Øyvind Anders Arntzen Toftegaard

dblp:224/9512 · DBLP profile ↗
← Back
2ranked-venue papers in the field
1as first author
2since 2021 · last 2022
—ORCID · none

Domains — venue-derived; a paper can count in several

Big Data, Cloud & Distributed Data Systems · 2 (1 first)
YearPublicationVenuePosition
2022 An Effect Analysis of ISO/IEC 27001 Certification on Technical Security of Norwegian Grid Operators
abstract
Digital vulnerabilities and the risk of cyberattacks against the electric grid are a concern for both governments and businesses. There are several opportunities for authorities to impose security measures on grid operators to reduce risks. German legislation requires grid operators to certify their information security management system according to the ISO/IEC 27001 standard. Some researchers have tried to measure various effects of ISO/IEC 27001 certification, but nobody has so far assessed the effect of certification on technical security performance. This study hypothesizes that ISO/IEC 27001 certification will lead to increased technical security performance for Norwegian grid operators. A Quasi-Experimental methodology based on Difference in Differences logic is applied to test the hypothesis. 11.010 technical security scores from 400 entities were collected through BlackKite’s Technical Cyber Rating tool and Security Scorecard’s Security Rating tool. The effect of ISO/IEC 27001 certification was estimated by taking the difference in technical security performance between uncertified Norwegian grid operators and certified German grid operators, and subtracting the difference between a control group of Norwegian and German banks. The analysis predicts a significant positive effect for small Norwegian grid operators, it is inconclusive for medium-sized grid operators, and it indicates a negative effect for large grid operators. Since the research was limited to externally identifiable security mechanisms only, more research is necessary to fully understand the effect of ISO/IEC 27001 certification on technical security performance.
Øyvind Anders Arntzen Toftegaard
IEEE Big Data1
2021 A Survey of Using Process Data and Features of Industrial Control Systems in Intrusion Detection
abstract
Protecting industrial control systems against cyber threats has become more pressing in the last decades. An increasing number of released vulnerabilities specifically targeting industrial systems makes protecting them exceedingly challenging. Incident detection is essential in protecting industrial systems, and this paper examines the state of the art in this area. The focus is on the research aspect, and the paper investigates "How has the research on the detection of cyber threats in industrial control systems evolved over the years?" This survey has explored research covering incident detection in industrial control systems from 1950 until today and reviewed a total of 750 papers, most of them published after 2003. After screening, 239 papers were relevant for a deeper exploration. The study reveals an increasing trend of published papers addressing detection capabilities in industrial control systems, with a rise in published papers from 2011. 86% of these research papers address standard features characteristic of industrial control systems, and 58% of the papers suggest using data from physical processes. However, most studies have a low technology readiness level; only 38 papers cover testing in a live test environment, and none cover testing in a system in operation. The overall findings show that, given the development of the threat landscape, and the urgency of good detection capabilities, there is a need for further research on detecting cyber threats using combined data sources in a live testing environment.
Jon-Martin Storm, Janne Merete Hagen, Øyvind Anders Arntzen Toftegaard
IEEE BigData3