Project
Federal Office for Information Security

Preparation of two BSI KRITIS studies on fuel and heating oil supply as well as gas supply

secunet Security Networks AG, together with its partner companies ILF Business Consult GmbH and TriLon GmbH, has prepared CRITIS studies for the German Federal Office for Information Security (BSI) on the fuel and heating oil supply industry and the gas supply industry in Germany.

The aim of the studies is to contribute to the fulfillment of the tasks of the BSI according to §§ 8a and 8b of the German Security Information Act (BSIG) and to compile information collections for the BSI to support the situation assessment according to § 8b (2) of the BSIG. In addition, the studies support the BSI in evaluating operator reports in accordance with Section 8b (4) BSIG and in involving its own staff in the specialist topics of the respective KRITIS areas.

One focus of the prepared studies is the explanation and analysis of facility categories according to the Ordinance on the Determination of Critical Infrastructures under the BSI Act (BSI-KritisV) in relation to the critical service to be provided. For each asset category, all assets and asset parts (asset view), internal operation-critical processes with interfaces (internal process view) and associated IT/OT components (IT/OT view) required to maintain the critical service were identified and described. The different views, i.e., plant view, internal process view, and IT/OT view, were analyzed in more detail, explained, and comprehensively presented in the overall context.
 
Selected security requirements (ISO/IEC 27002, ISO/IEC 27019, IT-Grundschutz-Kompendium, TeleTrusT handout on the state of the art) and the analysis of typical example scenarios were used to determine how their implementation by operators should be evaluated. Possible deviations were identified and corresponding recommendations developed that can be observed in the near future to ensure the current state of the art with regard to IT security.

The study concludes with an outlook on technological and business trends in the field of fuel or heating oil supply and gas supply.

In the course of the study, interviews and expert discussions were held with operators of the respective plant categories as well as with representatives of industry associations, employees of integrators, consulting engineers, IT security experts and employees of IT/OT component manufacturers to obtain the current status and insights from the industry and on the ICT used. The specific implementation of internal processes, the current status of the IT infrastructure used and the IT security implemented overall were also discussed and prepared for the study.