{"title":"安全与保障:工业实践中的紧张领域","authors":"Siegfried Hollerer, W. Kastner, T. Sauter","doi":"10.1109/INDIN51400.2023.10217900","DOIUrl":null,"url":null,"abstract":"The convergence of Information Technology (IT) and Operational Technology (OT) leads to an increasing interdependence between the protection goals of security and safety. A cyber-attack targeting safety functions may in turn lead to hazards endangering people and the environment. Furthermore, misusing safety functions may impact availability by causing a machine or production line to stop working. This work analyzes how Austrian stakeholders of industrial automation enterprises address security and safety risks to mitigate undesired situations. The stakeholder analysis performed considers vendors of products or components, integrators, and asset owners of industrial systems. Secure infrastructures, system architectures, and risk management are subject areas of this analysis. The analysis was conducted in two phases. First, an online survey was created where the involved stakeholder offered their answer simultaneously. Considering the results of the survey, individual stakeholder workshops were carried out to obtain additional, more specific perceptions about the stakeholder’s OT system and components with respect to security and safety considerations. The obtained results provide insights into the current practices in the industry regarding safety and security.","PeriodicalId":174443,"journal":{"name":"2023 IEEE 21st International Conference on Industrial Informatics (INDIN)","volume":"55 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-07-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"Safety and Security: A Field of Tension in Industrial Practice\",\"authors\":\"Siegfried Hollerer, W. Kastner, T. Sauter\",\"doi\":\"10.1109/INDIN51400.2023.10217900\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The convergence of Information Technology (IT) and Operational Technology (OT) leads to an increasing interdependence between the protection goals of security and safety. A cyber-attack targeting safety functions may in turn lead to hazards endangering people and the environment. Furthermore, misusing safety functions may impact availability by causing a machine or production line to stop working. This work analyzes how Austrian stakeholders of industrial automation enterprises address security and safety risks to mitigate undesired situations. The stakeholder analysis performed considers vendors of products or components, integrators, and asset owners of industrial systems. Secure infrastructures, system architectures, and risk management are subject areas of this analysis. The analysis was conducted in two phases. First, an online survey was created where the involved stakeholder offered their answer simultaneously. Considering the results of the survey, individual stakeholder workshops were carried out to obtain additional, more specific perceptions about the stakeholder’s OT system and components with respect to security and safety considerations. The obtained results provide insights into the current practices in the industry regarding safety and security.\",\"PeriodicalId\":174443,\"journal\":{\"name\":\"2023 IEEE 21st International Conference on Industrial Informatics (INDIN)\",\"volume\":\"55 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-07-18\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2023 IEEE 21st International Conference on Industrial Informatics (INDIN)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/INDIN51400.2023.10217900\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2023 IEEE 21st International Conference on Industrial Informatics (INDIN)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/INDIN51400.2023.10217900","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
Safety and Security: A Field of Tension in Industrial Practice
The convergence of Information Technology (IT) and Operational Technology (OT) leads to an increasing interdependence between the protection goals of security and safety. A cyber-attack targeting safety functions may in turn lead to hazards endangering people and the environment. Furthermore, misusing safety functions may impact availability by causing a machine or production line to stop working. This work analyzes how Austrian stakeholders of industrial automation enterprises address security and safety risks to mitigate undesired situations. The stakeholder analysis performed considers vendors of products or components, integrators, and asset owners of industrial systems. Secure infrastructures, system architectures, and risk management are subject areas of this analysis. The analysis was conducted in two phases. First, an online survey was created where the involved stakeholder offered their answer simultaneously. Considering the results of the survey, individual stakeholder workshops were carried out to obtain additional, more specific perceptions about the stakeholder’s OT system and components with respect to security and safety considerations. The obtained results provide insights into the current practices in the industry regarding safety and security.