To main content

Security and Independence of Process Safety and Control Systems in the Petroleum Industry

Abstract

The developments of reduced manning on offshore facilities and increased information transfer from offshore to land continue and may also be a prerequisite for the future survival of the oil and gas industry. A general requirement from the operators has emerged in that all relevant information from offshore-located systems should be made available so that it can be analysed on land. This represents a challenge to safety in avoiding negative impacts and potential accidents for these facilities. The layered Purdue model, which helps protect OT systems from unwanted influences through network segregation, is undermined by the many new connections arising between the OT systems and the surroundings. Each individual connection is not necessarily a problem; however, in aggregate, they add to the overall complexity and attack surface thereby exposing the OT systems to increased cyber risk. Since the OT systems are critical to controlling physical processes, the added connections represent a challenge not only to security but also to safety.

Category

Academic article

Client

  • Research Council of Norway (RCN) / 326717

Language

English

Affiliation

  • Norwegian University of Science and Technology
  • SINTEF Digital / Software Engineering, Safety and Security
  • SINTEF Group Head Office

Year

2022

Published in

Journal of Cybersecurity and Privacy (JCP)

Publisher

MDPI

Volume

2

Issue

1

Page(s)

20 - 41

View this publication at Cristin