|
The work plan of ESCORTS involves five main actions, each one structured as a single work package:
Work Package 1: Complete survey of stakeholder needs and evaluate the market for SCADA security. This package builds
upon previous background joint work of the participants and on the background of the project stakeholders to complete a
survey of the stakeholder needs across the sectors involved, evaluate the market for security related services in EU and
structure its key demands.
Work Package 2: Identify and evaluate best practice. This work package is to assess the current state of cyber security
best practice in EU, review the state of the art of standardisation activities and pinpoint current divergences among
existing standardisation efforts. The package will result in a commonly agreed technology taxonomy of security solutions
for the SCADA sector.
Work Package 3: Stimulating convergence of current standardisation efforts. This work package will result into a joint
understanding of the way current standardisation efforts are progressing. It is to point out and rationalise eventual
divergences, and develop a strategic standardisation roadmap so as to structure existing and forthcoming actions.
Because this work package concerns a standardisation activity, CEN intends to create a Focus Group in order to enable
the participation of the broadest possible stakeholder community.
Work Package 4: Requirements for appropriate test platforms for the security of process control equipment and
applications. This work package will review current experimental facilities in EU and compare their current state with
the US offer. The package will provide requirements for future cyber security laboratories to be established in Europe,
and develop and deploy a secure ICT platform for the exchange of relevant data among the stakeholders.
Work Package 5: Management and dissemination will profit from the advice of a stakeholders advisory board composed of
representatives of the relevant industrial sectors, such as power, oil, water, and process automation. The constituency
of this board will keep growing along the life of the project. Dissemination will target EU policy makers, stakeholders
and the public, to promote awareness on security risks, and show prospective benefits of best practices.
|