Security and Independence of Process Safety and Control Systems in the Petroleum Industry

The developments of reduced manning on offshore facilities and increased information transfer from offshore to land continue and may also be a prerequisite for the future survival of the oil and gas industry. A general requirement from the operators has emerged in that all relevant information from...

Full description

Bibliographic Details
Main Authors: Tor Onshus, Lars Bodsberg, Stein Hauge, Martin Gilje Jaatun, Mary Ann Lundteigen, Thor Myklebust, Maria Vatshaug Ottermo, Stig Petersen, Egil Wille
Format: Article
Language:English
Published: MDPI AG 2022-02-01
Series:Journal of Cybersecurity and Privacy
Subjects:
Online Access:https://www.mdpi.com/2624-800X/2/1/3
_version_ 1797470472893366272
author Tor Onshus
Lars Bodsberg
Stein Hauge
Martin Gilje Jaatun
Mary Ann Lundteigen
Thor Myklebust
Maria Vatshaug Ottermo
Stig Petersen
Egil Wille
author_facet Tor Onshus
Lars Bodsberg
Stein Hauge
Martin Gilje Jaatun
Mary Ann Lundteigen
Thor Myklebust
Maria Vatshaug Ottermo
Stig Petersen
Egil Wille
author_sort Tor Onshus
collection DOAJ
description The developments of reduced manning on offshore facilities and increased information transfer from offshore to land continue and may also be a prerequisite for the future survival of the oil and gas industry. A general requirement from the operators has emerged in that all relevant information from offshore-located systems should be made available so that it can be analysed on land. This represents a challenge to safety in avoiding negative impacts and potential accidents for these facilities. The layered Purdue model, which helps protect OT systems from unwanted influences through network segregation, is undermined by the many new connections arising between the OT systems and the surroundings. Each individual connection is not necessarily a problem; however, in aggregate, they add to the overall complexity and attack surface thereby exposing the OT systems to increased cyber risk. Since the OT systems are critical to controlling physical processes, the added connections represent a challenge not only to security but also to safety.
first_indexed 2024-03-09T19:36:43Z
format Article
id doaj.art-97224231f67f4bb49e40eaa9d4513073
institution Directory Open Access Journal
issn 2624-800X
language English
last_indexed 2024-03-09T19:36:43Z
publishDate 2022-02-01
publisher MDPI AG
record_format Article
series Journal of Cybersecurity and Privacy
spelling doaj.art-97224231f67f4bb49e40eaa9d45130732023-11-24T01:52:05ZengMDPI AGJournal of Cybersecurity and Privacy2624-800X2022-02-0121204110.3390/jcp2010003Security and Independence of Process Safety and Control Systems in the Petroleum IndustryTor Onshus0Lars Bodsberg1Stein Hauge2Martin Gilje Jaatun3Mary Ann Lundteigen4Thor Myklebust5Maria Vatshaug Ottermo6Stig Petersen7Egil Wille8Department of Engineering Cybernetics, Norwegian University of Science and Technology (NTNU), 7491 Trondheim, NorwaySoftware Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760 Torgarden, 7465 Trondheim, NorwaySoftware Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760 Torgarden, 7465 Trondheim, NorwaySoftware Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760 Torgarden, 7465 Trondheim, NorwayDepartment of Engineering Cybernetics, Norwegian University of Science and Technology (NTNU), 7491 Trondheim, NorwaySoftware Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760 Torgarden, 7465 Trondheim, NorwaySoftware Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760 Torgarden, 7465 Trondheim, NorwaySoftware Engineering, Safety and Security, SINTEF Digital, P.O. Box 4760 Torgarden, 7465 Trondheim, NorwaySINTEF Ålesund, Borgundvegen 340, 6009 Ålesund, NorwayThe developments of reduced manning on offshore facilities and increased information transfer from offshore to land continue and may also be a prerequisite for the future survival of the oil and gas industry. A general requirement from the operators has emerged in that all relevant information from offshore-located systems should be made available so that it can be analysed on land. This represents a challenge to safety in avoiding negative impacts and potential accidents for these facilities. The layered Purdue model, which helps protect OT systems from unwanted influences through network segregation, is undermined by the many new connections arising between the OT systems and the surroundings. Each individual connection is not necessarily a problem; however, in aggregate, they add to the overall complexity and attack surface thereby exposing the OT systems to increased cyber risk. Since the OT systems are critical to controlling physical processes, the added connections represent a challenge not only to security but also to safety.https://www.mdpi.com/2624-800X/2/1/3independencesecuritysafetypetroleumoffshore
spellingShingle Tor Onshus
Lars Bodsberg
Stein Hauge
Martin Gilje Jaatun
Mary Ann Lundteigen
Thor Myklebust
Maria Vatshaug Ottermo
Stig Petersen
Egil Wille
Security and Independence of Process Safety and Control Systems in the Petroleum Industry
Journal of Cybersecurity and Privacy
independence
security
safety
petroleum
offshore
title Security and Independence of Process Safety and Control Systems in the Petroleum Industry
title_full Security and Independence of Process Safety and Control Systems in the Petroleum Industry
title_fullStr Security and Independence of Process Safety and Control Systems in the Petroleum Industry
title_full_unstemmed Security and Independence of Process Safety and Control Systems in the Petroleum Industry
title_short Security and Independence of Process Safety and Control Systems in the Petroleum Industry
title_sort security and independence of process safety and control systems in the petroleum industry
topic independence
security
safety
petroleum
offshore
url https://www.mdpi.com/2624-800X/2/1/3
work_keys_str_mv AT toronshus securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT larsbodsberg securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT steinhauge securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT martingiljejaatun securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT maryannlundteigen securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT thormyklebust securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT mariavatshaugottermo securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT stigpetersen securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry
AT egilwille securityandindependenceofprocesssafetyandcontrolsystemsinthepetroleumindustry