Please use this identifier to cite or link to this item: https://repositorio.esg.br/handle/123456789/2137
metadata.dc.type: Outros
Title: Infraestruturas críticas e guerra cibernética: vulnerabilidades nos sistemas de óleo e gás
Authors: Moraes Junior, Antonio Carlos de
Advisors: Azevedo, João de
Course: Curso Superior de Segurança e Defesa Cibernética (CSSDC)
Keywords: Cibersegurança - Vulnerabilidades;Infraestruturas críticas;Estratégia empresarial;Óleo e gás
Issue Date: 2025
Publisher: Escola Superior de Guerra
Abstract: This academic essay analyzes cybersecurity vulnerabilities in critical infrastructures of the oil and gas sector, focusing on the automatic application of security patches in industrial systems (OT/ICS). The research problem aims to investigate to what extent patch automation can reduce the exposure window to cyberattacks without compromising operational availability. The study contextualizes the threat landscape and real incidents, reviews relevant standards such as Industrial communication networks - Network and system security series of standards (ISA IEC 62443), Pipeline Control Systems Cybersecurity (API 1164) and Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology (NIST SP 800-40), and evaluates hypotheses on the net effects of automation across different criticality levels. The main practical contribution is the proposal of a risk-oriented decision framework to help managers determine when to adopt automated patching in industrial environments. The findings indicate that automation can be effective for less critical assets but requires strict conditions for critical systems. The research highlights the importance of aligning cybersecurity with operational continuity in strategic sectors.
Description: Este ensaio acadêmico analisa as vulnerabilidades cibernéticas em infraestruturas críticas do setor de óleo e gás, com foco na aplicação automática de patches de segurança em sistemas industriais (OT/ICS). O problema de pesquisa propõe-se a investigar em que medida a automação do patching pode reduzir a janela de exposição a ataques sem comprometer a disponibilidade operacional. O estudo contextualiza o panorama de ameaças e incidentes reais, revisa normas relevantes como a Industrial communication networks - Network and system security series of standards (ISA IEC 62443), a Pipeline Control Systems Cybersecurity (API 1164) e Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology (NIST SP 800-40) e avalia hipóteses sobre os efeitos líquidos da automação em diferentes níveis de criticidade. A principal contribuição prática é a proposição de um quadro de decisão orientado a risco para auxiliar gestores a determinar quando adotar a automação de patches em ambientes industriais. Conclui-se que a automação pode ser eficaz em ativos de menor criticidade, mas exige condições específicas para sistemas críticos. A pesquisa reforça a importância de alinhar segurança cibernética e continuidade operacional em setores estratégicos.
URI: https://repositorio.esg.br/handle/123456789/2137
Appears in Collections:Diversos (Cibersegurança e Segurança da Informação)

Files in This Item:
File Description SizeFormat 
ENSAIO_ACAD_Antonio_rev_final_assinado.pdf350.62 kBAdobe PDFThumbnail
View/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.