LAPSE:2023.3705
Published Article

LAPSE:2023.3705
IEC 62443 Standard for Hydro Power Plants
February 22, 2023
Abstract
This study approaches cyber security in industrial environments focusing on hydro power plants, since they are part of the critical infrastructure and are the main source of renewable energy in some countries. The theoretical study case follows the standard IEC 62443-2-1 to implement a cyber security management system (CSMS) in a hydro power plant with two generation units. The CSMS is composed of six steps: (1) initiate CSMS, (2) high level risk assessment, (3) detailed risk assessment, (4) establish policies, procedures, and awareness, (5) select and implement countermeasures, and (6) maintain the CSMS. To perform the high-level risk assessment, an overview of the most common activities and vulnerabilities in hydro power plants systems is presented. After defining the priorities, the detailed risk assessment is performed based on a HAZOP risk analysis methodology focusing on hackable digital assets (cyber-HAZOP). The analysis of the cyber-HAZOP assessment leads to mitigations of the cyber risks that are addressed proposing modifications in the automation architecture, and this also involves checking lists to be used by the stakeholders during the implementation of the solution, emphasizing security configurations in digital assets groups.
This study approaches cyber security in industrial environments focusing on hydro power plants, since they are part of the critical infrastructure and are the main source of renewable energy in some countries. The theoretical study case follows the standard IEC 62443-2-1 to implement a cyber security management system (CSMS) in a hydro power plant with two generation units. The CSMS is composed of six steps: (1) initiate CSMS, (2) high level risk assessment, (3) detailed risk assessment, (4) establish policies, procedures, and awareness, (5) select and implement countermeasures, and (6) maintain the CSMS. To perform the high-level risk assessment, an overview of the most common activities and vulnerabilities in hydro power plants systems is presented. After defining the priorities, the detailed risk assessment is performed based on a HAZOP risk analysis methodology focusing on hackable digital assets (cyber-HAZOP). The analysis of the cyber-HAZOP assessment leads to mitigations of the cyber risks that are addressed proposing modifications in the automation architecture, and this also involves checking lists to be used by the stakeholders during the implementation of the solution, emphasizing security configurations in digital assets groups.
Record ID
Keywords
CSMS, cyber-HAZOP, HPPs cybersecurity, IEC 62443, smart grid
Subject
Suggested Citation
Heluany JB, Galvão R. IEC 62443 Standard for Hydro Power Plants. (2023). LAPSE:2023.3705
Author Affiliations
Heluany JB: Department of Information Security and Communication Technology, Norwegian University of Science and Technology, 2815 Gjøvik, Norway
Galvão R: PECE—Industrial Automation, University of São Paulo, São Paulo 2373, Brazil
Galvão R: PECE—Industrial Automation, University of São Paulo, São Paulo 2373, Brazil
Journal Name
Energies
Volume
16
Issue
3
First Page
1452
Year
2023
Publication Date
2023-02-01
ISSN
1996-1073
Version Comments
Original Submission
Other Meta
PII: en16031452, Publication Type: Journal Article
Record Map
Published Article

LAPSE:2023.3705
This Record
External Link

https://doi.org/10.3390/en16031452
Publisher Version
Download
Meta
Record Statistics
Record Views
383
Version History
[v1] (Original Submission)
Feb 22, 2023
Verified by curator on
Feb 22, 2023
This Version Number
v1
Citations
Most Recent
This Version
URL Here
https://psecommunity.org/LAPSE:2023.3705
Record Owner
Auto Uploader for LAPSE
Links to Related Works
(0.07 seconds)
[0.07 s]
