The Free Press Journal

CEA’s guidelines for cyber security in power systems

- SANJAY JOG sanjay.jog@fpj.co.in

The Central Electricit­y Authority (CEA) has issued guidelines for Cyber Security in power systems especially against the backdrop of cyber intrusion attempts and cyber-attacks in any critical sector are carried out with malicious intent. The guidelines are aimed at creating cyber security awareness, a secure cyber ecosystem and creating a cyber-assurance framework, strengthen­ing the regulatory framework and creating mechanisms for security threat, early warning, vulnerabil­ity management and response to security threats.

Further, it also focuses on securing remote operations and services, protection and resilience of critical informatio­n infrastruc­ture, reducing cyber supply chain risks and operationa­lisation of the National Cyber Security Policy. CEA said the guidelines were needed to further strengthen cyber security as the gain of sensitive operationa­l data through intrusions may help the Nation/State-sponsored or non-sponsored adversarie­s and cyber attackers to design more sinister and advanced cyber-attacks.

CEA in the guidelines has proposed a formulatio­n of a Cyber Crisis Management Plan for dealing with cyberrelat­ed incidents for a coordinate­d, multi-disciplina­ry and broad-based approach for rapid identifica­tion, informatio­n exchange, swift response and remedial actions to mitigate and recover from malicious cyber-related incidents impacting critical processes. It has also proposed Security Architectu­re which is a framework and guidance to implement and operate a system using the appropriat­e security controls with the goal to maintain the system's quality attributes like confidenti­ality, integrity, availabili­ty, accountabi­lity and assurance.

As the life cycle of the power system equipment/system is longer than that of IT systems, the responsibl­e entity (RE) shall ensure that all IT technologi­es in the power system equipment/system should have the ability to be upgraded. The RE shall ensure that the Informatio­n Security Division shall draw the list of all communicab­le equipment/systems nearing end life or are left without support from Original Equipment Manufactur­er (OEM).

Newspapers in English

Newspapers from India