameworks to protect industrial and manufacturing enterprises against Information and Communication Technology disruptions and malicious activity. In order to accomplish this purpose, the integration of traditional IT standards and good practices such as COBIT, PMI-PMBOK, ITIL and NIST have been merged. Hereby, COBIT has been applied to align management with the enterprise strategy, PMI-PMBOK for project management, and ITIL for the support and maintenance of ICS services. In this respect, NIST-SP 800-82 has been used as a Guide to ICS Security. Prior to its implementation, we performed an evaluation and selection of a group of tools of these frameworks. Furthermore, they have been used effectively in the operational management of the information security in real cases. Among the main obtained benefits, we were able to reduce incidents and accomplished a holistic management. The achieved results and indicators demonstrate that the management tools comply with the control of the information security in the ICS in the contexts of technology, processes, and people aligned with the strategic objectives.

Why it matters

OpenAlex reports 11 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

As an extension of a previous methodological proposal to provide management of information security in Industrial Control Systems (ICS), this study aims to adapt IT frameworks to protect industrial and manufacturing enterprises against Information and Communication Technology disruptions and malicious activity. In order to accomplish this purpose, the integration of traditional IT standards and good practices such as COBIT, PMI-PMBOK, ITIL and NIST have been merged. Hereby, COBIT has been applied to align management with the enterprise strategy, PMI-PMBOK for project management, and ITIL for the support and maintenance of ICS services. In this respect, NIST-SP 800-82 has been used as a Guide to ICS Security. Prior to its implementation, we performed an evaluation and selection of a group of tools of these frameworks. Furthermore, they have been used effectively in the operational management of the information security in real cases. Among the main obtained benefits, we were able to reduce incidents and accomplished a holistic management. The achieved results and indicators demonstrate that the management tools comply with the control of the information security in the ICS in the contexts of technology, processes, and people aligned with the strategic objectives.

Key concepts: COBIT, Information Technology Infrastructure Library, Information security management system, ITIL security management, Process management, Financial management for IT services, Information security, Knowledge management

Related papers

Back to paper searchBrowse research topicsOriginal source
Integration of IT frameworks for the management of information security within industrial control systems providing metrics and indicators — Research Paper | ScholarLens