You are on page 1of 5

Integration of Security, Functional and Ecology

Safety Management Systems:


Concept and Industrial Case
Sergiy Dotsenko Herman Fesenko Oleg Illiashenko
Department of specialized computer systems Department of computer systems, Department of computer systems,
of Ukrainian State University of networks and cybersecurity networks and cybersecurity
Railway Transport of National aerospace university “KhAI” of National aerospace university “KhAI”
Kharkiv, Ukraine Kharkiv, Ukraine Kharkiv, Ukraine
1sirius_3k3@ukr.net h.fesenko@khai.edu o.illiashenko@csn.khai.edu
Vyacheslav Kharchenko Valentin Moiseenko Liudmyla Yermolenko
Department of computer systems, Department of specialized computer systems Department of specialized computer systems
networks and cybersecurity of Ukrainian State University of of Ukrainian State University of
of National aerospace university “KhAI” Railway Transport Railway Transport
Kharkiv, Ukraine Kharkiv, Ukraine Kharkiv, Ukraine
v.kharchenko@csn.khai.edu mvi53@ukr.net ermolenkolp1@gmail.com

Abstract—The purpose of the article is to substantiate integration [3], as well as integrated management systems
the method of integration of the environmental management [4]. Standard [2] sets requirements for the integration of
system in the enterprise management system. In order to enterprise management systems, one of which is its
meet the requirements of ISO 7498-2-99, the structure of a information security system [5]. These standards are the
multilevel integrated enterprise security management
system has been developed. The system provides security
basis for the development of integrated functional
management for physical, information, signaling and security systems for intelligent manufacturing systems
environmental spaces. An additional environmental [6]. Works [7, 8, 9, 10] are also dedicated to this
management layer was introduced in comparison with the direction of research.
security management system proposed in [12]. The The developed and applied ITs are based on the
integration of environmental management meets the representation of their functions. Besides, the IEC 62264-
requirements of IEC 62264-1-2014. This allows us to form 1-2014 standards specify that the following aspect should
inter-layers connections and coordinate the operation of be the most important: methodologies of the enterprise
individual subsystems at the physical security, information modeling in which physical, informational and cybernetic
(cyber) security, functional and ecological security layers.
The implementation of this approach enhances enterprise
(in the form of data transmission) representations are
security and environment security as a whole. presented. This requirement is particularly relevant to the
Keywords—security, functional safety, ecology safety, concept of Industry 4.0.
management system, industrial case. Therefore, the following tasks are important to assure
the physical security by limiting access to the objects, to
I. INTRODUCTION realize control of the flow of information that comes out
of objects to protect intellectual property and to control
An important part of the implementation of strategy of data transmissions, to avoid influencing the production
Industry 4.0 is the formation of enterprise security process by unauthorized remote access.
management. According to [1], the term “security” used Unfortunately, this standard does not contain
for minimizing the vulnerability of means and resources. requirements for the management of technological risks
Any means have their correspondent value. Vulnerability for enterprise that may arise in the course of the
can be defined as a sort of weakness that can be used to enterprise's activities and which may cause environmental
violate the system or information contained therein. In a damages. IEC 62264-1:2014 standard introduces a system
global sense threat can be defined as a potential breach of to protect the enterprise from external and internal
system’s protection. According to [1], security threats. Management of risks of the harmful effects of the
management is an enterprise function that includes the enterprise activity on the environment is not considered.
following features of the production site: safety, Wherein, the damages that the enterprise may cause to
information security, and computer security. The main the environment creates for the enterprise the risk of
role of security in the production process is to guarantee obtaining image, material, and moral losses. So for the
that only authorized personnel can make changes in it or enterprise security management system we recommend
influence production in a permissible manner. Physical distributing the control object into two components,
security also implies access control, information flows specifically: technological processes, that are realized in
control and much more. real-time mode as well as organizational processes that
Development information technologies at the provide the organization of technological processes and
beginning of the twenty-first century stimulated the are implemented beyond the boundaries of technological
development of models and methods of enterprise processes (physical processes) and.

978-1-7281-9957-3/20/$31.00 © 2020 IEEE

470

Authorized licensed use limited to: Carleton University. Downloaded on July 28,2020 at 06:46:01 UTC from IEEE Xplore. Restrictions apply.
It is clear that technological processes carry risks of taking into account aspects of the life cycle of the project
harm to the environment, and therefore these risks need that prevents the environmental impact from an
to be managed in real-time. Currently, enterprise unanticipated transition from one stage of the life cycle to
environmental management systems are being another throughout the life cycle [11]. That is, the main
implemented in accordance with a series of ISO 14000 possible source of environmental impact is the
standards [11] whose development is also based on the "unpredictable transition from one stage of the life cycle
methodology of the ISO 9000 series of standards. In this to another. However, environmental risks exist at all
case, a methodology is fundamentally different from the stages of the life cycle. Unfortunately, this aspect is not
methodology used to form traditional automatic and taken into account.
automated control systems. It is based on the principle of The Plan-Do-Check-Act (PDCA) concept is the basis
a systematic approach. It is assumed that such systems for the environmental management system. The PDCA
operate in the mode of delayed time, i.e., the elements of model reflects an iterative process used by organizations
the control cycle are implemented at different points in to achieve continuous improvement, and can be applied
time. This leads to contradictions, specifically, to the environmental management system and to each of
technological processes are implemented in real-time its individual elements. According to this approach, the
mode, elements of the control cycle are implemented in fundamental principle is the continuous improvement of
the delayed time mode. the environmental management system. That is, one
The solution to this contradiction is possible by aspect of the environmental management system activity
substantiating the feasibility of forming environmental is the requirement of self-improvement. Figure 1 shows
management systems based on the principles of forming the general scheme described in the standard to be
systems of automatic and automated management. mapped out by the PDCA model, which can help new and
Therefore, the purpose of this article is to substantiate the current users realize the importance of a systems
method of integrating the environmental management approach.
system into enterprise management system.
The paper is organized in the next way. In section II
we analyze the methodology of formation the
environmental management system. Section III presents
the integration of the environmental management system
into the integrated enterprise security management
system. We discuss examples of practical implementation
of the proposed concept in Section IV and conclude our
work in Section V.
II. ANALYSIS OF THE METHODOLOGY OF FORMATION
ENVIRONMENTAL MANAGEMENT SYSTEMS
As it is stated in [11] “the societal expectations for
sustainable development, transparency and accountability
have evolved with increasingly stringent legislation,
growing pressures on the environment from pollution,
Fig.1. Accordance between the PDCA model and the general
inefficient use of resources, improper waste management, scheme presented in the standard
climate change, degradation of ecosystems and loss of
biodiversity. It pushed organizations to adopt a From the overview of organizational security
systematic approach of environmental management by management and environmental management approaches,
implementing special environmental management there are contradictions between these approaches as
systems with the aim of contributing to the environmental follows:
pillar of sustainability”. At the same time, on the basis of  enterprise security management systems are
a systematic approach to environmental management, it is developed as automatic and automated control systems
possible to provide top management with information that with uniquely defined control objects and methods for
will be useful for achieving long-term success and constructing control systems [12];
acquiring opportunities that will contribute to sustainable  for the environmental management systems that
development. So, the main task of the environmental are not uniquely defined there is the principle of their
management system is to “provide top management with formation (defined only the content of the management
information to build success over the long term and cycle of the PDCA), and the objects of management:
create options for contributing to sustainable "unpredictable transition from one stage of the life cycle
development.” to another".
Unfortunately, no task of real-time managing It is proposed to consider the solution of the problem
environmental security risks is set. At the same time, the of formation of the environmental management system on
main method of management is determined the method of the basis of the methodology of formation of enterprise
controlling the ways of (or influencing them) security management systems in accordance with the
development of products and services of the organization; requirements of IEC 62264-1-2014.
production, distribution, consumption, and disposal,

471

Authorized licensed use limited to: Carleton University. Downloaded on July 28,2020 at 06:46:01 UTC from IEEE Xplore. Restrictions apply.
III. INTEGRATION OF THE ENVIRONMENTAL MANAGEMENT
SYSTEM INTO THE INTEGRATED ENTERPRISE SECURITY
MANAGEMENT SYSTEM
Based on the requirements of IEC 62264-1-2014 [2], in
terms of security, the most significant requirement should
implies the enterprise modeling methodologies where physical,
informational and cybernetic views are represented. Based on
that, Figure 2 presents the integrated enterprise security
management system proposed in [12]. The architecture of each
channel of this control system is similar to the architecture of
the operation management system.

Fig.3. Integrated Enterprise Management System with Enterprise


Security Management System

The integration of security management system of


enterprise into enterprise management system includes the
communication of production process management subsystems
with the respective security management subsystems. A similar
interaction do exists between production subsystems and
subsystems that describe the Signal level, Information level and
Physical Security level. Further development of the enterprise
security management system (Fig. 2) is a system which
Fig.2. Integrated Safety and Security Management System includes an environmental management channel (Fig. 4).
The system includes three interconnected security areas at
the different levels: Physical, Information and Signal spaces.
Let us examine the operation of the system at the example of
the security management channel "Physical Space" according
to [12]. The security status signals of the enterprise as a
physical object (Xps) are transmitted to the PSP block in which
the corresponding diagnosis is formed (Zps). This diagnosis is
transmitted to the adder. Then it is compared with the reference
value (Xpsе) formed in the PSE and the formation of the control
signal as the difference (ΔXpsе) = (Zps) – (Xpsе) is provided.
Under the influence of the resulting signal, a control action is
formed in the PSM unit, which is directed to processes in
Physical Space. Similar algorithm is implemented in the
channels "Information Space" and "Signal Space".
Control channels integration is taken place by sending
control signals from the channel "Physical Space" (PSM) to the
inputs of ISM and FSM. Due to this fact, the channels
Information and Signal Spaces are managed based on the state
of the Physical Space control channel. Moreover, control
commands from the ISM and FSM blocks are proceed to the
PSM block. Due to this, the control action in the PSM unit is
formed in accordance with the states of the channels
Information and Signal Spaces. The system discussed above
(see Fig. 2) forms part of the overall management system of the Fig.4. Integrated Enterprise Management System with Environmental
enterprise. The results of integration of the enterprise Management System
management system together with an enterprise security
management system is depicted on Fig. 3 [13]. This channel provides obtaining information of the state of
technological processes (the element “Object”) and the state of

472

Authorized licensed use limited to: Carleton University. Downloaded on July 28,2020 at 06:46:01 UTC from IEEE Xplore. Restrictions apply.
the environment (the element “I&C of the environment”). On the other countries of the world. Examples of such systems are
basis of this data, the ESP unit generates data on the state of the automated information and measuring system for environmental
environment and the process Zes. Comparison of these data with monitoring of the production of CJSC “UKRANALIT”,
the data of the reference signal Xese provides the formation of a automated measuring system of production and environmental
discrepancy signal ΔXese on the basis of which the control signal monitoring of production of the Corporation
Yes is formed. This signal provides the implementation of impact “UKRATOMPRILAD”, automated groundwater monitoring
on the environment directly as well as the effect on the system “Ozone AKVA” and others.
technological process through the block “FSM”. The requirements for the development of such systems are
The peculiarity of this method of integration of the given in the following documents [19]: Rules for the creation and
environmental management system into the enterprise operation of automated systems of environmental control and
management system are: monitoring (ASECM) of objects (enterprises) of high
 the sources of information are actually technological environmental risk (facilities with increased danger) and the
processes that have additional special sensors that check rules for their creation and operation; Ministry of Emergencies
deviations of technological parameters from the specified ones, standard of Ukraine “Safety in emergencies automated systems of
as well as sensors of the system of monitoring environmental early detection emergencies and notification. Types and general
parameters; technical requirements” (SOUME 75.2-00013528-003:2011).
 the methodological basis for the construction of the So the task of monitoring the state of the environment is
environmental management system is the theory of automatic considered as an independent self-sufficient task. But in order to
and automated control systems which provides modeling of both prevent harmful effects on the environment, it is necessary to
management objects and the actual control system; form control (corrective) actions in real time. It is clear that
 the main focus of the environmental management monitoring systems are the first important task but it is the only
system is on managing the risks of environmental safety but not part of the environmental management system. After all, the task
on the continuous improvement of the elements of the system for an environmental management system is to ensure safety
itself; conditions of the environment. Therefore, the task of forming
 the concept of a systematic approach to the environmental safety management systems for high-risk objects
development of management systems was formed in time when remains unresolved.
highly specialized management systems for certain objects, An example of the integration of physical, information,
aspects of activity and technological processes of enterprises functional and environmental security systems is NPP
were developed; management systems. In particular, the automated radiation
 by this time the concept of enterprise integration based monitoring system (ARMS) on Zaporizhzhya NPP is responsible
on the latest information technologies [14], management systems for the continuity of monitoring the parameters characterizing the
[2] and management [15] has been developing rapidly. radiation status at the industrial site of the NPP, in the sanitary
protection zone, in the observation area during the normal
IV. EXAMPLES OF PRACTICAL IMPLEMENTATION OF THE operation of the NPP, in the case of design accidents, and
PROPOSED CONCEPT OF FORMING AND ENVIRONMENTAL termination of their operation. ARMS is built as an automated
MANAGEMENT SYSTEM two-level measuring information system with centralized
The problem of environmental protection is divided into two automated control of functioning and distributed organization of
parts, depending on the level of risk of harm to the environment. measuring, collecting and processing information (Fig. 5).
The first is the problem of protection from the damage by
facilities with increased danger. The second is the problem of
defense against the injury by industrial and agricultural
enterprises. In order to protect against harm from industrial and
agricultural enterprises, it is proposed that these enterprises
voluntarily establish environmental management systems in
accordance with the requirements of the ISO 14000 series, the
characteristics of which are discussed above.
To protect the environment against injury from objects
(companies) with increased environmental risk (of facilities with
increased danger) according to national and international
documents proposed to form environmental monitoring [16 –
18]. Thorough analysis of the current state of the environmental
monitoring tasks was performed in [19]. According to the results
of this analysis, monitoring of environmental impact of facilities
of increased danger for the environment and providing them with
environmental reporting will allow to increase the amount of
operative information on the state of environment, to improve
control over the compliance of enterprises with environmental
regulations, to take management and technical decisions at
enterprises to prevent negative impact on environment.
According to [19], modern automated environmental
monitoring systems have been developed both in Ukraine and in Fig.5. Structure of ARMS “Zaporizhzhya NPP”

473

Authorized licensed use limited to: Carleton University. Downloaded on July 28,2020 at 06:46:01 UTC from IEEE Xplore. Restrictions apply.
The following functions are implemented at the high REFERENCES
level: [1] ІSО 7498-2:99, Information technology. Open Systems
 collection and operation the information from the Interconnection. Basic Reference Model. Part 2. Security Architecture
lower ARMS level; [2] IEC 62264-1-2014, Enterprise-control system integration. Part 1.
Models and terminology
 providing the operator with the operating modes [3] ISO 19439:2006, Enterprise integration — Framework for enterprise
controls of ARMS with modern human-machine interface; modeling
 display the controlled parameters in a format [4] PAS 99:2006 Specification of common management system
requirements as a framework for integration
convenient for perception, diagnosis and management; [5] ISO/IEC 27000:2018, Information security management systems -
 performance of special calculations; control of the Overview and vocabulary
modes of operation of the lower level of ARMS; [6] Kosmowski K. T., Śliwiński M., Piesik J., Integrated Functional
 organization of ARMS performance and Safety and Cybersecurity. Analysis Method for smart manufacturing
systems. Task Quar terly vol. 23, No 2, 2019, P. 177–207 (2019)
workability testing; [7] Kosmowski K., Gołębiewski D., Functional safety and cyber security
 development and issuance of recommendations, as analysis for life cycle management of industrial control systems in
well as implementation of forecast calculations; hazardous plants and oil port critical infrastructure including
insurance, Interreg Baltic Sea Region, HAZARD Report (2019)
 exchange of information with related systems and [8] Li S. W., et al. Architecture Alignment and Interoperability, An
consumers. Industrial Internet Consortium and Platform Industrie 4.0,
The lower level of ARMS implements the following IIC:WHT:IN3:V1.0:PB:20171205 (2017)
functions: [9] MERgE 2016 Safety & Security, Recommendations for Security and
Safety Co-engineering, Multi-Concerns Interactions System
 automatic measurement of radiation parameters, Engineering ITEA2 Project #1 101 1
temperature and volume consumption of gas-aerosol [10] Kosmowski K. T., Safety Integrity Verification Issues of the Control
emissions and discharges; Systems for Industrial Power Plants, Advanced Solutions in
Diagnostics and Fault Tolerant Control, Springer International
 automatic measurement of meteorological Publishing AG 420 (2017)
parameters that characterize the state of the atmosphere; [11] ISO 14001:2015, Environmental management systems —
 automatic measurement and measurement by the Requirements with guidance for use.
laboratory of external radiation control of radiation [12] Kharchenko V., Dotsenko S., Illiashenko O., Kamenskyi S.,
"Integrated Cyber Safety & Security Management System: Industry
parameters characterizing the radiation situation at the 4.0 Issue" 2019 10th International Conference on Dependable
industrial site, in the sanitary protection zone and the Systems, Services and Technologies (DESSERT), Leeds, United
observation zone; automatic mode of operation of the Kingdom, 2019, P. 197-201.
suction unit in the mode of emergency radiation situation; [13] Dotsenko S., Illiashenko O., Kamenskyi S., Kharchenko V.
"Integrated Security Management System for Enterprises in Industry
 organization of performance and workability 4.0", Information & Security: An International Journal 43, no. 3
testing of low-level equipment; (2019), P. 294-304.
 accumulation, initial processing, indication and [14] ISO 19439:2006 Enterprise integration — Framework for enterprise
modeling (IDT).
transfer of information to the top level of the system. [15] PAS 99: Publicly Available Specification for Common Management
Thus the ARMS is an integral part of the overall NPP Systems.
safety management system in addition to the information [16] Resolution of the Cabinet of Ministers of Ukraine from December 05,
and control systems that ensure the safe operation of the 2007 No. 1376 “On Approval of the State Target Environmental
Program for Environmental Monitoring”
reactor equipment and the like. [17] Resolution of the Cabinet of Ministers of Ukraine of August 28, 2013
No. 808 “On approving the list of activities and objects posing an
V. CONCLUSION AND FUTURE WORK increased environmental hazard”
In order to meet the requirements of ISO 7498-2-99 for [18] RD 52.04.186 - 89 "Guidelines for the control of atmospheric
pollution" (the validity of the document was extended by the Order of
the allocation of security areas, a multi-level integrated the SES of Ukraine №473 from 31.08.2017)
enterprise security management system has been developed. [19] Dmitrieva O., Palaguta O. (Eds.) et.al, Development of a draft
The system provides security controls for physical, methodology for monitoring the impact on environmental objects of
information, signaling and environmental spaces. An enterprises of high environmental risk in agglomerations: report on
Scientific and Research Work (final), Scientific Institution "Ukrainian
additional eco-safety management unit was introduced in Research Institute of Environmental Problems", Kharkiv, 2018. P.
comparison with the safety management system proposed in 476.
[12]. Integration of the environmental management [20] Kharchenko V., Illiashenko O. (2017) Concepts of Green IT
subsystem complies with the requirements of IEC 62264-1- Engineering: Taxonomy, Principles and Implementation. In:
Kharchenko V., Kondratenko Y., Kacprzyk J. (eds) Green IT
2014. Engineering: Concepts, Models, Complex Systems Architectures.
This allows one to form inter-circuit connections and Studies in Systems, Decision and Control, Springer, Cham, Vol. 74.
coordinate the operation of individual subsystems at the pp. 3-19
levels of physical security, information (cyber) security, [21] Potii O., Illiashenko O., Komin D. (2015) Advanced Security
Assurance Case Based on ISO/IEC 15408. In: Zamojski W.,
functional and ecological safety. The implementation of this Mazurkiewicz J., Sugier J., Walkowiak T., Kacprzyk J. (eds) Theory
approach enhances the security of enterprises and the and Engineering of Complex Systems and Dependability. DepCoS-
environment in general. It also can be used in order to RELCOMEX 2015. Advances in Intelligent Systems and Computing,
developed cybersecurity (and not only) assurance cases for Springer, Cham, Vol. 365, pp. 391-401.
the demonstration of compliance with security standards
[21].

474

Authorized licensed use limited to: Carleton University. Downloaded on July 28,2020 at 06:46:01 UTC from IEEE Xplore. Restrictions apply.

You might also like