Home
FT
STOP-IT Quantity FT
STOP-IT Water Quality FT
Import
List
SP Wizard
Risknought
Lists
Measures
Events
Tools
ST Procedures
Search
Login
Measure: EntranceAccessControl
Description
Implementation of an access control system for entrances to sensitive sites. Thus it shall be avoided that unauthorized people get access to the sensitive sites. The aim is to protect the infrastructures of the water utility from damages.
Comments
The physical access control can be implemented in different forms. The most common way of access control is the distribution of keys or access cards for sensitive sites only to authorized personnel. Another way of access control would be the implementation of regularly changing codes that are necessary to open doors. Also the access permission via biometric data like fingerprints is possible. In case of biometric entrance systems special attention has to be paid to data protection issues. Access control can also be realized by personnel that is positioned at entrances to check access permissions manually. The principle of minimum access permissions should be applied, that means that as few access authorizations as possible should be distributed.
Event source types
External attacker
Internal attacker
Human fault
Natural phenomena
Event types
Destruction
Manipulation
Pollution
Risk reduction mechanism
Frequency/Likelihood
Threat Types
Physical
Cyber-Physical
Action characteristics
Proactive
Measure types
Physical Barriers
Control System
event_ measures
Event-Measure: 98136
Event-Measure: 98164
Event-Measure: 98216
Event-Measure: 98249
Event-Measure: 98288
Event-Measure: 98430
Event-Measure: 98555
Event-Measure: 98562
Event-Measure: 98573
Event-Measure: 98604
Event-Measure: 98666
Event-Measure: 98798
Event-Measure: 98830
Event-Measure: 98850
Event-Measure: 98881
Event-Measure: 98886
Event-Measure: 98893
Event-Measure: 98990
Event-Measure: 99096
Event-Measure: 99159
Event-Measure: 99163
Event-Measure: 99180
Event-Measure: 99195
Event-Measure: 99259
Event-Measure: 99424
Event-Measure: 99438
Event-Measure: 99463
Event-Measure: 99489
Event-Measure: 99543
Event-Measure: 99547
Event-Measure: 99599
Event-Measure: 99626
Event-Measure: 99816
Event-Measure: 99829
Event-Measure: 99891
Event-Measure: 99893
Event-Measure: 99941
Event-Measure: 100007
Event-Measure: 100060
Event-Measure: 100098
Event-Measure: 100141
Event-Measure: 100168
Event-Measure: 100199
Event-Measure: 100263
Event-Measure: 100265
Event-Measure: 100318
Event-Measure: 100384
Event-Measure: 100426
Event-Measure: 100488
Event-Measure: 100492
Event-Measure: 100519
Event-Measure: 100563
Event-Measure: 100581
Event-Measure: 100638
Event-Measure: 100645
Event-Measure: 100815
Event-Measure: 100822
Event-Measure: 100874
Event-Measure: 100954
Event-Measure: 101004
Event-Measure: 101013
Event-Measure: 101041
Event-Measure: 101070
Event-Measure: 101118
Event-Measure: 101156
Event-Measure: 101218
Event-Measure: 101231
Event-Measure: 101458
Event-Measure: 101549
Event-Measure: 101611
Event-Measure: 101632
Event-Measure: 101648
Event-Measure: 101684
Event-Measure: 101711
Event-Measure: 101717
Event-Measure: 101785
Event-Measure: 101881
Event-Measure: 101929
Event-Measure: 101956
Event-Measure: 101995
Event-Measure: 101999
Event-Measure: 102048
Event-Measure: 102086
Event-Measure: 102174
Event-Measure: 102235
Event-Measure: 102254
Event-Measure: 102265
Event-Measure: 102274
Event-Measure: 102288
Event-Measure: 102317
Event-Measure: 102330
Event-Measure: 102332
Event-Measure: 102355
Event-Measure: 102398
Event-Measure: 102617
Event-Measure: 102641
Event-Measure: 102654
Event-Measure: 102686
Event-Measure: 102701
Event-Measure: 102709
Event-Measure: 102721
Event-Measure: 102779
Event-Measure: 102985
Event-Measure: 103019
Event-Measure: 103057
Event-Measure: 103063
Event-Measure: 103104
Event-Measure: 103241
Event-Measure: 103317
Event-Measure: 103337
Event-Measure: 103409
Event-Measure: 103475
Event-Measure: 103579
Event-Measure: 103647
Event-Measure: 103649
Event-Measure: 103733
Event-Measure: 103746
Event-Measure: 103763
Event-Measure: 103805
Event-Measure: 103849
Event-Measure: 103987
Event Consequences
Quantity
Quality
Financial
Reputation
Asset types
Catchment Area
Drinking Water Tanks
Pressure Boosting Station
Raw Water Bodies
Water Abstraction Points
Water Treatment Plants
Events
Basic Event 159 - Incorrect execution or failure of software acquired from an external party crashes WTP control system
Basic Event 201 - Malware performs DoS attack on abstraction well PLCs
Basic Event 69 - Internal person physically destroys WTP dosing system
Gate 176 - Staff controlled processes run without WTP data
Basic Event 70 - Natural phenomena alter reagent dosing system
Basic Event 216 - Incorrect execution or failure of software acquired from an external party crashes WTP control system
Basic Event 76 - External person physically damages WTP coagulation system
Basic Event 80 - External person induces chemical or radioactive substance to treated water tank
Basic Event 53 - Biological, chemical or radioactive substance injected to water tank
Basic Event 154 - External attacker destroyes absraction point quality sensors
Basic Event 81 - Additive and/or disinfectant overdose from WTP staff error
Gate 177 - Staff or PLC controlled processes run on altered WTP data
Basic Event 65 - DoS attack to dosing system PLC
Basic Event 67 - Natural phenomena destroy dosing system
Basic Event 161 - External person adds substance to WTP stored additives
Basic Event 279 - Malware corrupts prediction model database
Basic Event 160 - Failure to regulate the temperature, humidity and air quality in environments where information systems are located
Basic Event 78 - Internal person adds substance to WTP coagulant storage tank
Basic Event 77 - External person adds substance to WTP coagulant storage tank
Basic Event 66 - No back-up alternative for WTP dosing system PLC
Basic Event 71 - Contaminated floodwater mixed with treated water in WTP
Basic Event 73 - High biological load from improperly maintained WTP storage tank
Basic Event 42 - External person physically destroys WTP sensors
Basic Event 39 - External person adds substance through monitoring well
Basic Event 162 - Internal person adds substance to WTP stored additives
Basic Event 255 - Man-in-the-Middle attack manipulates local power transformer signals
Basic Event 48 - External person physically manipulates WTP sensor readings
Basic Event 72 - External person induces biological substances to treated water tank
Basic Event 163 - External person attacks surface water system management party e.g. water board
Basic Event 187 - External person physically manipulates groundwater quality sensor readings
Basic Event 68 - External person physically destroys WTP dosing system
Basic Event 39 - External person adds substance through monitoring well
Basic Event 217 - Failure to regulate the temperature, humidity and air quality in environments where information systems are located
Basic Event 276 - SQL injection to data used for demand prediction
Basic Event 233 - External person damages WDN tank
Basic Event 188 - Internal person physically manipulates groundwater quality sensor readings
Basic Event 205 - External person physically destroys WTP sensors
Basic Event 164 - External person physically destroys surface water system sensors
Basic Event 53 - Biological, chemical or radioactive substance injected to water tank
Basic Event 171 - Human error in operating/using surface water management system
Basic Event 257 - Incorrect execution or failure of software acquired from an external party crashes PBS control system
Gate 193 - Surface water management system functions on altered data
Basic Event 250 - Malware alters PLC statements that control pump
Basic Event 170 - External attacker manipulates surface water system transmission devices
Basic Event 194 - External person manipulates transmission wires of wells
Gate 113 - Lower efficiency of WTP disinfectant undetected
Gate 142 - Chemical overdosing due to loss of WTP control
Basic Event 189 - Man-in-the-Middle attack manipulates groundwater quality sensor signal
Basic Event 152 - Man-in-the-Middle attack manipulates quality sensor signals
Basic Event 224 - External person destroys data transmission system of WTP power transformers
Basic Event 209 - External person physically manipulates WTP sensor readings
Basic Event 219 - DoS attack to WTP process system PLC
Basic Event 195 - External person manipulates data transmission system of wells
Gate 118 - Disinfectant composition altered
Gate 122 - THM by-product formation in WTP
Basic Event 151 - External person physicaly manipulates tank quality sensor readings
Basic Event 225 - External person destroys WTP power transformer
Basic Event 190 - External person physically destroys observation well sensors
Basic Event 186 - Quality sensor transmission wires of observation wells manipulated
Gate 143 - External contamination of WTP
Basic Event 156 - Man-in-the-Middle attack manipulates abstraction point quality sensors
Gate 179 - Dosing system destroyed
Basic Event 49 - Internal person physically manipulates WTP sensor readings
Gate 117 - Staff or PLC controlled disinfection processes run on altered WTP data
Basic Event 196 - Man-in-the-Middle attack manipulates well sensor signal
Gate 114 - Staff operate disinfection process without WTP data
Basic Event 191 - External person physically destroys data transmission system of wells
Gate 186 - Quality verification process runs on altered WTP data
Gate 185 - Undetected contamination of WTP chemical solutions
Basic Event 50 - Man-in-the-Middle attack manipulates WTP sensor signal
Basic Event 153 - External attacker manipulates WTP transmission devices
Gate 111 - Insufficient disinfection due to loss of WTP control
Basic Event 47 - Internal person physically destroys WTP sensors
Basic Event 151 - External person physicaly manipulates tank quality sensor readings
Basic Event 41 - Disinfectant missdosage from WTP from operational staff error
Basic Event 62 - Internal person silently takes over SCADA control
Basic Event 61 - External person breaks in to WTP and takes over SCADA undetected
Gate 234 - Contamination of WDN tank
Basic Event 51 - Internal cyber manipulation of WTP sensor signal
Gate 119 - Insufficient disinfection process controlled by intruder
Gate 187 - Contamination of WTP chemical solutions
Basic Event 44 - External person adds substance to WTP disinfectant storage tank
Basic Event 207 - External person destroys WTP transmission wires
Gate 239 - Mislead PLC controlled WDN tank refill process
Basic Event 240 - Upadate of OS causes false positive alarms from Event Detection System
Basic Event 152 - Man-in-the-Middle attack manipulates quality sensor signals
Gate 219 - Staff controlled hydraulic processes run without WTP data
Basic Event 167 - External person physically manipulates surface water system sensor readings
Basic Event 259 - External person physically damages PBS PLC
Basic Event 261 - Undetected SCADA hijacking software takes control of PBS operation
Gate 189 - Additives composition altered
Basic Event 63 - Undetected SCADA hijacking software takes control of WTP operation
Basic Event 178 - Internal person silently takes over reservoir SCADA control
Basic Event 155 - External person physicaly manipulates abstraction point quality sensor readings
Basic Event 45 - Internal person adds substance to WTP disinfectant storage tank
Basic Event 192 - External person physically destroys data transmission wires of wells
Basic Event 260 - Internal person silently takes over PBS SCADA control
Basic Event 64 - Man-in-the-Middle attack manipulates WTP control signals
Basic Event 179 - Man-in-the-Middle attack manipulates reservoir control signals
Basic Event 202 - External person destroys abstraction wells
Basic Event 218 - Accidental errors by authorized user while maintaining information system
Basic Event 197 - External person physically manipulates well sensor signal
Basic Event 211 - External attacker manipulates WTP transmission devices
Basic Event 232 - External person physically interrupts WDN tank outflow
Gate 220 - Staff or PLC controlled hydraulic processes run on altered WTP data
Basic Event 168 - External person physically manipulates surface water system sensor readings
Basic Event 252 - Man-in-the-Middle attack manipulates WDN PBS sensor signals
Basic Event 180 - Incorrect execution or failure of software acquired from an external party crashes reservoir control system
Basic Event 198 - External person breaks in to well control area and takes over SCADA
Basic Event 200 - Incorrect execution or failure of software acquired from an external party crashes abstraction well control system
Basic Event 220 - External person physically destroys WTP process system
Basic Event 214 - Undetected SCADA hijacking software takes control of WTP operation
Basic Event 213 - Internal person silently takes over WTP SCADA control
Basic Event 253 - External person in situ destroys PBS sensors
Basic Event 199 - Internal person silently takes over abstraction well SCADA control
Basic Event 52 - Restricted area authorization procedure failure
Basic Event 221 - Internal person physically destroys WTP process system
Basic Event 177 - External person breaks in to reservoir control area taking over SCADA
Gate 182 - Seepage of contaminated floodwater through monitoring wells
Gate 116 - Chemical overdosing due to misled WTP operation
Basic Event 254 - External person physically destroys PBS data transmission wires
Specific Assets
Additives
Control Center
Control System
Dosing System
Drinking Water Tanks
Power Transformer
Pressure Boosting Station
Pump
Sensor
Server
Spring Water
Transmission Devices
Water under treatment
Well
Measure ID
M09
Name
EntranceAccessControl
Risk reduction mechanism
Frequency/Likelihood
Action characteristics
Proactive