PROBLEMS OF IMPLEMENTING INFORMATION SECURITY REQUIREMENTS IN INDUSTRIAL CONTROL SYSTEMS
DOI:
https://doi.org/10.56132/2791-3368-2026-2-66-113-123Keywords:
industrial control systems (ICS), information security, OT cybersecurity, risk-based approach, information security management system, critical infrastructure protection, defense-related infrastructure, national securityAbstract
This article examines the key challenges associated with implementing information security requirements in industrial control systems. Based on the analysis of scientific publications, international standards, and industry analytical reports, as well as on the author’s own analysis and practical experience, the limitations of directly transferring information security requirements developed for corporate information systems to the industrial environment are identified. It is shown that the architectural and operational characteristics of ICS, the priority of availability and continuity of technological processes, and the long life cycle of industrial equipment necessitate the adaptation of information security requirements. The role of an information security management system is substantiated as a tool for risk-oriented adaptation of security requirements and for the implementation of compensating security measures in industrial systems.
Downloads
References
1. InfoWatch Expert and Analytical Center. (2024). Trends in the development of cyber incidents in industrial control systems. https://www.infowatch.ru/sites/default/files/analytics/files/tendentsii-razvitiya-kiberintsidentov-asu-tp-za-dve-tysyachi-dvadtsat-chetyvertiy-god.pdf
2. Verizon. (2024). The report on the investigation of data leaks for 2024. https://www.verizon.com/business/resources/reports/2024-dbir-data-breach-investigations-report.pdf
3. IBM. (2024). The X-Force Threat Analysis Index 2024. https://newsletter.radensa.ru/wp-content/uploads/2024/03/IBM-XForce-Threat-Intelligence-Index-2024.pdf
4. Kravchuk A. Yu., Kotova N. A., Anichkin I. I. (2022). Modern approaches to information security in industrial control systems. Innovation and Investments, № 3.
5. NIST SP 800-82. Guide to Industrial Control Systems (ICS) Security. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf
6. IEC 62443. Industrial communication networks – Network and system security. https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards
7. ARinteg. (n.d.). Information security in industrial control systems. https://arinteg.ru/solutions/zashchita-asu-tp/
8. Dragos. (n.d.). OT Cybersecurity Year in Review. https://www.dragos.com/blog/dragos-8th-annual-ot-cybersecurity-year-in-review-is-now-available
9. Kaspersky ICS CERT. (n.d.). Analytical reports on threats to industrial control systems.
10. Positive Technologies. (n.d.). Industrial Cybersecurity reports. https://ptsecurity.com/research/analytics/kiberugrozy-dlya-promyshlennosti-industrial-iot/#id6
11. CISA. Recommended Cybersecurity Practices for Industrial Control Systems.https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems_508.pdf
12. JetInfo. (n.d.). Security problems of industrial networks. https://www.jetinfo.ru/pochemu-bezopasnost-promyshlennyh-setej-na-10-let-otstaet-ot-korporativnyh-standartov/
