Cyber Security: Development of a Best Practice Guide for Process Safety Systems
It is widely recognised that systems accessible over the internet are susceptible to on-line attack. The process control sector has generally controlled the threat through restricting access to critical systems, particularly where the systems provide safety protection or mitigation functions. However, for less critical systems the benefits of remote access for surveillance, diagnostics and upgrade activities makes it difficult to maintain a completely "closed" approach within the overall system architecture. Where control and monitoring systems communicate with safety critical systems, or where safety functionality is not strictly segregated from the control system, then vulnerabilities in the on-line systems could compromise safety functions. Recognising that industry needs to gain the commercial…