By Sam Cohen
Missouri State University DC Graduate Campus
Georgetown University
Abstract: The 2015 attack on Ukraine’s power grid represented the first publically documented cyber incident disrupting electrical utility and power distribution control systems. While the incident was temporary, it impacted critical services supporting 225,000 customers—including businesses, industrial facilities, and government offices. The attack has been recognized as a highly complex and persistent operation that could have escalated to a significantly larger power outage disaster, threatening long-term essential service disruptions at hospitals, government facilities, telecommunication sites, and financial institutions. This paper examines how cybersecurity standards developed or approved by organizations such as the National Institute for Standards and Technology (NIST), the American National Standards Institute (ANSI), the International Organization for Standardization (ISO), the North American Electric Reliability Corporation (NERC), and the International Electrotechnical Commission (IEC) could have either mitigated or entirely prevented this attack. Specifically, log collection and analysis (NERC CIP007-6 and NIST SP-800-92), external network and boundary protection (IEC 62443-3, adopted as ANSI/ISA 99.03.03), and incident response (NIST-7628 Rev.1 and ISO/IEC 27002:2013) standards are mapped against key cybersecurity gaps that enabled the attackers to compromise and exploit key assets throughout Ukraine. The paper then determines how controls listed in these standards could have assisted cybersecurity and IT staff with the defense of their control systems and supervisory control and data acquisition (SCADA) networks, thereby reducing the destructive potential of the attack and possibly mitigating the disaster altogether. The standards analyzed in this paper are identified for their mitigation utility during the Ukraine attacks, and also for their applicability to any power grid owner or operator aiming to reduce cyber risk.
Issue: [12-78]
Category: Academics, Public Policy
Colleagues: Mike Anthony, Christine Fischer, Paul Green,
More
ANSI Essential Requirements: Due process requirements for American National Standards.
ANSI Committee on Education Student Paper Competition
https://www.standardslearn.org/
Missouri State University Department of Defense and Strategic Studies
“There was a time when meadow, grove, and stream,
The earth, and every common sight
To me did seem
Apparelled in celestial light,
The glory and the freshness of a dream….”
Ode on Intimations of Immortality from Recollections of Early Childhood
William Wordsworth
Monday | May 20 | Colloquium 15:00 UTC
Tuesday | May 21 | Colloquium 15:00 UTC
Wednesday | May 22 | Colloquium 15:00 UTC
Thursday | May 23 | Colloquium 15:00 UTC
Friday | May 24 | Colloquium 15:00 UTC
Start of Memorial Day Weekend in the United States
Saturday | May 25
Sunday | May 26
List of multinational festivals and holidays
This content is accessible to paid subscribers. To view it please enter your password below or send [email protected] a request for subscription details.
New update alert! The 2022 update to the Trademark Assignment Dataset is now available online. Find 1.29 million trademark assignments, involving 2.28 million unique trademark properties issued by the USPTO between March 1952 and January 2023: https://t.co/njrDAbSpwB pic.twitter.com/GkAXrHoQ9T
— USPTO (@uspto) July 13, 2023
Standards Michigan Group, LLC
2723 South State Street | Suite 150
Ann Arbor, MI 48104 USA
888-746-3670