Regulation-Directed Cybersecurity Best Practices for Operational Technology Environments
Hämtar...
Ladda ner
Publicerad
Författare
Typ
Examensarbete för masterexamen
Master's Thesis
Master's Thesis
Modellbyggare
Tidskriftstitel
ISSN
Volymtitel
Utgivare
Sammanfattning
Operational Technology (OT) systems refer to hardware and software used to monitor
and control physical processes, devices, and infrastructure in industrial environments.
These systems are typically designed for long operational lifecycles and are expected
to function reliably over extended periods. In recent years, industrial sectors have
increasingly integrated OT systems with Information Technology (IT) networks to
enable digital transformation, improve data-driven decision-making, and support
remote monitoring and control, thereby enhancing operational efficiency and connectivity. However, this integration also introduces significant cybersecurity risks.
The incorporation of legacy OT systems into modern and continuously evolving IT
environments makes them more vulnerable to cyberattacks and easier to exploit.
Cyber incidents targeting OT systems can result in severe consequences, including
physical damage to equipment, production disruptions, financial losses, safety risks
to personnel, and loss of operational control. Consequently, OT environments have
emerged as critical targets for malicious actors.
To address the growing cybersecurity threat landscape, the European Union has
introduced the Network and Information Security Directive 2 (NIS2) Directive, which
establishes standardized cybersecurity requirements for essential and important
entities, including those in the manufacturing sector. Prior to the introduction of
NIS2, the National Institute of Standards and Technology (NIST) cybersecurity
framework has been widely adopted across industries as a best-practice guideline
for managing cybersecurity risks. Most companies are required to meet the NIS2
requirements, however redesigning the security infrastructure from scratch is an
expensive and complicated process. One possible approach to address this issue is to
map NIS2 requirements to existing cybersecurity frameworks. In this thesis, NIST
standards are mapped to the NIS2 Directive to identify compliance gaps and evaluate
cybersecurity alignment within IT and OT environments. The associated risks in OT
components are analyzed through the development of a Failure Modes and Effects
Analysis (FMEA) table. Additionally, an OT and IT component checklist is created
to ensure the adequacy mitigation and redundancy measures across systems.
This approach helps identify existing gaps, thereby improving overall security and
strengthening compliance. Furthermore, it enables organizations to proactively
address vulnerabilities and adapt to evolving cybersecurity threats.
Beskrivning
Ämne/nyckelord
Operational Technology(OT), Security Standardization, Network and Information Systems Directive, Risk Analysis, Cybersecurity regulation
