<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<dokAAPp xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="../../../../../../prj/bin/GuidICS/dokAAPp.xsd">
    <author>
        <individual>
            <ind firstName="Paweł" ini="pb" msr="Mr" org="NIK" role="draft" surName="Banaś"/>
        </individual>
        <organization>
            <org kraj="Netherlands" nm="Algemene Rekenkamer" skr="NCA" www="www.rekenkamer.nl"/>
        </organization>
    </author>
    <about caseNumber="4" file="waterCybersecurity" folder="C:\pb\algorytm\SAI_robo\NL\2019\waterCybersecurity" id="NL2019waterCybersecurity" issueYear="2019" waga="157">
        <tyt>
            <tx file="waterCybersecurity.pdf" l="en" nm="Strengthening the digital defences: the cyber security and critical water structures" typDok="authorized_translation"/>
            <tx file="waterCybersecurity_NL.pdf" l="nl" nm="Digitale dijkverzwaring: cybersecurity en vitale waterwerken" typDok="original_document"/>
        </tyt>
        <portfolio>
            <pfl zn="cybersecurity"/>
        </portfolio>
        <ver put="202609181427" stage="final"/>
        <ver put="202501230942" stage="final"/>
        <ver put="202409230546" stage="draft"/>
    </about>
    <part id="lead">
        <tyt>
            <tx l="en" nm="Cyber security of critical water structures not watertight"/>
        </tyt>
        <narrative>
            <narr l="en">
                <ak nr="1">The audit asks whether the agency responsible for the country's critical water structures is equipped to detect and withstand a cyber attack, and the cases below show a gap opening at each stage. Detection was meant to be immediate and is not: the security operations centre has no current picture of the structures it watches, so an intrusion can pass unnoticed. Response was never rehearsed for this kind of crisis - no scenario was written for it, nothing was known centrally about how an attack would cascade, and the documents responders would reach for were out of date. Behind both sits a capacity problem the centre itself reports, in staff and in expertise, which turns low-priority alerts into a queue measured in days. And the systems being defended were designed before the term cyber security was in common use, then connected to wider networks for remote operation, gaining an exposure they were never built for.</ak>
            </narr>
        </narrative>
    </part>
    <part id="background" v="01">
        <tyt>
            <tx l="en" nm="Background"/>
        </tyt>
        <part id="scale">
            <tyt>
                <tx l="en" nm="Scale"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak tp="li">Every critical water structure managed by the national directorate for public works and water management - the storm surge barriers, locks, weirs and pumping stations the country depends on.</ak>
                    <ak tp="li">Their operating systems largely date from the 1980s and 1990s and were built to run stand-alone, before being linked to wider networks.</ak>
                    <ak tp="li">One security operations centre watches the whole estate for cyber threats.</ak>
                </narr>
            </narrative>
        </part>
        <part id="compliance">
            <tyt>
                <tx l="en" nm="Compliance"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak tp="li">A national data-processing and cyber-security act, with a companion act on the security of network and information systems, sets the baseline duties of critical-infrastructure operators.</ak>
                    <ak tp="li">An EU directive on network and information system security obliges member states to protect essential services.</ak>
                    <ak tp="li">A government accounts act, together with the ministry's own security programme and regulations, governs how the agency organises that protection and accounts for it.</ak>
                </narr>
            </narrative>
        </part>
        <part id="perfromance">
            <tyt>
                <tx l="en" nm="Performance"/>
            </tyt>
            <part id="economy">
                <tyt>
                    <tx l="en" nm="Economy"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">The audit puts no figure on the cost of protection: the resource in question is the staffing and expertise of a single security operations centre.</ak>
                        <ak tp="li">That centre reports a shortfall in both, with nothing to show it was resourced for the task it was given.</ak>
                    </narr>
                </narrative>
            </part>
            <part id="efficiency">
                <tyt>
                    <tx l="en" nm="Efficiency"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">Low-priority alerts may wait several days before anyone acts on them.</ak>
                        <ak tp="li">The target of detecting attacks instantly, set for the end of 2017, had not been met by the autumn of 2018.</ak>
                        <ak tp="li">Crisis maps and network reports that responders would depend on were not kept up to date.</ak>
                    </narr>
                </narrative>
            </part>
            <part id="effectiveness">
                <tyt>
                    <tx l="en" nm="Effectiveness"/>
                </tyt>
                <narrative>
                    <narr l="en">
                        <ak tp="li">The security operations centre has no up-to-date picture of the cyber-security status of all critical water structures.</ak>
                        <ak tp="li">No scenario had been prepared for a crisis caused by a cyber attack, and head office held no information on its cascade effects.</ak>
                        <ak tp="li">How great the threat of an attack on the sea-defence and water-management sector actually is remains unclear.</ak>
                    </narr>
                </narrative>
            </part>
        </part>
    </part>
    <part id="cases" v="01">
        <tyt>
            <tx l="en" nm="Cases"/>
        </tyt>
        <ctsy>
            <gr gn="area">
                <cts id="infrastructure"/>
                <cts id="water-management"/>
                <cts id="cybersecurity"/>
            </gr>
            <gr gn="ins">
                <cts id="ministry"/>
                <cts id="directorate"/>
                <cts id="government-agency"/>
            </gr>
            <gr gn="control">
                <cts id="design"/>
                <cts id="monitoring"/>
                <cts id="continuity"/>
                <cts id="documentation"/>
            </gr>
            <gr gn="value">
                <cts id="asset"/>
                <cts id="human_capital"/>
                <cts id="domain_knowledge"/>
            </gr>
            <gr gn="fun">
                <cts id="security"/>
                <cts id="IT"/>
                <cts id="infrastructure"/>
                <cts id="humanResources"/>
            </gr>
            <gr gn="quality">
                <cts id="reliableInformationBase"/>
                <cts id="soundRiskManagement"/>
                <cts id="adequateResourcesCompetences"/>
                <cts id="adequatelyStaffedWorkforce"/>
                <cts id="appropriateUseOfTechnology"/>
                <cts id="reliabilityAvailability"/>
            </gr>
            <gr gn="sta">
                <cts id="operator"/>
                <cts id="staff"/>
            </gr>
        </ctsy>
        <part id="detectionFallsShortTarget">
            <tyt>
                <tx l="en" nm="Detection falls short of its own target, so an intrusion can pass unnoticed"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="2" ref="draft draft" tp="xm" zn="NL2019waterCybersecurity">The detection and response strategy was not yet complete: 'the objective set for the end of 2017 of instantly detecting any cyber attacks directed against critical water structures had not been achieved by the autumn of 2018'. As a result the security operations centre 'does not have an up-to-date picture of the cyber security status of all critical water structures, which means that there is a risk of hackers being able to break into critical structures unnoticed'. A Monitoring gap rooted in a Design that was never finished, leaving the agency at risk of detecting an attack too late, or not at all.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="monitoring"/>
                    <cts id="design"/>
                </gr>
                <gr gn="value">
                    <cts id="asset"/>
                </gr>
                <gr gn="fun">
                    <cts id="security"/>
                </gr>
                <gr gn="quality">
                    <cts id="reliableInformationBase"/>
                    <cts id="soundRiskManagement"/>
                </gr>
                <gr gn="sta">
                    <cts id="operator"/>
                </gr>
            </ctsy>
        </part>
        <part id="scenarioPreparedCyberCrisis">
            <tyt>
                <tx l="en" nm="No scenario was prepared for a cyber crisis, and the response documents were out of date"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="3" ref="draft draft" tp="xm" zn="NL2019waterCybersecurity">'No scenario had been constructed specifically for a crisis caused by a cyber attack. Moreover, no information was available at head office on the cascade effects caused by a cyber attack on the critical water structures.' Certain important documents relating to the response - crisis maps and network reports - 'were not kept up to date'. A Continuity gap compounded by Documentation: the response to a cyber crisis may be neither sufficiently rapid nor sufficiently effective.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="continuity"/>
                    <cts id="documentation"/>
                </gr>
                <gr gn="value">
                    <cts id="asset"/>
                </gr>
                <gr gn="fun">
                    <cts id="security"/>
                </gr>
                <gr gn="quality">
                    <cts id="soundRiskManagement"/>
                    <cts id="reliabilityAvailability"/>
                </gr>
            </ctsy>
        </part>
        <part id="monitoringCentreReportsToo">
            <tyt>
                <tx l="en" nm="The monitoring centre reports too few people and too little expertise, and alerts queue for days"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="4" ref="draft draft" tp="xm" zn="NL2019waterCybersecurity">The security operations centre 'claims to have a capacity problem - in terms of both staff and expertise. This lack of capacity causes delays, for example, in analysing reports of potential threats: the SOC claims that it may take several days before any action is taken in response to low-priority alerts.' Its staff would like to refine and professionalise their detection practices further, for instance by checking log data in ways that would surface suspicious patterns. A Monitoring function limited less by method than by the Human capital available to run it.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="monitoring"/>
                </gr>
                <gr gn="value">
                    <cts id="human_capital"/>
                </gr>
                <gr gn="fun">
                    <cts id="humanResources"/>
                </gr>
                <gr gn="quality">
                    <cts id="adequateResourcesCompetences"/>
                    <cts id="adequatelyStaffedWorkforce"/>
                </gr>
                <gr gn="sta">
                    <cts id="staff"/>
                </gr>
            </ctsy>
        </part>
        <part id="systemsBuiltBeforeCyber">
            <tyt>
                <tx l="en" nm="Systems built before cyber security was a concern were later opened to wider networks"/>
            </tyt>
            <narrative>
                <narr l="en">
                    <ak nr="5" ref="draft draft" tp="xm" zn="NL2019waterCybersecurity">'The operating processes at critical water structures use computer systems many of which date back to the 1980s and 1990s, a time when the term cyber security was not in common use. Although these systems were originally designed to operate on a stand-alone basis, they have over the years been gradually linked up with bigger computer networks, for example in order to facilitate remote operation. However, this trend has made the systems more vulnerable to cyber threats.' A Design decision taken for operational convenience that changed the threat surface of an Asset, while it remains unclear how great the threat to the sea defence and water management sector actually is.</ak>
                </narr>
            </narrative>
            <ctsy>
                <gr gn="control">
                    <cts id="design"/>
                </gr>
                <gr gn="value">
                    <cts id="asset"/>
                    <cts id="domain_knowledge"/>
                </gr>
                <gr gn="fun">
                    <cts id="IT"/>
                    <cts id="infrastructure"/>
                </gr>
                <gr gn="quality">
                    <cts id="appropriateUseOfTechnology"/>
                </gr>
            </ctsy>
        </part>
    </part>
</dokAAPp>
