Please use this identifier to cite or link to this item:
https://repositorio.esg.br/handle/123456789/2137| metadata.dc.type: | Outros |
| Title: | Infraestruturas críticas e guerra cibernética: vulnerabilidades nos sistemas de óleo e gás |
| Authors: | Moraes Junior, Antonio Carlos de |
| Advisors: | Azevedo, João de |
| Course: | Curso Superior de Segurança e Defesa Cibernética (CSSDC) |
| Keywords: | Cibersegurança - Vulnerabilidades;Infraestruturas críticas;Estratégia empresarial;Óleo e gás |
| Issue Date: | 2025 |
| Publisher: | Escola Superior de Guerra |
| Abstract: | This academic essay analyzes cybersecurity vulnerabilities in critical infrastructures of the oil and gas sector, focusing on the automatic application of security patches in industrial systems (OT/ICS). The research problem aims to investigate to what extent patch automation can reduce the exposure window to cyberattacks without compromising operational availability. The study contextualizes the threat landscape and real incidents, reviews relevant standards such as Industrial communication networks - Network and system security series of standards (ISA IEC 62443), Pipeline Control Systems Cybersecurity (API 1164) and Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology (NIST SP 800-40), and evaluates hypotheses on the net effects of automation across different criticality levels. The main practical contribution is the proposal of a risk-oriented decision framework to help managers determine when to adopt automated patching in industrial environments. The findings indicate that automation can be effective for less critical assets but requires strict conditions for critical systems. The research highlights the importance of aligning cybersecurity with operational continuity in strategic sectors. |
| Description: | Este ensaio acadêmico analisa as vulnerabilidades cibernéticas em infraestruturas críticas do setor de óleo e gás, com foco na aplicação automática de patches de segurança em sistemas industriais (OT/ICS). O problema de pesquisa propõe-se a investigar em que medida a automação do patching pode reduzir a janela de exposição a ataques sem comprometer a disponibilidade operacional. O estudo contextualiza o panorama de ameaças e incidentes reais, revisa normas relevantes como a Industrial communication networks - Network and system security series of standards (ISA IEC 62443), a Pipeline Control Systems Cybersecurity (API 1164) e Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology (NIST SP 800-40) e avalia hipóteses sobre os efeitos líquidos da automação em diferentes níveis de criticidade. A principal contribuição prática é a proposição de um quadro de decisão orientado a risco para auxiliar gestores a determinar quando adotar a automação de patches em ambientes industriais. Conclui-se que a automação pode ser eficaz em ativos de menor criticidade, mas exige condições específicas para sistemas críticos. A pesquisa reforça a importância de alinhar segurança cibernética e continuidade operacional em setores estratégicos. |
| URI: | https://repositorio.esg.br/handle/123456789/2137 |
| Appears in Collections: | Diversos (Cibersegurança e Segurança da Informação) |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| ENSAIO_ACAD_Antonio_rev_final_assinado.pdf | 350.62 kB | Adobe PDF | ![]() View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.
