lagen.nu
Mapping of OES Security Requirements to Specific Sectors

Mapping of OES Security Requirements to Specific Sectors

Utgivare
Europeiska unionens cybersäkerhetsbyrå
Antagen
2018-01-18
Språk
engelska
Ämnesord
Cybersecurity of Critical Sectors
Källa
www.enisa.europa.eu
Endast på engelskaEuropeiska unionens cybersäkerhetsbyrå har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska unionens cybersäkerhetsbyrå.

Mapping of OES Security Requirements to Specific Sectors DECEMBER 2017

www.enisa.europa.eu European Union Agency For Network and Information Security Mapping of OES Security Requirements to Specific Sectors December 2017

About ENISA

The European Union Agency for Network and Information Security (ENISA) is a centre of network and information security expertise for the EU, its member states, the private sector and EU citizens. ENISA works with these groups to develop advice and recommendations on good practice in information security. It assists member states in implementing relevant EU legislation and works to improve the resilience of Europe’s critical information infrastructure and networks. ENISA seeks to enhance existing expertise in member states by supporting the development of cross-border communities committed to improving network and information security throughout the EU. More information about ENISA and its work can be found at www.enisa.europa.eu. Contact For queries in relation to this paper, please use resilience@enisa.europa.eu For media enquires about this paper, please use press@enisa.europa.eu. Legal notice Notice must be taken that this publication represents the views and interpretations of ENISA, unless stated otherwise. This publication should not be construed to be a legal action of ENISA or the ENISA bodies unless adopted pursuant to the Regulation (EU) No 526/2013. This publication does not necessarily represent state-of the-art and ENISA may update it from time to time. Third-party sources are quoted as appropriate. ENISA is not responsible for the content of the external sources including external websites referenced in this publication. This publication is intended for information purposes only. It must be accessible free of charge. Neither ENISA nor any person acting on its behalf is responsible for the use that might be made of the information contained in this publication. Copyright Notice © European Union Agency for Network and Information Security (ENISA), 2017 Reproduction is authorised provided the source is acknowledged. ISBN 978-92-9204-232-5, DOI 10.2824/844702 02 Mapping of OES Security Requirements to Specific Sectors December 2017

Table of Contents

Executive Summary 4 1 Introduction 5 1.1 Background 5 1.2 Target Audience 5 1.3 Goal and Scope of the report 6 1.4 Methodology 6 2 Mapping of Baseline Security Measures for OESs per sector 8 2.1 Energy 8 2.1.1 Electricity 9 2.1.2 Oil & Gas 14 2.2 Transport 19 2.2.1 Air Transport 20 2.2.2 Rail Transport 23 2.2.3 Water Transport 23 2.2.4 Road Transport 26 2.3 Financial and Banking 27 2.4 Healthcare 37 2.5 Drinking Water Supply & Distribution 42 2.6 Digital Infrastructures 42 2.7 Matching of baseline security measures with sectors 46 3 Mapping the Baseline Security Measures for OES to cross sector international standards 54 03 Mapping of OES Security Requirements to Specific Sectors December 2017

Executive Summary

According to the Directive (EU) 2016/1148 issued by the European Parliament and the Council, hereafter referred to as ‘Network and Information Security (NIS) Directive’, specific types of entities which provide essential services to the European internal market, shall be identified by the Member States. The business sectors for these entities are depicted in Annex II of the NIS Directive. One of the main objectives of the NIS Directive is to enact security measures for operators of essential services (OES) across the European Union, in order to achieve a high common level of Security of Network and Information Systems. The current report provides a substantial and comprehensive mapping of the security requirements for OES, as they have been agreed in the NISD Cooperation Group, to sector specific information security standards. Initially, ENISA conducted desktop research on international security standards, guidelines and good practices per sector. Finally, the security requirements for OES were mapped to international standards used by operators covering all business sectors under scope. This report is a living document that we will augment on a regular basis to keep it up to date with the latest developments. 04 Mapping of OES Security Requirements to Specific Sectors December 2017

1 Introduction

This report provides the mapping of security measures for OES to international standards used by operators in the business sectors mentioned in Annex II of the NIS Directive , namely energy, transport, banking, financial market infrastructures, health, drinking water supply & distribution and digital infrastructures. The current report involves the security requirements for OES, as they have been defined in the specific work stream of the Cooperation Group of the NIS Directive, and they are presented in details in ENISA’s deliverable “Baseline Security Requirements for OES”. The mapping of security requirements for OES to specific sector standards contributes to achieving a common and converged level of security in network and information systems (Article 3 of the NIS Directive) at EU level. This report is a ‘living document’ that we will augment on a regular basis to keep it up to date with the latest developments. It is important to note that the security measures described in this document derived from the work performed under the specific work stream of the NIS Directive Cooperation Group for the security measures for OES. The proposed security measures are not intended to replace existing standards, frameworks or good-practices in use by OES. However, operators could map the standards they use (internally) to the proposed security measures, and in this way assess their information security practices against the requirements adopted by the Cooperation Group. 1.1 Background The ultimate goal of the NIS Directive is to ensure a culture of network and information systems security across sectors (i.e. energy, transport, water, banking, financial market infrastructures, healthcare and digital infrastructure), vital for our society and economy and heavily dependent on ICT (Article 5 §2-b, NISD). The operators identified by the Member States as OES should take appropriate and proportionate technical and organisational measures to manage the risks posed to the security of network and information systems which they use in their operations (Article 14 §1, NISD). Therefore, this mapping contributes to the establishment of a harmonised baseline security level of OES across EU. 1.2 Target Audience The intended audience of this report consists of the OES as well as the public authorities for the following (sub)sectors:  Energy o Electricity o Oil 05 Mapping of OES Security Requirements to Specific Sectors December 2017 o Gas  Transport o Air Transport o Rail Transport o Water Transport o Road Transport  Banking  Financial Market Infrastructures  Health  Drinking Water Supply & Distribution  Digital Infrastructures 1.3 Goal and Scope of the report The main goal of this report is to associate the security requirements for OES, adopted by the Cooperation Group, with information security standards applicable to the sectors of interest as mentioned above and referred to in the Annex II of the NIS Directive. In order to achieve a common, baseline, cross-sector (horizontal) framework of security measures for the OES at EU level, the security requirements for the OES are primarily mapped to the most frequently used international information security standards by operators in each of these sectors. 1.4 Methodology Initially, ENISA conducted a desktop research of international information security standards, guidelines and good practices, relevant to security measures applicable by OES of the business sectors in scope. The final output of the desktop research is contained in the tables [Table 1,Table 2,Table 4,Table 6,Table 8,Table 9, Table 11, Table 12, Table 14, Table 16 ,Table 17 ], depicting the existing information security standards and good practices for each sector, as found in section 2. The next step of the methodology was to map the identified and agreed by the Cooperation Group security measures for OES to the most commonly applicable sector specific standards by the operators of the business sectors. Finally, the security measures were mapped to the three (3) most frequently used international standards, across all the sectors of interest, as found below:  ISO 27001 ISO/IEC 27001 , part of the growing ISO/IEC 27000 family of standards, is an Information Security Management Systems (ISMS) standard published in October 2013 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). ISO/IEC 27001 formally specifies a management system that is intended to bring information security under explicit management control. 06 Mapping of OES Security Requirements to Specific Sectors December 2017  ANSI ISA/IEC 62443 ISA (International Society of Automation) and IEC have developed the IEC 62443 series of standards in order to address the need to design cybersecurity robustness and resilience into industrial automation control systems (IACS). The concept of industrial automation and control systems electronic security is applied in the broadest possible sense, encompassing all types of plants, facilities, and systems in all industries. IEC 62443 targets people, processes, systems, solutions and components/products.  NIST Framework for Improving Critical Infrastructure Cybersecurity This Framework enables organizations – regardless of size, degree of cybersecurity risk, or cybersecurity sophistication to apply the principles and best practices of risk management to improving the security and resilience of critical infrastructure. The Framework provides structure to today’s multiple approaches to cybersecurity by assembling standards, guidelines, and practices that are working effectively in industry today. Moreover, because it references globally recognized standards for cybersecurity, the Framework can also be used by organizations located outside the United States and can serve as a model for international cooperation on strengthening critical infrastructure cybersecurity. The above standards were selected according to:  the results of the survey that was filled in by the representatives of EU Member States, in the th th Cooperation Group. The survey was launched on 6 March 2017 and it was active until 15 May 2017. More specifically, ISO 27001 was emerged by the survey as the most commonly followed standard.  the input provided during phone interviews by EU operators in the sectors; referred to the NIS Directive. More specifically, o ANSI ISA/IEC 62443 is the most applicable international standard for IACS (Industrial Automation and Control Systems), as they constitute the core components of the OES; o NIST Cybersecurity Framework is followed by some European utilities which operate in U.S. and therefore they need a common denominator and ground policy. 07 Mapping of OES Security Requirements to Specific Sectors

December 2017

2 Mapping of Baseline Security Measures for OESs per sector

With the adoption of the Directive on security of Network and Information Systems (NIS) in 2016, a baseline level of security in network and information systems is aimed to be achieved at EU level. This will support the broader vision of the EU Digital Single Market , whilst protecting the interests of the European society and the provision of essential services to European citizens. The following subsections present the mapping of the proposed security measures by the NIS Directive Cooperation Group to industry specific standards that are usually applied by operators covering the sectors under scope. 2.1 Energy The European Union's prosperity and security hinges on a stable and abundant supply of energy. As energy is a vital part of Europe's economy and of modern lifestyles, European citizens expect uninterrupted flows of energy and access to energy sources. Numerous policies have been introduced to secure and create a European sustainable energy network, like the NIS Directive. The NIS Directive distinguishes the subsectors of Electricity, Oil and Gas for the Energy sector. Table 1 below, lists international standards and good practices applicable across all the Energy subsectors of interest. It is the outcome of the conducted desktop research and it is not an all-inclusive table, as it is mainly based on bibliography.

STANDARDS GOOD PRACTICES

 Detailed Measures – Cybersecurity for Industrial Control Systems – ANSSI (France)  Good Practice Guide Process Control and SCADA Security – CPNI  AMI System Security Requirements updated – UCAIUG:  ISO 27001 Information technology — Security AMI‐SEC‐ASAP techniques — Information security management  BDEW whitepaper – Requirements for secure controls systems — Requirements and telecommunications systems – Bundesverband der  ANSI/ISA, Series “ISA-62443: Security for industrial energie un Wasserwirtschaft automation and control system”  Information security baseline requirements for process  NIST Framework for Improving Critical Infrastructure control, safety and support ICT systems – OLF Cybersecurity  Twenty Critical Controls for Effective Cyber Defence: Consensus Audit Guidelines  Catalog of Control Systems Security: Recommendations for Standards Developers – USA DHS  21 Steps to Improve Cyber Security of SCADA Networks – US DOE

Table 1: International standards and good practices applicable across the Energy sector.

According to feedback provided by Energy operators, the most frequently applicable standards for the energy sector, in its entirety, are ISO 27001 and ISA/IEC 62443. The mapping of the security measures to the above listed standards is depicted in section 3, Table 22.

http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52015DC0192&from=EN

08 Mapping of OES Security Requirements to Specific Sectors

December 2017

In the following subsections, electricity, oil and gas specific standards and good practices along with the mapping to the security measures are presented. 2.1.1 Electricity Table 2 below, lists international standards and good practices applicable across the Electricity subsector. SUB- STANDARDS GOOD PRACTICES SECTOR

 NIST SP800-82 Guide to Industrial Control  Cybersecurity model electricity subsector Systems (ICS) Security cybersecurity capability maturity model (es-  ISO 27019 -- Information security management c2m2) - U.S. Department of Energy guidelines based on ISO/IEC 27002 for process  NISTR 7628 - Guidelines for Smart Grid Cyber control systems specific to the energy utility Security: Vol. 1, Smart Grid Cyber Security industry Strategy, Architecture, and High-Level

Electricity

 NERC CIP Series "Critical Infrastructure Requirements Protection Cyber Security": CIP–002 to CIP-011.  ENISA Appropriate security measures for Smart  IEEE STANDARD 1402-2000 - IEEE Guide for Grids - ENISA Electric Power Substation Physical and Electronic  Best practices for handling smart grid cyber Security security - California Energy Commission  IEC 61850 - Power Utility Automation

Table 2: International standards and good practices applicable across the Electricity subsector

Table 3 illustrates the mapping of security measures with Electricity specific standards, such as:  NIST SP 800-82 Rev. 2 (Guide to Industrial Control Systems (ICS) Security) provides guidance on how to secure Industrial Control Systems (ICS) and is usually followed by EU operators as a good practice;  ISO 27019 is the information security management guidelines based on ISO/IEC 27002 for process control systems specific to the energy utility industry;  NERC CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) is a set of requirements for North America's bulk electric system. Nevertheless, it is followed as well by EU operators that extend their business in U.S.

SECURITY D/N DOMAIN NAME NIST SP-800-82 ISO 27019 NERC CIP MEASURE

Part 1 – Governance and Ecosystem

Information 3. ICS Risk Management Information 14.1.4 Business CIP-002-3 Critical System Security and Assessment 1.1 system security continuity planning Cyber Asset

Governance &

risk analysis 4.5 Implement an ICS framework Identification

Risk Management

Security Risk

https://csrc.nist.gov/csrc/media/publications/sp/800-82/rev-2/final/documents/sp800_82_r2_second_draft.pdf https://www.iso.org/standard/43759.html http://www.nerc.com/pa/Stand/Pages/CIPStandards.aspx

09 Mapping of OES Security Requirements to Specific Sectors

December 2017

SECURITY D/N DOMAIN NAME NIST SP-800-82 ISO 27019 NERC CIP MEASURE

Management 6.2.1 Identification of CIP-002-5 BES Cyber Framework risks related to external System parties Categorization 6.1 Executing the Risk Management CIP-010-2Table R3 – Framework Tasks for Vulnerability Assessments Industrial Control Systems

6.2.14 Risk Assessment

CIP-003-6 Cyber Security - Security Management Information 3.3.1 Policy and Controls system security Procedure 5. Security policy policy Vulnerabilities CIP-011-2Table R1 – Information Protection

Information 6.1.1 Security system security Assessment and ─ ─ accreditation Authorization

Information 3.3 Potential ICS system security ─ ─ Vulnerabilities indicators

10.10.1 Audit logging CIP-003-6—Cyber 6.2.3 Information Security —Security system security 15.3 Information Management Audit and audit systems audit Controls, Compliance Accountability considerations Monitoring Process

CIP-004 Cyber Security - Personnel & Training

CIP-004-6 Table R1 – Human resource 6.2.1 Personnel 8. Human resource Security Awareness security Security security Program

CIP-004-6Table R3– Personnel Risk Assessment Program

CIP-002-5.1a Cyber Asset #6.2.7 Media Security — BES Cyber 8. Asset Management Management Protection System Categorization

Ecosystem Ecosystem 1.2 ─ 6.2 External parties ─ Management mapping

Mapping of OES Security Requirements to Specific Sectors

December 2017

SECURITY D/N DOMAIN NAME NIST SP-800-82 ISO 27019 NERC CIP MEASURE

6.2.2 Addressing security when dealing Ecosystem with customers ─ ─ relations 6.2.3 Addressing

security in third-party agreements

Part 2 – Protection

CIP-007-6Table R1– 11.4.4 Remote Ports and Services Systems 6.2.4 Configuration diagnostic and configuration Management configuration port CIP-010-2Table R1 – protection Configuration Change Management

5.1 Network 10.6 Network security Segmentation and management CIP-005-5 Table R1 – System Segregation Electronic Security segregation 11.4.5 Segregation in 5.5 Network Perimeter networks IT Security Segregation 2.1

Architecture

6.3.3 Audit and Accountability 10.10.2 Monitoring Traffic filtering ─ 6.1.1 Security system use Assessment and Authorization

12.3 Cryptographic controls CIP-011-2 Cyber Cryptography 6.3.4.1 Encryption Security - Information 15.1.6 Regulation of Protection cryptographic controls

CIP-007-6Table R5 – System Access Control Administration 6.3.1 Identification and 11.5 Operating system accounts Authentication access control CIP-004-6Table R4– Access Management Program

IT Security

2.2

Administration

CIP-007-6Table R5 – System Access Administration Control 10.10.4 Administrator information ─ and operator logs CIP-004-6Table R4– systems Access Management Program

Mapping of OES Security Requirements to Specific Sectors

December 2017

SECURITY D/N DOMAIN NAME NIST SP-800-82 ISO 27019 NERC CIP MEASURE

CIP-007-6Table R5 – System Access 6.3.2 Access Control Authentication Control 11. Access control and identification 6.3.1 Identification and CIP-004-6Table R4– Authentication Access Management Program

Identity and

2.3 access CIP-007-6Table R5 – management System Access Control

CIP-004-6Table R4– Access rights 6.3.2 Access Control 11. Access control Access Management Program

CIP-004-6Table R5– Access Revocation

9.2.4 Equipment maintenance IT security CIP-007-6Table R2 – maintenance 6.2.9 Maintenance 12 Information systems Security Patch procedure acquisition, Management development and maintenance

IT security

2.4

maintenance

11.4 Network access control CIP-005-5 Table R2 – 6.3.2 Access Control Interactive Remote access 11.4.4 Remote 6.3.1 Identification and diagnostic and Remote Access Authentication configuration port Management protection

Physical and CIP-006-6 Cyber environmental 6.2.2 Physical and Security - Physical Physical and 9. Physical and security Environmental Security of BES Cyber environmental security 2.5 environmental Protection Systems security 9.2 Equipment security 6.2.7 Media Protection CIP-014-1 Physical Security

Part 3 - Defence

CIP-007-6 Table R4 – Security Event 3.3 Potential ICS Monitoring 3.1 Detection Detection ─ Vulnerabilities CIP-007-6 Table R3 –

Malicious Code Prevention

Mapping of OES Security Requirements to Specific Sectors

December 2017

SECURITY D/N DOMAIN NAME NIST SP-800-82 ISO 27019 NERC CIP MEASURE

11.5.1 Secure log-on CIP-007-6 Table R4 – 5.16 Monitoring, procedures Logging Security Event Logging,and Auditing Monitoring

10.2.2 Monitoring and review of third party CIP-007-6 Table R4 – Logs correlation 5.16 Monitoring, services Security Event and analysis Logging, and Auditing 10.10.2 Monitoring Monitoring

system use

CIP-008-5 Table R1 – Cyber Security Incident Response Information 5.17 Incident Detection, Plan Specifications 13 Information security system security Response, and System CIP-008-5 Table R2 – incident management incident response Recovery Cyber Security

Incident Response Plan Implementation and Testing

Computer security

CIP-008 Cyber 3.2 incident Security - Incident

management

13.1 Reporting Reporting and Incident report 6.2.8 Incident Response information security Response Planning events and weaknesses CIP-001 Sabotage Reporting

6.1.6 Contact with CIP-008-5 Table R3 – Communication authorities Cyber Security with competent ─ Incident Response authorities 6.1.7 Contact with Plan Review, Update, special interest groups and Communication

Part 4 - Resilience

6.1.2 Planning CIP-013-1 Cyber Business 6.1.3 Risk Assessment 14. Business continuity Security - Supply continuity management Chain Risk management 6.1.5 Program Management Management

Continuity of

4.1 Operations CIP-009-1 Cyber 14.1 Information Security - Recovery Disaster recovery 6.2.3 Contingency security aspects of Plans for Critical management Planning business continuity Cyber Assets management CIP-009-5 Cyber Security - Recovery

Mapping of OES Security Requirements to Specific Sectors

December 2017

SECURITY D/N DOMAIN NAME NIST SP-800-82 ISO 27019 NERC CIP MEASURE

Plans for BES Cyber Systems

CIP-009-6Table R1 – Recovery Plan Specifications Crisis management 6.2.6 Contingency 14.2 Essential organization Planning emergency services CIP-009-6Table R2 – Recovery Plan Crisis Implementation and 4.2 Management Testing

CIP-009-6Table R3 – Crisis management 6.2.6 Contingency 14.2.1 Emergency Recovery Plan process Planning communication Review, Update and Communication

Table 3: Mapping of security measures with electricity subsector specific standards

2.1.2 Oil & Gas Protection of the Oil and Gas subsector within EU, but also globally, is considered of highly strategic and economic importance in the light of emerging hybrid threats targeting energy utilities. Table 4 below lists international standards and good practices applicable across the Oil and Gas sectors of interest.

SUB-SECTORS STANDARDS GOOD PRACTICES

 API STD 1164 - Pipeline SCADA Security  Oil and Natural Gas subsector cybersecurity capability maturity model - (ONG-C2M2)  Chemical Facility Anti-Terrorism  GIE - Gas Infrastructure Europe Security Risk Assessment Oil & Gas 11 Standards (CFATS) Methodology  Control Systems Cyber Security Guidelines for the Natural Gas Pipeline Industry - Interstate Natural Gas Association of America (INGAA)

Table 4: International standards and good practices applicable across the Oil and Gas subsectors

The most known security framework related to the Oil and Gas subsector is the Chemical Facility Anti-Terrorism Standards (CFATS) program, which is a risk-based performance program that sets the standards for security at the United States highest risk chemical facilities. The CFATS program covers equally both subsectors, while it identifies and regulates ensuring that high-risk chemical facilities have in place security measures to reduce the risks posed against these chemicals. However, the CFATS program does not consider cybersecurity, but safety.

http://www.gie.eu/index.php/publications/gie/cat_view/2-gie-publications#

Mapping of OES Security Requirements to Specific Sectors

December 2017

Table 5 illustrates the mapping of security measures with Oil and Gas specific good practices, such as:  API STD 1164 - Pipeline SCADA Security good practice provides guidance to the operators of oil and gas liquids pipeline systems for managing SCADA system integrity and security.  ONG-C2M2 good practice assist oil and natural gas organizations of all types to evaluate and make improvements to their cybersecurity programs.

D/N DOMAIN NAME SECURITY MEASURE API STD 1164 ONG-C2M2

Part 1 – Governance and Ecosystem

3.4 Risk and Vulnerability Risk Management Information system Assessment Threat and Vulnerability security risk analysis 3.8 Asset Inventory/Categorizing/Tracking Management

1.3 Roles and Responsibilities Information system Cybersecurity Program 3.1 Security Plan security policy Management 3.3 Security Policies

Information system security ─ ─ Information System accreditation 1.1 Security Governance

& Risk Management

Information system ─ ─ security indicators

Information system 7.2.2.6 File Audit and Control ─ security audit

Human resource 3.2 Personnel Workforce Management security 5.12 Personnel Administration

Asset, Change, and Configuration 3.8 Asset Inventory/ Management Asset Management Categorizing/Tracking Situational Awareness

7.3.4 Connections to Third Parties Supply Chain and External Ecosystem mapping for Support Dependencies Management

Ecosystem

1.2 Management 3.11 Procurement Supply Chain and External Ecosystem relations 7.3.4 Connections to Third Parties Dependencies Management for Support

https://global.ihs.com/doc_detail.cfm?document_name=API%20STD%201164 https://energy.gov/sites/prod/files/2014/03/f13/ONG-C2M2-v1-1_cor.pdf

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE API STD 1164 ONG-C2M2

Part 2 – Protection

3.9 Change Management 3.10.1 System Hardening 3.10.2 Software Patching and Updates 3.10.3 Proper Disposal of Equipment and Media. 5.9 Disabled Non-Required Systems Asset, Change, and Configuration Services configuration Management 5.10 Operating System Tools 7.1.6 Defense in Depth 7.2.2.4 White Listing 7.2.2.5 Host/Endpoint Security 7.2.2.6 File Audit and Control 8.2.1 Network Protocols 7 Network Design/Security and Data Interchange 7.1 Network Design

IT Security

2.1 Architecture 7.1.1 Interconnected Business and SCADA Networks 7.1.2 Communication Demarcation Points 7.1.3 Firewalls 7.1.4 Demilitarized Zone (DMZ) 7.1.5 Dual-Homed Computers System segregation 7.1.7 Firewall Management ─ 7.1.8 Virtualization 7.1.8.2 Hypervisor and Virtual Machine Services 7.1.8.3 Networking 7.1.8.4 Resource Allocation 7.2 Network Management 7.3.1 Connections Between the SCADA Control Center Operational Facilities, Data Center, and Telecommunications Center

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE API STD 1164 ONG-C2M2

7.3.2 Connections Between the SCADA System and Business Networks 7.3.3 Connections Between the SCADA System and Business Partners SCADA Systems

7.3.5 Internet and Business Network Access

7.3.6 Voice Over IP/IP telephony (VoIP/IPT)

7.3.7 Instant Messaging (IM) 7.3.8 Wireless Networking

7.3.9 Audio/Video Conferencing 7.3.10 Video Surveillance

7.3.11 Cloud Computing 8 Field Communication 8.1 Field Device Technology

7.1.7 Firewall Management

Traffic filtering 7.1.8.3 Networking ─ 7.3 Data Interchange

7 Network Design/Security and Data Interchange Cryptography 7.3 Data Interchange ─

8.2.2 Encryption of Data on Accessible Paths

5.3 User Accounts Administration 5.4 Operating System Accounts Identity and Access Management accounts IT Security 5.5 SCADA Accounts 2.2

Administration

5.4 Operating System Accounts Administration ─ information systems 5.5 SCADA Accounts

5.3 User Accounts 5.6 Password Controls Authentication and Identity and Access Management Identity and access identification 5.7 Multi-factor Authentication 2.3

management

5.8 Biometrics

Access rights 5.1 Restricted Access Identity and Access Management

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE API STD 1164 ONG-C2M2

5.2 Logical Access Control to Control Systems and Control Networks 5.11 Device Access

7.1.8.1 Permissions 7.2 Network Management

8.2 System Access 8.2.3 Casual User Access to Network

3.5 New or Replacement System Security Design 3.10 Operating System and Application Updates IT security 3.10.2 Software Patching and maintenance ─ Updates procedure 3.10.3 Proper Disposal of Equipment and Media. 9 Annual Review, Reassessment, and Update

IT security 5.1 Restricted Access 2.4

maintenance

5.2 Logical Access Control to Control Systems and Control Networks

5.11 Device Access 7.2 Network Management Remote access ─ 7.3.4 Connections to Third Parties for Support

8.2.4 Remote Access to SCADA Components

8.2.5 Dial-up Modem Access for Maintenance

Physical and Physical and 2.5 environmental environmental 4 Physical Security ─ security security

Part 3 - Defence

7.2.2 Network Security 3.1 Detection Detection 7.2.2.1 Intrusion Detection and Situational Awareness Prevention Systems (IDPS)

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE API STD 1164 ONG-C2M2

7.2.2.2 Malware Detection and Avoidance

7.2.1 Network Monitoring & Logging Advanced Threat Protection Situational Awareness

7.2.2 Network Security

7.2.2 Network Security

7.2.2.1 Intrusion Detection and Logs correlation and Prevention Systems (IDPS) ─ analysis 7.2.2.3 Security Information and Event Management (SIEM)

Information system Event and Incident Response, security incident 3.7 Incident Response Plan (IRP) Continuity of Operations response

Event and Incident Response, Incident report ─ Continuity of Operations

Computer security

3.2 incident 6 Information Distribution

management

6.1 Confidential Communication with Information Sharing and competent 6.2 Restricted Communications authorities 6.3 Internal Use Only

6.4 Public

Part 4 - Resilience

Business continuity Event and Incident Response, 3.6 Business Continuity Plan (BCP) management Continuity of Operations

Continuity of

4.1

Operations

Disaster recovery ─ ─ management

Crisis management ─ ─ organization 4.2 Crisis Management Crisis management ─ ─ process

Table 5: Mapping of security measures with Oil and Gas subsector specific standards

Finally, according to the input gathered by Oil and Gas operators in EU, the most applicable information security standards are ISO 27001, the NIST Cybersecurity Framework and ISA/IEC 62443. The mapping of security measures to these standards is presented in section 3, Table 22. 2.2 Transport According to the NIS Directive, the Transport sector is divided in the following subsectors: Mapping of OES Security Requirements to Specific Sectors December 2017  Air Transport;  Rail Transport;  Water Transport;  Road Transport. Due to a great range of threats, cyber security and physical safety of the transport sector can no longer be treated separately . Among the good practices for the transport sector, the “Roadmap to Secure Control Systems in the Transportation Sector” is included, while there are no specific cybersecurity standards. Therefore, risk management methodologies and security standards usually incorporate measures of both natures, cyber and physical as well. Besides ISO 27001 and ISA/IEC 62443 standards that are mainly followed by transport operators, in the following sections, the mapping of security measures to specific subsector standards is presented respectively. 2.2.1 Air Transport Table 6 lists international standards and good practices applicable across the Air Transport sector.

SUB-SECTOR STANDARDS GOOD PRACTICES

 ICAO Aviation Security Manual - Document 8973  AIAA (The American Institute of Aeronautics and

(Restricted Access) Astronautics) The Connectivity Challenge:

 ARINC 811 Commercial aircraft information Protecting Critical Assets in a Networked World security concepts of operations and process  Information Security Certification and framework Accreditation (C&A) Handbook – FAA

Air Transport

 EUROCAE ED-201 – 204 Aeronautical Information  FAA Issue Paper, Aircraft Electronic Systems System Security (AISS) Framework Security Protection from Unauthorized External Access  RTCA DO-326 Airworthiness security process  FAA Aircraft systems information security specifications protection overview

Table 6: International standards and good practices applicable across the Air Transport sector

Airports, Airlines and Air Navigation Service providers mainly use a risk based approach to security and rely on international information security standards, such as ISO27001 and NIST Cybersecurity Framework. Table 7 illustrates the mapping of security measures to Air transport specific standards and good practices, such as:  ICAO Aviation Security Manual - Document 8973 (Restricted Access) gives a layout on cyber threats to critical aviation information and communication technology systems. Guidance material on areas such as unpredictability, behaviour detection techniques, landside security, and screening of persons other than passengers have been incorporated in the latest version.  AIAA (The American Institute of Aeronautics and Astronautics) The Connectivity Challenge: Protecting Critical Assets in a Networked World outlines a framework for helping the aviation Mapping of OES Security Requirements to Specific Sectors

December 2017

community build a roadmap for ensuring that aviation’s critical infrastructure is secure and able to withstand and rapidly recover from the evolving threats. This framework addresses all security levels including know, prevent, detect, respond and recover.

D/N DOMAIN NAME SECURITY MEASURE ICAO AIAA

Part 1 – Governance and Ecosystem

Information system #3 Security Measures for #3 Define Operational Principals security risk analysis Infrastructure

Information system #3 Security Measures for #3 Define Operational Principals security policy Infrastructure

Information system #3 Security Measures for #5 Establish common cyber security Infrastructure standards for aviation systems accreditation

Information System

1.1 Security Governance Information system & Risk Management ─ ─ security indicators

Information system ─ ─ security audit

Human resource #6 Establish a Cybersecurity ─ security Culture

Asset Management #4 Define Design Principals #4 Define Design Principals

#1 Supply Chain Security for #7 Strengthen the defensive Ecosystem mapping Hardware and Software system

Ecosystem

1.2

Management

#1 Supply Chain Security for #7 Strengthen the defensive Ecosystem relations Hardware and Software system

Part 2 – Protection

Systems #1 Supply Chain Security for ─ configuration Hardware and Software

System segregation #3 Security Measures for #4 Define Design Principals Infrastructure

IT Security

2.1

Architecture

Traffic filtering #3 Security Measures for #7 Strengthen the defensive

Infrastructure system

Cryptography #3 Security Measures for #7 Strengthen the defensive

Infrastructure system

IT Security Administration #7 Strengthen the defensive 2.2 ─ Administration accounts system

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ICAO AIAA

Administration ─ ─ information systems

Authentication and #3 Security Measures for ─ identification Infrastructure

Identity and access

2.3

management

Access rights #3 Security Measures for ─ Infrastructure

IT security #3 Security Measures for maintenance ─ Infrastructure IT security procedure 2.4

maintenance

Remote access #3 Security Measures for ─ Infrastructure

Physical and Physical and

2.5 environmental environmental ─ ─

security security

Part 3 - Defence

Detection #7 Strengthen the defensive #2 Cyber Attack Incident Records system

Logging #7 Strengthen the defensive 3.1 Detection ─ system

Logs correlation and #7 Strengthen the defensive ─ analysis system

Information system

security incident #2 Cyber Attack Incident Records #2 Provide incident response

response

Computer security

3.2 incident Incident report #2 Cyber Attack Incident Records #2 Provide incident response

management

Communication with

competent #2 Cyber Attack Incident Records #2 Provide incident response

authorities

Part 4 - Resilience

Business continuity #3 Security Measures for ─ management Infrastructure

Continuity of

4.1

Operations

Disaster recovery #3 Security Measures for ─ management Infrastructure

Crisis management #3 Security Measures for 4.2 Crisis Management ─ organization Infrastructure

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ICAO AIAA

Crisis management #3 Security Measures for ─ process Infrastructure

Table 7: Mapping of security measures with the Air Transport sector specific standards

2.2.2 Rail Transport The majority of security standards and frameworks in the domain of Rail Transport is dealing mainly with safety aspects, rather than cybersecurity challenges which may affect eventually the safety and security of modern signalling and train control systems. Table 8 below, lists international information security standards and good practices applicable to the Rail Transport subsector.

SUB-SECTOR STANDARDS GOOD PRACTICES

 ISO 27001 Information technology — Security techniques — Information security management  UK Rail Cyber Security Guidance to Rail Transport systems — Requirements Industry  ANSI/ISA, Series “ISA-62443: Security for industrial automation and control system”

Table 8: International standards and good practices applicable across the Rail Transport subsector

According to the feedback taken by EU rail operators, the most commonly applicable standards regarding network and information systems security are ISO 27001 and ANSI ISA/IEC 62443. The mapping of the proposed security measures with the above mentioned standards is presented in section 3, Table 22. 2.2.3 Water Transport ICT systems supporting maritime operations, extending from port management to ship communication, are generally highly complex and employ a variety of ICT technologies. There is lack of holistic consideration of cybersecurity in this particular working environment. Table 9 lists some international standards and good practices applicable in the Water Transport subsector taking into account security and mainly safety aspect.

SUB-SECTOR STANDARDS GOOD PRACTICES

18  BIMCO Guidelines on Cyber Security on  International Safety Management (ISM) Code)  IMO interim guidelines on maritime cyber risk board Ships - The Guidelines on Cyber management security on board ships

Water

 International Ship and Port Facility Security (ISPS) Code Transport  DNVGL-RP-0496 (DNV-GL, 2016) Cyber  ISO 27001— Information security management systems security resilience management for  ANSI/ISA, Series “ISA-62443: Security for industrial ships and mobile offshore units in automation and control system operation

http://www.imo.org/en/Publications/PublishingImages/PagesfromEB117E.pdf & http://www.imo.org/en/OurWork/humanelement/safetymanagement/pages/ismcode.aspx

Mapping of OES Security Requirements to Specific Sectors

December 2017

 IEC 62351:2017 SER - Power systems management and  Cyber-enabled ships: ShipRight associated information exchange - Data and procedure – autonomous ships communications security  Cyber-enabled ships: Deploying  IEC 61162 - Digital interfaces for navigational information and communications equipment within a ship technology in shipping – Lloyd’s  ISO 13613:2011 - Ships and marine technology -- Register’s approach to assurance Maintenance and testing to reduce losses in critical  United States coast guard – Cyber systems for propulsion Strategy Draft guidelines on maritime  ISO 14885:2014 - Large yachts -- Diesel engines for cyber risk management main propulsion and essential auxiliaries -- Safety  The Tanker Management and Self requirements Assessment (TMSA) is a best practice guide for ship operators whose latest version (TMSA 3) includes a new element about cybersecurity for both vessels and onshore

Table 9: International standards and good practices applicable in the Water Transport subsector

In the current regulatory context for the water transport subsector, either at regional or national level, there is very little consideration given to cyber security elements . According to the input taken by Water Transport operators, Table 10 illustrates the mapping of security measures to Water transport specific standards and good practices, such as:  Cybersecurity On-board Ships is a guideline for cybersecurity on board and it is made by the cooperation of BIMCO, CLIA, ICS, INTERCARGO, INTERTANKO, OCIMF and IUMI.

CYBERSECURITY ONBOARD SHIPS (BIMCO, CLIA, ICS, INTERCARGO, D/N DOMAIN NAME SECURITY MEASURE INTERTANKO, OCIMF AND IUMI)

Part 1 – Governance and Ecosystem

Information system # 2.1 Determination of vulnerability security risk analysis # 2.2 Risk assessment made by the company

Information system ─ security policy

Information System

1.1 Security Governance ─ Information system

& Risk Management

security accreditation

─ Information system security indicators

https://www.hklaw.com/publications/Coast-Guard-DHS-Mandate-Cybersecurity-Reporting-Move-to-Require-Maritime- Cybersecurity-Programs-07-20-2017/ & http://www.ubak.gov.tr/BLSM_WIYS/DISGM/tr/HTML/20130304_142647_66968_1_67502.pdf The Guidelines on Cybersecurity onboard ships refer exclusively to cybersecurity for vessels | http://www.icsshipping.org/docs/default-source/resources/safety-security-and-operations/guidelines-on-cyber-security-onboardships.pdf?sfvrsn=16

Mapping of OES Security Requirements to Specific Sectors

December 2017

CYBERSECURITY ONBOARD SHIPS (BIMCO, CLIA, ICS, INTERCARGO, D/N DOMAIN NAME SECURITY MEASURE INTERTANKO, OCIMF AND IUMI)

─ Information system security audit

Human resource # 3.2.1 Training and awareness security

#1.1 Plans and procedures Asset Management #3.1 Ship to shore interface

Ecosystem mapping # 2.3 Third party risk assessments

Ecosystem

1.2

Management

Ecosystem relations # 2.3 Third party risk assessments

Part 2 – Protection

# 3.1.1 Limitation to and control of network ports, protocols and Systems services configuration # 3.1.2 Configuration of network devices such as firewalls, routers and

switches

# 3.1.3 Secure configuration for hardware and software

# 3.1.4 Email and web browser protection

IT Security

2.1 # 3.1.10 Secure network design

Architecture

System segregation # 3.1.10 Secure network design

Traffic filtering # 3.1.5 Satellite and radio communication

Cryptography ─

IT Security Administration # 3.1.3 Secure configuration for hardware and software

Administration accounts # 3.2.4 Use of administrator privileges

2.2

Administration # 3.1.3 Secure configuration for hardware and software information systems

Authentication and # 3.1.12 Boundary defence Identity and access identification 2.3

management

Access rights ─

IT security # 3.1.9 Application software security

maintenance # 3.2.2 Upgrades and software maintenance

IT security

2.4 procedure # 3.2.3 Anti-virus and anti-malware tool updates

maintenance

Remote access # 3.1.8 Wireless access control

Physical and Physical and # 3.1.11 Physical security 2.5 environmental environmental # 3.1.12 Boundary defence security security

Part 3 - Defence

Mapping of OES Security Requirements to Specific Sectors

December 2017

CYBERSECURITY ONBOARD SHIPS (BIMCO, CLIA, ICS, INTERCARGO, D/N DOMAIN NAME SECURITY MEASURE INTERTANKO, OCIMF AND IUMI)

Detection # 3.1.6 Malware defences

─ Logging 3.1 Detection ─ Logs correlation and analysis

─ Information system security incident response

Computer security

─ 3.2 incident Incident report

management

Communication with competent # 4.3 Investigate cyber incidents authorities

Part 4 - Resilience

Business continuity # 3.1.7 Data recovery capability management # 4.1 Response Plan

Continuity of

4.1

Operations

Disaster recovery # 4.2 Recovery management

Crisis management # 3.2.7 Obtaining support from ashore and contingency plans organization 4.2 Crisis Management Crisis management # 4.2 Recovery process

Table 10: Mapping of security measures with the Water Transport sector specific standard

ISO 27001 and ANSI ISA/IEC 62443 are among the most applicable standards for network and information systems security in the domain. The mapping with these standards is provided below in section 3, Table 22. 2.2.4 Road Transport Several initiatives led to defining guidelines or rules to implement security in the automotive industry , and other initiatives asked for collaboration on the security topics from the automotive industry . Although some of them are well under development, like ISO/AWI 21434 (Road Vehicles -- Automotive Security

https://www.automotiveisac.com/best-practices/ https://wiki.unece.org/download/attachments/40009763/%28ITS_AD-10-11- Rev1%29%20Revised%20draft%20of%20guideline%20on%20cybersecurity%20and%20data%20protection.pdf?api=v2 https://www.iamthecavalry.org/domains/automotive/5star/

Mapping of OES Security Requirements to Specific Sectors

December 2017

Engineering) , safety and security considerations are currently handled by the TC22/SC3/WG16 committee under the development of ISO 26262 . Table 11 lists international standards and good practices applicable across the Road Transport subsector.

SUB-SECTOR STANDARDS GOOD PRACTICES

 SAE J3061 Cybersecurity Guidebook for Cyber- Physical Vehicle Systems  SAE J3101 Requirements for Hardware- Protected Security for Ground Vehicle Applications (WiP)  ISO 15031 Road Vehicles - Communication between. vehicle and external equipment for  ENISA Cyber Security and Resilience of smart emissions-related diagnostics. Part 7: Data link cars – ENISA security  Auto ISAC, Automotive Information Sharing and  ISO 15764 Road Vehicles - Extended data link Analysis Center, Best Practices Road security  Five Star Automotive Cyber Safety Program, I Transport  ISO/AWI 21434 - Road Vehicles -- Automotive Am The Cavalry Security Engineering  Guideline on cybersecurity and data protection  ISO 26262-1:2011 - Road vehicles -- Functional of connected vehicles and vehicles with ADT – safety UNECE  TS 102 940 Intelligent Transport Systems (ITS); Security; ITS communications security architecture and security management  TS 103 096-1 to TS 103 096-3: Intelligent Transport Systems (ITS);  TR 103 061-6 Intelligent Transport Systems (ITS); Testing; Conformance test specifications for ITS Security; Part 6: Validation report

Table 11: International standards and good practices applicable across the Road Transport subsector

According to the input taken by EU road transport operators, SAE J3061 - Cybersecurity Guidebook for Cyber- Physical Vehicle Systems has a predominant position, as it describes a cybersecurity process framework according to which an organization can develop an internal process for designing and building cybersecurity in-vehicle systems. As this standard is not publicly available, the mapping of security measures to this standard is not presented. Nevertheless, ISO 27001 is the most applicable standard for both vehicle and road-side infrastructure, while ANSI ISA/IEC 62443 is usually applied in the road side infrastructure. The mapping of the security measures to these two standards is provided below in section 3, Table 22. 2.3 Financial and Banking Table 12 lists international standards and good practices applicable across the Financial and Banking sector.

https://www.iso.org/standard/70918.html https://www.iso.org/obp/ui/#iso:std:iso:26262:-1:en

Mapping of OES Security Requirements to Specific Sectors

December 2017

SECTOR STANDARDS GOOD PRACTICES

 ISO/TR 13569:2005  Gramm–Leach–Bliley Act  Payment Card Industry Data Security Standard  Sarbanes–Oxley Act (PCI DSS)  27  Payment services (PSD 2) - Directive (EU) Basel II 2015/2366  Draft Guidelines on the security measures for Financial &  26 operational and security risks of payment services EBA on the security of internet payments Banking 28  ISO/IEC 27015:2012 Information technology - under PSD2 Security techniques – Information security  CPMI-IOSCO Guidance on cyber resilience for management guidelines for financial services financial market infrastructure  30]  American National Standards Institute (ANSI) X9 SEC OCIE Cybersecurity series

Table 12: International standards and good practices applicable across the Financial and Banking sector

According to input taken by Financial and Banking institutions in EU, Table 13, illustrates the mapping of security measures to sector specific standards and good practices, such as:  ISO/TR 13569:2005 Financial services -- Information security guidelines provides guidelines on the development of an information security programme for institutions in the financial services industry. Considerations for the selection and implementation of security controls, and the elements required to manage information security risk within a modern financial services institution are discussed.  Gramm-Leach-Bliley Act (GLB Act or GLBA) , also known as the Financial Modernization Act of 1999, is a federal law enacted in the United States to control the ways that financial institutions deal with the private information of individuals. It requires financial institutions – companies that offer consumers financial products or services like loans, financial or investment advice, or insurance – to explain their information-sharing practices to their customers and to safeguard sensitive data.  Sarbanes-Oxley Act of 2002 (SOX) is an act passed by U.S. Congress in 2002 to protect investors from the possibility of fraudulent accounting activities by corporations. The SOX Act mandated strict reforms to improve financial disclosures from corporations and prevent accounting fraud.

http://www.eba.europa.eu/regulation-and-policy/consumer-protection-and-financial-innovation/guidelines-on-the-security-ofinternet-payments

Basel II or International Convergence of Capital Measurement and Capital Standards is a set of recommendations issued by the Basel Committee on Banking Supervision. Basel II is considered by the Basel Committee to be instrumental in assessments of risk provided by banks’ internal systems as inputs to capital calculations. Its relevance is complicated, since it is partially dependant on whether or not local governments have adopted it into their local regulations (or if Basel I has), and how this adoption has occurred. [https://www.enisa.europa.eu/topics/threat-risk-management/riskmanagement/current-risk/laws-regulation/corporate-governance/basel-ii] The mapping to Basel II will be added in the next version of this document.

http://www.eba.europa.eu/documents/10180/1836621/Consultation+Paper+on+the+security+measures+for+operational+and+ security+risks+of+payment+services+under+PSD2+%28EBA-CP-2017-04%29.pdf http://www.bis.org/cpmi/publ/d146.pdf https://www.sec.gov/spotlight/cybersecurity https://www.iso.org/standard/37245.html https://www.gpo.gov/fdsys/pkg/PLAW-106publ102/pdf/PLAW-106publ102.pdf http://www.ey.com/Publication/vwLUAssets/ey-the-sarbanes-oxley-act-at-15/$File/ey-the-sarbanes-oxley-act-at-15.pdf

Mapping of OES Security Requirements to Specific Sectors December 2017  Payment services (PSD 2) - Directive (EU) 2015/2366 seeks to improve the existing EU rules for electronic payments. It takes into account emerging and innovative payment services, such as internet and mobile payments. It sets out rules concerning strict security requirements for electronic payments and the protection of consumers' financial data, guaranteeing safe authentication and reducing the risk of fraud; the transparency of conditions and information requirements for payment services; the rights and obligations of users and providers of payment services.  Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle branded credit cards from the major card schemes. The PCI Standard is mandated by the card brands and administered by the Payment Card Industry Security Standards Council. The standard was created to increase controls around cardholder data to reduce credit card fraud. Mapping of OES Security Requirements to Specific Sectors

December 2017

DOMAIN SECURITY D/N PSD2 PCI-DSS ISO/TR 13569:2005 GLBA SOX NAME MEASURE

Part 1 – Governance and Ecosystem

8.1 Processes

Information 8.2 Risk assessment system security ─ § 314.1 (a) Purpose ─ 36: process risk analysis Guideline 1

Governance 9.1 Risk mitigation

5.1 Purpose Operational and security risk 5.2 Legal and regulatory Information Security Requirement 12 § 314.1 (b) Scope Information Information management Maintain a policy that compliance Policy System system security framework addresses information § 314.3 (a) Information Security policy 5.3 Development Records Retention 1.1 security for all personnel Security Program Governance & Policy and Procedures 5.4 Documentation

Risk

hierarchy

Management

Information 8.3 Security Acquisition and Guideline 6: Testing of § 314.3 (b) (1) Security of planning process system security ─ recommendations and Customer Information security measures accreditation risk acceptance Security Standards

Information Guideline 7: Situational Requirement 11 § 314.3 (a) Information Policy and Procedure system security awareness and Regularly test security 13.2 Security compliance Security Program Compliance indicators continuous learning systems and processes

Taken from Art 95 Management of operational and Security risks Mapping of OES Security Requirements to Specific Sectors

December 2017

DOMAIN SECURITY D/N PSD2 PCI-DSS ISO/TR 13569:2005 GLBA SOX NAME MEASURE

Threat landscape and

situational awareness

Guideline 1: Post Implementation

Governance Reviews

Information Operational and Review of Security system security ─ 12.2 Audit § 314.1 (b) Scope security risk Tests audit management Policy and Procedure framework Compliance

Guideline 2: Risk

assessment 9.6 Information security Human resource ─ awareness § 314.1 (a) Purpose ─ Identification of security functions, processes 9.7 Human factors

and assets

Guideline 2: Risk

assessment Requirement 6: Develop Asset and maintain secure Management Identification of functions, processes systems and applications

and assets

Guideline 2: Risk § 314.1 (b) Scope Monitoring Third Party

assessment Services § 314.2 (b) Customer Ecosystem Ecosystem 12.4 External service 1.2 ─ Information Third Party Contracting  Identification of Management mapping providers Procedures functions, processes § 314.2 (d) Service Third Party and assets Provider Qualification

Mapping of OES Security Requirements to Specific Sectors

December 2017

DOMAIN SECURITY D/N PSD2 PCI-DSS ISO/TR 13569:2005 GLBA SOX NAME MEASURE

 Classification of Vendor Management

functions, processes Policy and assets Third Party Risk assessments of Qualification functions, processes and assets § 314.1 (b) Scope Ecosystem 12.4 External service Addressing Risks in ─ relations providers § 314.2 (b) Customer Third Party Contracts Information

Part 2 – Protection

10.1 Protecting IT Guideline 2: Risk Requirement 1 Install and maintain a firewall systems assessment configuration to protect 10.3 Software systems Systems cardholder data § 314.3 (a) Information security ─ configuration Security Program Identification of Requirement 6 Develop 10.4 Network and functions, processes and maintain secure network systems and assets systems and applications controls

IT Security

2.1

Architecture

Guideline 3: Protection 10.4 Network and System § 314.3 (a) Information Data and Systems ─ network systems ─ segregation Integrity and Security Program controls Confidentiality

Guideline 3: Protection § 314.3 (a) Information Traffic filtering ─ 12.2 Audit ─ Security Program

Mapping of OES Security Requirements to Specific Sectors

December 2017

DOMAIN SECURITY D/N PSD2 PCI-DSS ISO/TR 13569:2005 GLBA SOX NAME MEASURE

Requirement 4 Encrypt 12.6 Cryptographic

transmission of operations § 314.3 (b) (2) Protect

Cryptography ─ cardholder data across against Threats or ─ 12.7 Key management open, public networks hazards

12.8 Privacy

Guideline 3: Protection Requirement 2 Do not § 314.3 (b) (1) Security of

use vendor-supplied Customer Information

Administration defaults for system 9.3 Logical access § 314.3 (b) (3) Protect ─ accounts passwords and other control against Unauthorized security parameters Access

IT Security

2.2

Administration

Guideline 3: Protection § 314.3 (b) (1) Security of

Customer Information Administration 9.3 Logical access information ─ § 314.3 (b) (3) Protect ─ control systems against Unauthorized

Access

Requirement 8 Identify § 314.1 (b) Scope Authentication and authenticate access 9.3 Logical access § 314.3 (b) (3) Protect and to system components ─ control identification Guideline 3: Protection against Unauthorized Identity and Access

2.3 access

management

Access control Requirement 3 Protect

stored cardholder data 9.3 Logical access Review of Access Access rights § 314.1 (b) Scope control Rights Requirement 7 Restrict

access to cardholder

Mapping of OES Security Requirements to Specific Sectors

December 2017

DOMAIN SECURITY D/N PSD2 PCI-DSS ISO/TR 13569:2005 GLBA SOX NAME MEASURE

data by business need to § 314.3 (b) (3) Protect know against Unauthorized Access

Guideline 2: Risk Requirement 5 Protect assessment all systems against IT security 9.5 Change control malware and regularly § 314.2 (c) Information maintenance ─ Risk assessments of Security Program IT security update anti-virus 13.1 Maintenance 2.4 procedure functions, processes maintenance software or programs and assets

Remote access Guideline 3: Protection ─ ─ ─ ─

Guideline 3: Protection Requirement 9 Restrict § 314.1 (a) Purpose Physical and Physical and physical access to Physical Protection 11.1 Financial § 314.1 (b) Scope 2.5 environmental environmental cardholder data ─ transaction cards security security § 314.2 (c) Information Security Program

Part 3 – Defense

Guideline 2: Risk § 314.3 (a) Information Detection ─ 8.1 Detection 13.3 Monitoring assessment Security Program

3.1 Detection Requirement 10 Track § 314.1 (b) Scope Classification of and monitor all access to Logging 8.2 Logging 9.4 Audit journals functions, processes network resources and § 314.3 (a) Information and assets cardholder data Security Program

Mapping of OES Security Requirements to Specific Sectors

December 2017

DOMAIN SECURITY D/N PSD2 PCI-DSS ISO/TR 13569:2005 GLBA SOX NAME MEASURE

Logs 8.3 Logs correlation and § 314.3 (a) Information correlation and ─ ─ analysis Security Program analysis

14.1 Managing Events Information § 314.3 (b) (2) Protect system security 14.3 Incident handling Security Incident ─ against Threats or incident Response 14.4 Emergency hazards response problems

Computer § 314.3 (b) (2) Protect security Article 96 (Incident 14.2 Investigations and Security Incident 3.2 Incident report ─ against Threats or incident Reporting) forensics Response hazards

management

§ 314.3 (b) (2) Protect Communication against Threats or

with hazards Security Incident ─ 14.3 Incident handling competent Response authorities § 314.2 (c) Information

Security Program

Part 4 – Resilience

§ 314.3 (b) (2) Protect Guideline 5: Business against Threats or Business continuity Continuity of hazards 4.1 continuity ─ ─ ─ Operations Business continuity management § 314.3 (b) (1) Security of management Customer Information

Mapping of OES Security Requirements to Specific Sectors

December 2017

DOMAIN SECURITY D/N PSD2 PCI-DSS ISO/TR 13569:2005 GLBA SOX NAME MEASURE

Disaster § 314.3 (b) (2) Protect 12.3 Disaster recovery recovery ─ against Threats or ─ planning management hazards

Crisis Guideline 5: Business § 314.3 (b) (2) Protect 6.5 Incident management continuity ─ against Threats or ─ management organization hazards Business continuity Crisis 4.2 management Management Crisis § 314.3 (b) (2) Protect Incident management 6.5 Incident management ─ against Threats or ─ and crisis management process hazards communication

Table 13: Mapping with the security measures of the Financial and Banking sector specific standards

Mapping of OES Security Requirements to Specific Sectors

December 2017

2.4 Healthcare Table 14 lists international standards and good practices applicable across healthcare sector.

SECTOR STANDARDS GOOD PRACTICES

 ISO 27799:2008 Health informatics - Information security management in health using ISO/IEC 27002  Health Insurance Portability and Accountability Act (HIPPA)  ISO 13485:2003 Medical devices -- Quality management systems – Requirements for regulatory purposes  ISO 80001-1:2010 Application of risk management for IT networks incorporating medical devices  Royal Australian College of General  ETSI eHealth Standard TR 102 764 eHEALTH; Architecture; Healthcare Practitioners (RACGP) Computer Analysis of user service models, technologies and 37 Information Security Standards (CISS) applications supporting eHealth  Digital Imaging and Communications in Medicine (DICOM)  EC Medical Devices Regulation (text agreed by EP and Council – in adoption process)  NIST SP 800-66 An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Guide

Table 14: International standards and good practices applicable across Healthcare sector

According to input taken by healthcare operators in EU, Table 15, illustrates the mapping of security measures to sector specific standards and good practices, such as:  ISO 27799:2016 gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization's information security risk environment(s). It defines guidelines to support the interpretation and implementation in health informatics of ISO/IEC 27002 and is a companion to that International Standard.  Health Insurance Portability and Accountability Act of 1996 (HIPAA) required the Secretary of the U.S. Department of Health and Human Services (HHS) to develop regulations protecting the privacy and security of certain health information. The Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) establish a national set of security standards for protecting certain health information that is held or transferred in electronic form. The Security Rule operationalizes the protections contained in the Privacy Rule by addressing the technical and non-technical safeguards that organizations called “covered entities” must put in place to secure individuals’ “electronic protected health information” (e-PHI).

http://www.etsi.org/technologies-clusters/technologies/ehealth https://www.iso.org/standard/62777.html https://www.hhs.gov/hipaa/for-professionals/security/index.html?language=es https://www.hhs.gov/hipaa/for-professionals/privacy/index.html?language=es https://www.awwa.org/store/productdetail.aspx?productid=20779

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ISO 27799 HIPAA

Part 1 – Governance and Ecosystem

5.1 Management direction for Assigned Security Responsibility information security Information Security Activity 6.1 Internal organization Review Information system security risk analysis Assigned Security Responsibility

Risk analysis

Risk management

5.1 Management direction for Assigned Security Responsibility information security Information system Information Security Activity security policy 6.1 Internal organization Review

Assigned Security Responsibility

5.1 Management direction for Assigned Security Responsibility information security Information Security Activity Information system 6.1 Internal organization Review security 8.1 Responsibility for assets Assigned Security Responsibility accreditation 8.2 Information classification Risk analysis

Risk management 1.1 Information System Security Governance 5.1 Management direction for Assigned Security Responsibility & Risk Management information security Information Security Activity 6.1 Internal organization Review Information system security indicators 18.1 Compliance with legal and Assigned Security Responsibility contractual requirements Sanction policy 18.2 Information security reviews Evaluation

5.1 Management direction for Assigned Security Responsibility information security Information Security Activity 6.1 Internal organization Review Information system 7.1 Prior to employment Assigned Security Responsibility security audit 7.2 During employment

7.3 Termination and change of employment

5.1 Management direction for Assigned Security Responsibility information security Information Security Activity Human resource 6.1 Internal organization Review security 7.1 Prior to employment Workforce clearance procedure

7.2 During employment Termination procedures

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ISO 27799 HIPAA

7.3 Termination and change of Sanction policy employment Security Training 15.2 Supplier service delivery Response and reporting management Protection from malicious 18.1 Compliance with legal and software contractual requirements Written Contract or Other Arrangement

8.1 Responsibility for assets Integrity Controls 8.2 Information classification Mechanism to Authenticate Electronic Protected Health 8.3 Media Handling Information Accountability Asset Management Device and Media Controls

Disposal Encryption and Decryption

Encryption

15.1 Information security in supplier relationships Ecosystem mapping ─ 15.2 Supplier service delivery management

Ecosystem

1.2

Management

15.1 Information security in supplier relationships Ecosystem relations ─ 15.2 Supplier service delivery management

Part 2 – Protection

Systems 13.1 Network security configuration management ─ 13.2 Information transfer

System segregation 13.1 Network security management ─ IT Security 13.2 Information transfer 2.1

Architecture

Traffic filtering 13.1 Network security management ─ 13.2 Information transfer

Cryptography 13.1 Network security ─ management

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ISO 27799 HIPAA

13.2 Information transfer

IT Security Administration ─ ─ Administration accounts 2.2 Administration ─ ─ information systems

Authentication and 9.1 Business requirements of Access authorization identification access control Termination Procedures 9.2 User access management Unique User Identification 9.3 User responsibilities Access Establishment and 9.4 System and application access Modification control Authorization and/or supervision

Unique User Identification

Person or Entity Authentication

Automatic Logoff

Workstation use

Identity and access

2.3

management

Access rights 9.1 Business requirements of Access authorization access control Termination Procedures 9.2 User access management Unique User Identification 9.3 User responsibilities Access Establishment and 9.4 System and application access Modification control Authorization and/or supervision

Unique User Identification

Person or Entity Authentication

Automatic Logoff

Workstation use

IT security 12.5 Control of operational Integrity Controls maintenance software Mechanism to Authenticate procedure 12.6 Technical vulnerability Electronic Protected Health IT security management Information 2.4

maintenance

Remote access 13.1 Network security Person or Entity Authentication management

13.2 Information transfer

Physical and Physical and 11.1 Secure areas Physical Safeguards environmental 2.5 environmental 11.2 Equipment Access Control and Validation security security Procedures

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ISO 27799 HIPAA

Authorization and/or supervision Workstation Use

Workstation Security Disposal

Media Re-use Accountability

Part 3 - Defence

Detection 12.4 Logging and monitoring Information Security Activity Review

Logging 12.4 Logging and monitoring Audit controls 12.7 Information systems audit 3.1 Detection considerations

Logs correlation and 12.4 Logging and monitoring  Audit controls analysis 12.7 Information systems audit considerations

Information system 16.1 Management of information Information Security Activity security incident security incidents and Review response improvements Protection Against Malicious Software

Data Backup Plan Computer security Testing and Revision Procedures 3.2 incident

management

Incident report 16.1 Management of information Information Security Activity security incidents and Review improvements

Communication with competent ─ ─ authorities

Part 4 - Resilience

Business continuity 17.1 Information security Contingency Plan management continuity Testing and Revision Procedures 17.2 Redundancies Disaster Recovery Plan

Continuity of

4.1 Applications and Data Criticality

Operations

Analysis

Disaster recovery 17.1 Information security Disaster Recovery Plan management continuity

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ISO 27799 HIPAA

17.2 Redundancies

Crisis management 17.1 Information security Contingency Plan organization continuity Testing and Revision Procedures 17.2 Redundancies Disaster Recovery Plan Applications and Data Criticality Analysis 4.2 Crisis Management Crisis management 17.1 Information security Contingency Plan process continuity Testing and Revision Procedures 17.2 Redundancies Disaster Recovery Plan Applications and Data Criticality Analysis

Table 15: Mapping of security measures with Healthcare sector specific standards

2.5 Drinking Water Supply & Distribution Table 16 below, lists international information security standards and good practices applicable to the Drinking Water Supply and Distribution sector.

SECTOR STANDARDS GOOD PRACTICES

 ISO 27001 Information technology — Security techniques — Drinking  ANSI/AWWA G430-09/“Security Water Information security management systems — Requirements Practices for Operations and  ANSI/ISA, Series “ISA-62443: Security for industrial Supply and Management” Distribution automation and control system”

Table 16: International standards and good practices specific to the Drinking Water Supply & Distribution sector

According to the input by EU drinking water operators, the most applicable standards for this sector are ISO-27001 and ISA/IEC62443, for which the mapping with the security measures is presented in section 3, Table 22. Nevertheless, it’s worth mentioning the standard ANSI/AWWA G430-09/“Security Practices for Operations and Management” published by the American Water Works Association which purpose is to define the minimum requirements for a protective security program for a water or wastewater utility, that will promote the protection of employee safety, public health, public safety, and public confidence. The ANSI/AWWA G430-09 standard is applied in United States and it is not publicly available. 2.6 Digital Infrastructures Table 17 lists international standards and good practices specific to the Digital Infrastructures.

https://www.iso.org/standard/43751.html

Mapping of OES Security Requirements to Specific Sectors

December 2017

SECTOR STANDARDS GOOD PRACTICES

 Technical guidance on the security  ISO/IEC 27011:2008 Information technology -- Security Digital measures for Telcos in Article 13a, techniques -- Information security management guidelines ENISA Infrastructure for telecommunications organizations based on ISO/IEC  Best Practices – IX-F 27002

Table 17: International standards and good practices specific to the Digital Infrastructures sector

According to input taken by Digital Infrastructures operators in EU, Table 18, illustrates the mapping of security measures to sector specific standards, such as:  ISO/IEC 27011:2008 which refers to Information security management guidelines for telecommunications organizations and it is based on ISO/IEC 27001:2013.

D/N DOMAIN NAME SECURITY MEASURE ISO 27011

Part 1 – Governance and Ecosystem

Information system ─ security risk analysis

# 4.2 Information security management systems in telecommunications Information system business security policy # 5. Security Policy

Information system ─ security accreditation

Information System

1.1 Security Governance Information system ─

& Risk Management

security indicators

Information system ─ security audit

# 8.1 Prior to employment Human resource # 8.2 During employment security # 8.3 Termination or change of employment

Asset Management 7. Asset management

# 6.1 Internal organization Ecosystem mapping # 6.2 External Parties

Ecosystem

1.2

Management

# 6.2 External Parties Ecosystem relations # 10.2 Third party service delivery management

Part 2 – Protection

ISO/IEC 27011:2008 - Information security management guidelines for telecommunications organizations based on ISO/IEC 27002; URL: https://www.iso.org/standard/43751.html Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ISO 27011

Systems # 12.1 Security requirements of information systems configuration # 12.2 Correct processing in applications

IT Security System segregation # 10.6 Network security management 2.1

Architecture

Traffic filtering # 10.8 Exchange of information

Cryptography # 12.3 Cryptographic controls

Administration # 11.2 User access management accounts

IT Security

2.2

Administration

Administration # 11.2 User access management information systems

Authentication and # 11.1 Business requirement for access control identification # 11.4 Network access management # 11.5 Operating system access control

Identity and access

2.3 # 11.6 Application and information access control

management

Access rights # 11.2 User access management # 11.3 User responsibilities

IT security maintenance ─

IT security

2.4 procedure

maintenance

Remote access # 11.7 Mobile Computing and teleworking

Physical and Physical and # 9.1 Secure areas 2.5 environmental environmental security security # 9.2 Equipment security

Part 3 - Defence

Detection # 10.10 Monitoring

Logging # 10.10 Monitoring 3.1 Detection

Logs correlation and # 10.10 Monitoring analysis

Information system # 13.2 Management of information security incidents and Computer security security incident improvements 3.2 incident response

management

Incident report # 13.1 Reporting information security events and weaknesses

Mapping of OES Security Requirements to Specific Sectors

December 2017

D/N DOMAIN NAME SECURITY MEASURE ISO 27011

Communication with competent ─ authorities

Part 4 - Resilience

Business continuity # 14.1 Information security aspects of business continuity management management

Continuity of

4.1

Operations

Disaster recovery # 14.1 Information security aspects of business continuity management management

Crisis management ─ 4.2 organization

Crisis Management

Crisis management ─ process

Table 18: Mapping of security measures with Digital Infrastructure sector specific standard

Mapping of OES Security Requirements to Specific Sectors 2.7 Matching of baseline security measures with sectors Table 19 summarizes the matching of the proposed security measures with sector-specific international standards, regulations and well accepted good practices of Energy and Transport sector, that were presented in more details above.

ENERGY TRANSPORT

DOMAIN SECURITY ELECTRICITY OIL & GAS AIR RAIL WATER ROAD NAMES MEASURES NIST SP API STD ONG- (TABLE (TABLE ISO 27019 NERC CIP ICAO AIAA BIMCO 800-82 1164 C2M2 22) 22)

Part 1 – Governance and Ecosystem

Information system security ● ● ● ● ● ● ● ─ ● ─ risk analysis

Information system security ● ● ● ● ● ● ● ─ ─ ─ policy

Information

Information

system security ● ─ ─ ─ ─ ● ● ─ ─ ─

System Security

accreditation

Governance & Risk

Information

Management

system security ● ─ ─ ─ ─ ─ ─ ─ ─ ─ indicators

Information system security ● ● ● ● ─ ─ ─ ─ ─ ─ audit

Human resource ● ● ● ● ● ─ ● ─ ● ─ security

Mapping of OES Security Requirements to Specific Sectors

ENERGY TRANSPORT

DOMAIN SECURITY ELECTRICITY OIL & GAS AIR RAIL WATER ROAD NAMES MEASURES NIST SP API STD ONG- (TABLE (TABLE ISO 27019 NERC CIP ICAO AIAA BIMCO 800-82 1164 C2M2 22) 22)

Asset ● ● ● ● ● ● ● ─ ● ─ Management

Ecosystem ─ ● ─ ● ● ● ● ─ ● ─ mapping

Ecosystem Management

Ecosystem ─ ● ─ ● ● ● ● ─ ● ─ relations

Part 2 – Protection

Systems ● ● ● ● ● ● ─ ─ ● ─ configuration

System IT Security ● ● ● ● ─ ● ● ─ ● ─ segregation

Architecture

Traffic filtering ● ● ─ ● ─ ● ● ─ ● ─

Cryptography ● ● ● ● ─ ● ● ─ ─

Administration ● ● ● ● ● ─ ● ─ ● ─ accounts

IT Security

Administration Administration information ─ ● ● ● ─ ─ ─ ─ ● ─ systems

Mapping of OES Security Requirements to Specific Sectors

ENERGY TRANSPORT

DOMAIN SECURITY ELECTRICITY OIL & GAS AIR RAIL WATER ROAD NAMES MEASURES NIST SP API STD ONG- (TABLE (TABLE ISO 27019 NERC CIP ICAO AIAA BIMCO 800-82 1164 C2M2 22) 22)

Authentication Identity and and ● ● ● ● ● ● ─ ─ ● ─ access identification

management

Access rights ● ● ● ● ● ● ─ ─ ─

IT security maintenance ● ● ● ● ─ ● ── ─ ● ─

IT security

procedure

maintenance

Remote access ● ● ● ● ─ ● ─ ─ ● ─

Physical and Physical and environmental environmental ● ● ● ● ─ ─ ─ ─ ● ─ security security

Part 3 - Defence

Detection ● ─ ● ● ● ● ● ─ ● ─

Logging ● ● ● ● ● ● ─ ─ ─

Detection

Logs correlation ● ● ● ● ─ ● ─ ─ ─ and analysis

Information

Computer

system security security incident ● ● ● ● ● ● ● ─ ─ ─ incident

management

response

Mapping of OES Security Requirements to Specific Sectors

ENERGY TRANSPORT

DOMAIN SECURITY ELECTRICITY OIL & GAS AIR RAIL WATER ROAD NAMES MEASURES NIST SP API STD ONG- (TABLE (TABLE ISO 27019 NERC CIP ICAO AIAA BIMCO 800-82 1164 C2M2 22) 22)

Incident report ● ● ● ─ ● ● ● ─ ─ ─

Communication with competent ─ ● ● ● ● ● ● ─ ● ─ authorities

Part 4 - Resilience

Business continuity ● ● ● ● ● ● ─ ─ ● ─ management

Continuity of Operations

Disaster recovery ● ● ● ─ ─ ● ─ ─ ● ─ management

Crisis management ● ● ● ─ ─ ● ─ ─ ● ─ organization

Crisis Management

Crisis management ● ● ● ─ ─ ● ─ ─ ● ─ process

Table 19: Overview of the proposed security measures with Energy and Transport sector-specific international standards, regulations and good-practices

Table 20 summarizes the matching of the proposed security measures with sector-specific international standards, regulations and well accepted good practices of Financial & Banking, Healthcare, Drinking Water and Digital Infrastructures sectors, that were presented in more details above. Mapping of OES Security Requirements to Specific Sectors

DRINKING WATER SUPPLY DIGITAL FINANCIAL AND BANKING HEALTHCARE AND INFRASTRUCTURES DOMAIN SECURITY DISTRIBUTION NAMES MEASURES

ISO/TR PSD2 PCI-DSS 13569:20 GLBA ISO2779 ISO 27011 SOX HIPAA (Table 22) 05 9

Part 1 – Governance and Ecosystem

Information system security ● ─ ● ● ─ ● ● ─ ─ risk analysis

Information system security ● ● ● ● ● ● ● ─ ● policy

Information system security ● ─ ● ● ● ● ● ─ ─ Information accreditation

System

Security Information Governance & system security ● ● ● ● ● ● ● ─ ─ Risk indicators

Management

Information system security ● ─ ● ● ● ● ● ─ ─ audit

Human resource ● ─ ● ● ─ ● ● ─ ● security

Asset ● ● ● ● ─ ● Management

Mapping of OES Security Requirements to Specific Sectors

Ecosystem ● ─ ● ● ● ● ─ ─ ● mapping

Ecosystem Management

Ecosystem ● ─ ● ● ● ● ─ ─ ● relations

Part 2 - Protection

Systems ● ● ● ● ─ ● ─ ─ ● configuration

System IT Security ● ─ ● ● ─ ● ─ ─ ● segregation

Architecture

Traffic filtering ● ─ ● ● ─ ● ─ ─ ●

Cryptography ● ● ● ─ ● ─ ─ ●

Administration ● ● ● ● ─ ─ ─ ─ ● accounts

IT Security

Administration Administration information ● ─ ● ● ─ ─ ─ ─ ● systems

Authentication Identity and and ● ● ● ● ─ ● ● ─ ● access identification

management

Access rights ● ● ● ● ● ● ● ─ ●

IT security maintenance ● ● ● ● ─ ● ● ─ ─

IT security

procedure

maintenance

Remote access ● ─ ─ ─ ─ ● ● ─ ●

Mapping of OES Security Requirements to Specific Sectors

Physical and Physical and environmental environmental ● ● ● ● ─ ● ● ─ ● security security

Part 3 - Defence

Detection ● ─ ● ● ● ● ● ─ ●

Logging ● ● ● ● ● ● ● ─ ●

Detection

Logs correlation ● ─ ● ─ ● ● ● ─ ● and analysis

Information system security ● ─ ● ● ● ● ● ─ ● incident Computer response

security

incident Incident report ● ─ ● ● ● ● ● ─ ●

management

Communication with competent ● ─ ● ● ● ─ ─ ─ ─ authorities

Part 4 - Resilience

Business continuity ● ─ ─ ● ─ ● ● ─ ● management

Continuity of Operations

Disaster recovery ● ─ ● ● ─ ● ● ─ ● management

Crisis

Crisis

management ● ─ ● ● ─ ● ● ─ ─

Management

organization

Mapping of OES Security Requirements to Specific Sectors

Crisis management ● ─ ● ● ─ ● ● ─ ─ process

Table 20: Overview of the proposed security measures with Energy and Transport sector-specific international standards, regulations and good-practices

Mapping of OES Security Requirements to Specific Sectors

3 Mapping the Baseline Security Measures for OES to cross sector international standards

Table 21 lists international standards and good practices applicable across all the sectors referred to in the NIS Directive.

SECTOR STANDARDS GOOD PRACTICES

 ANSI/ISA, Series “ISA-62443: Security for industrial

automation and control system”

 ISO 27001 Information Technology Security

Techniques Information Security Management Systems Requirements

 NIST Framework for Improving Critical Infrastructure

Cybersecurity

 ISO/IEC 27002:2013: Code of practice for information security controls  ISO 27003 - Information technology -- Security techniques -- Information security management system  The CIS Critical Security Controls for implementation guidance Effective Cyber Defence Version 6.1  ISO/IEC 27004:2016 Information technology -- Security  Organisation for Economic Co-operation techniques -- Information security management -- and Development (OECD), Guidelines for Monitoring, measurement, analysis and evaluation the Security of Information Systems and  ISO/IEC 20000-1:2011 Information technology -- Service Networks, 2002, management -- Part 1: Service management system  Generally Accepted Information Security requirements Principles (GAISP) – ISSA  ISO/IEC 27010:2015 Information technology -- Security  The Open Group Open Information techniques -- Information security management for Security Management Maturity Model inter-sector and inter-organizational communications (O-ISM3) Cross sector  ISO/IEC 21827:2008 Information technology -- Security  ISACA BMIS techniques -- Systems Security Engineering -- Capability  IT Baseline Protection Manual Standard Maturity Model® (SSE-CMM®) Security Measures – BSI  ISO/IEC 10181-2:1996 Information technology -- Open  UK Cyber Essentials (CREST) Systems Interconnection -- Security frameworks for  Cyber Defence Capability Assessment open systems: Authentication framework Tool (CDCAT®) – CESG  ISO/IEC 27013:2015 Information technology -- Security  HMG Security Policy Framework (SPF) – techniques -- Guidance on the integrated CESG implementation of ISO/IEC 27001 and ISO/IEC 20000-1  NIST/NSA/DISA/DoD Security Technical  ISO/IEC 27014:2013 Information technology — Security Implementation Guides (STIGs) techniques — Governance of information security  Carnegie Melon Capability Maturity  ISO/IEC 27032:2012 Information technology -- Security Model (CMM) techniques -- Guidelines for cybersecurity  ISO/IEC 27033-1:2015 Information technology -- Security techniques -- Network security -- Part 1: Overview and concepts  ISO/IEC 27034-1:2011 Information technology -- Security techniques -- Application security -- Part 1: Overview and concepts  ISO/IEC TR 19791:2010 Information technology -- Security techniques -- Security assessment of operational systems

Mapping of OES Security Requirements to Specific Sectors

 European Telecommunications Standards Institute (ETSI) Cybersecurity Standards  TR 103 303 - TR 103 309 CYBER series  TR 103 331 CYBER; Structured threat information sharing  TR 103 369 CYBER; Design requirements ecosystem  TS 103 487 CYBER; Baseline security requirements regarding sensitive functions for NFV and related platforms  IT Infrastructure Library (ITIL) v3  NIST SP 800-53  Information Assurance for SMEs (IASME)  ISF Standard of Good Practice for Information Security  ITU X series : Information security management framework

Table 21: International standards and good practices applicable across all the sectors

The Table 22 depicts the mapping of the information security measures identified and agreed in the NIS Directive Cooperation Group to the international information security standards applied to all the sectors referred to in the NIS Directive. The standards and good practices, that are usually applied by the operators of all the sectors referred to in the NIS Directive, were identified through the survey filled in by the Cooperation Group representatives, as well as by the feedback provided by EU operators, are:  ISO 27001 Revision 2013, which is the most globally widespread standard covering all aspects of information security management systems across all the sectors.  ISA/IEC 62443, which is a series of standards that define procedures for implementing electronically secure Industrial Automation and Control Systems (IACS). This guidance applies to end-users (i.e. asset owner), system integrators, security practitioners, and control systems manufacturers responsible for manufacturing, designing, implementing, or managing industrial automation and control systems.  NIST Cybersecurity Framework, which despite the fact that is not compulsory even in the U.S., it is usually followed by EU operators that work beyond EU’s territory as it is a good point of reference for cybersecurity requirements.

NIST CYBER D/N DOMAIN NAME SECURITY MEASURE ISO 27001:2013 SECURITY ISA/IEC 62443 3-3 FRAMEWORK

Part 1 – Governance and Ecosystem

# 8.2 Information security risk assessment (ISO ID.GV-4 Information system 27001) ID.RA-1,2,3,4,5,6 SR 5.2, 5.3, security risk analysis # 8.3 Information D.RM-1,2,3

Information System

security risk PR.AT-2 1.1 Security Governance treatment (ISO

& Risk Management

27001)

# 5.1 Management Information system direction for ID.GV-1,2,3 ─ security policy information security

Mapping of OES Security Requirements to Specific Sectors

NIST CYBER D/N DOMAIN NAME SECURITY MEASURE ISO 27001:2013 SECURITY ISA/IEC 62443 3-3 FRAMEWORK

Information system # 12.7.1 Information security systems audit ─ SR 2.8, 2.9, 2.10, 2.12 accreditation controls

Information system # 12.1.3.Capacity ─ SR 1.4, 3.9, 6.1 security indicators Management

Information system # 9.2 Internal Audit SR 2.8, 2.9, 2.10, PR.PT-1 security audit (ISO 27001) 2.11, 2.12, 3.9,

# 7.1 Prior to employment # 7.2 During Human resource employment PR.AT-1,2,3,4,5 SR 1.1 security # 7.3 Termination and change of employment

PE-20 Asset Monitoring and A.8 Asset Tracking SR 7.2 – Resource Asset Management management CM-8 Information management System Component Inventory

# 15.1 Information Ecosystem mapping security in supplier ID.BE-1,2 ─ relationships

Ecosystem

1.2

Management

# 15.2 Supplier ID.BE-3,4 Ecosystem relations service delivery SR 1.1, 1.13, 2.6 PR.AT-3 management

Part 2 – Protection

Systems # 12.1.1 configuration Documented SR 2.5, 2.6, 2.7, 3.4, operating procedures PR.IP-1,3 3.5, 3.6, 3.7, 7.6, 7.7 # 12.5 Control of operational software

System segregation # 13.1 Network PR.AC-5 security management

IT Security

2.1

Architecture

Traffic filtering # 12.5 Control of operational software # 12.6 Technical ─ SR 6.2, 7.1, 7,2 vulnerability management

Cryptography # 10.1 Cryptographic ─ SR 1.8, 1.9, controls

Mapping of OES Security Requirements to Specific Sectors

NIST CYBER D/N DOMAIN NAME SECURITY MEASURE ISO 27001:2013 SECURITY ISA/IEC 62443 3-3 FRAMEWORK

Administration # 9.2 User access PR.AT-2 SR 1.3, 1.4, accounts management

IT Security

2.2 Administration Administration # 9.4 System and

information systems application access PR.AT-2 SR 2.1,

control

Authentication and # 9.1 Business SR 1.1, 1.2, 1.5, 1.7, identification requirements of PR.AC-1 1.10, 1.11 Identity and access access control 2.3

management

Access rights # 9.2 User access ID.AM-5,6 SR 2.1, 2.5, management PR.AC-1,4

IT security # 14.1 Security

maintenance requirements of

procedure information systems PR.IP-2 SR 3.3, 3.4, 3.7 # 14.2 Security in PR.MA-1,2

IT security

2.4 development and

maintenance

support processes

Remote access # 6.2 Mobile devices PR.AC-3 SR 1.6, 1.13, 2.2, 2.6, and teleworking

Physical and Physical and #11.1 Secure areas PR.AC-2 2.5 environmental environmental SR 1.1, 1.5 #11.2 Equipment PR.IP-5 security security

Part 3 - Defence

Detection DE.AE-1 # 12.4 Logging and DE.CM-1,2,3,4,5,6,7,8 SR 3.1, 3.2 monitoring DE.DP-1,2,3,4,5

3.1 Detection Logging # 12.4 Logging and DE.CM-1 SR 6.1 monitoring

Logs correlation and # 12.4 Logging and DE.CM-1 SR 6.1 analysis monitoring

Information system # 16.1.4

security incident Management of DE.AE-2,3,4,5

response information security RS.AN-1,2,3,4

incidents and

Computer security

improvements 3.2 incident SR 6.1, 6.2 PR.IP-9 management # 16.1.5 Response to RS.RP-1 information security RS.CO-1 incidents RS.MI-1,2,3

Mapping of OES Security Requirements to Specific Sectors

NIST CYBER D/N DOMAIN NAME SECURITY MEASURE ISO 27001:2013 SECURITY ISA/IEC 62443 3-3 FRAMEWORK

Incident report # 16.1.5 Response to information security RS.CO-1,2,3,4,5 SR 6.2 incidents

Communication with competent ─ ─ ─ authorities

Part 4 - Resilience

Business continuity ID.BE-5 # 17.1 Information management PR.DS-4 SR 7.3, 7.4 security continuity Continuity of PR.IP-4 4.1

Operations

Disaster recovery PR.DS-4 # 17.2 Redundancies SR 7.4, 7.5 management PR.IP-10

Crisis management # 17.1 Information PR.DS-4 SR 7.4, 7.5 organization security continuity PR.IP-10 4.2 Crisis Management Crisis management # 17.1 Information PR.DS-4 SR 7.4, 7.5 process security continuity

Table 22: Mapping of the information security measures to the international information security standards applied to all the sectors

ENISA

European Union Agency for Network and Information Security Science and Technology Park of Crete (ITE) Vassilika Vouton, 700 13, Heraklion, Greece

Athens Office

1 Vasilissis Sofias Marousi 151 24, Attiki, Greece Catalogue Number PO Box 1309, 710 01 Heraklion, Greece ISBN 978-92-9204-232-5, DOI 10.2824/844702 Tel: +30 28 14 40 9710 info@enisa.europa.eu www.enisa.europa.eu

Fotnoter

  1. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  2. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  3. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  4. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  5. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  6. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  7. th The NIS Directive was adopted by the European Parliament on the 6 of July, 2016 and entered into force in August 2016. Member States have 21 months to transpose the Directive into their national legislation and 6 more months to identify operators of essential services.
  8. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  9. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  10. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  11. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  12. 3 These documents were originally referred to as ANSI/ISA-99 or ISA99 standards, as they were created by the International Society for Automation (ISA) and publicly released as American National Standards Institute (ANSI) documents. In 2010, they were renumbered to be the ANSI/ISA-62443 series. This change was intended to align the ISA and ANSI document numbering with the corresponding International Electrotechnical Commission (IEC) standards https://en.wikipedia.org/wiki/Cyber_security_standards 4 https://www.isa.org/store/ansi/isa-62443-3-3-990303-2013-security-for-industrial-automation-and-control-systems-part-3-3system-security-requirements-and-security-levels/116785 The Version 1.0 of the NIST Cybersecurity Framework was taken into account for the mapping it, as the newest version of the framework is still in draft status. 6 https://www.nist.gov/sites/default/files/documents/cyberframework/cybersecurity-framework-021214.pdf
  13. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  14. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  15. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  16. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  17. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency
  18. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  19. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  20. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  21. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  22. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  23. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  24. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  25. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  26. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  27. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  28. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  29. 14 https://www.enisa.europa.eu/publications/good-practices-recommendations 15 https://ics-cert.us-cert.gov/sites/default/files/documents/TransportationRoadmap20120831.pdf 16 http://www.icao.int/Security/SFP/Pages/SecurityManual.aspx 17 https://www.hklaw.com/publications/Coast-Guard-DHS-Mandate-Cybersecurity-Reporting-Move-to-Require-Maritime- Cybersecurity-Programs-07-20-2017/
  30. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  31. European Union Agency for Network and Information Security
  32. ENISA - The EU Cyber Security Agency
  33. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  34. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  35. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  36. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  37. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  38. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  39. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  40. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  41. 34 https://ec.europa.eu/info/law/payment-services-psd-2-directive-eu-2015-2366_en 35 https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf
  42. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  43. European Union Agency for Network and Information Security
  44. ENISA - The EU Cyber Security Agency
  45. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  46. European Union Agency for Network and Information Security
  47. ENISA - The EU Cyber Security Agency
  48. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  49. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  50. European Union Agency for Network and Information Security
  51. ENISA - The EU Cyber Security Agency
  52. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  53. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  54. European Union Agency for Network and Information Security
  55. ENISA - The EU Cyber Security Agency
  56. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  57. European Union Agency for Network and Information Security
  58. ENISA - The EU Cyber Security Agency
  59. Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  60. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  61. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  62. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  63. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  64. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  65. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  66. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  67. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds
  68. European Union Agency for Network and Information Security ENISA - The EU Cyber Security Agency Follow the EU cyber security affairs of ENISA: www.enisa.europa.eu & Facebook, Twitter, LinkedIn, YouTube, RSS feeds