• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
Athens Group Logo

Athens Group Services

Rig Inspection

  • Home
  • Services
    • Reactivation, Commissioning, and Upgrade
    • Marine Services
    • Rig Inspection & Acceptance
    • Well Control Equipment
    • Cybersecurity
      • TMECA®
    • Risk Management
  • About Us
    • About Us
    • Our Mission & Core Business Principles
    • Athens Group Services Advantage
    • Surveyor Competency Assurance
    • Integrated Knowledge Management
    • Covid-19 Policy
    • Workplace
    • CyberSecurity Policy
  • News & Resources
    • Projects
    • Newsletters
    • Oil Field Digitalization
  • Contact

CyberSecurity: Use the Tools You Have – FMECA

April 16, 2019
LnRiLWZpZWxke21hcmdpbi1ib3R0b206MC43NmVtfS50Yi1maWVsZC0tbGVmdHt0ZXh0LWFsaWduOmxlZnR9LnRiLWZpZWxkLS1jZW50ZXJ7dGV4dC1hbGlnbjpjZW50ZXJ9LnRiLWZpZWxkLS1yaWdodHt0ZXh0LWFsaWduOnJpZ2h0fS50Yi1maWVsZF9fc2t5cGVfcHJldmlld3twYWRkaW5nOjEwcHggMjBweDtib3JkZXItcmFkaXVzOjNweDtjb2xvcjojZmZmO2JhY2tncm91bmQ6IzAwYWZlZTtkaXNwbGF5OmlubGluZS1ibG9ja311bC5nbGlkZV9fc2xpZGVze21hcmdpbjowfQ==
IEBtZWRpYSBvbmx5IHNjcmVlbiBhbmQgKG1heC13aWR0aDogNzgxcHgpIHsgICB9IEBtZWRpYSBvbmx5IHNjcmVlbiBhbmQgKG1heC13aWR0aDogNTk5cHgpIHsgICB9IA==

In our last three posts, we looked at three tools you already use to help provide a safely functioning system at the front end – HAZOP, HAZID, and Failure Modes, Effects, and Criticality Analysis (FMECA) – and recommended their use for CyberSecurity. In our most recent post, we looked specifically at utilizing HAZIDs for CyberSecurity. We’ll now take a look at utilizing the FMECA for the same purpose. 

How can we make our FMECA’s address CyberSecurity? First by following an established FMECA process starting with Discovery:

Then, include the following in the initial sets of documents:

  1. System Network Topology including all access points
  2. External Users including contractor access, application access, classes of users
  3. Internal Users including application access, classes of users
  4. Access policies
  5. User responsibilities
  6. Management of Change Policy
  7. Formats for operational access logs
  8. Current activity logs for existing or “as like” assets
  9. Typical network traffic

In the workshop phase of the FMECA focus on CyberSecurity Risks:

  1. Security breach or hacker attack
  2. Loss or compromise of customers data
  3. Loss or compromise of employee data
  4. Loss or compromise of intellectual property and trade secrets
  5. DDoS attack
  6. Monetary loss
  7. Violation of laws and regulations
  8. Virus/ransomware attack
  9. Damaging downtime
  10. Reputational damage
  11. Physical data loss

Finally, in the Reporting Phase ensure that CyberSecurity is emphasized:

That’s it for recognizing CyberSecurity in your FMECA. Next, we’ll recap putting CyberSecurity into your projects using the HAZOP, HAZID and FMECA tools.

Read the blog entries on our website – www.athensgroupservices.com, join our LinkedIn Group, and subscribe to our newsletter.

Category: Oil Field DigitalizationTag: Oil Field Digitalization Series
Previous Post:CyberSecurity: Use the Tools You Have – HAZID
Next Post:CyberSecurity: Use the Tools You Have – Wrap-Up
  • Home
  • Services
    • Reactivation, Commissioning, and Upgrade
    • Marine Services
    • Rig Inspection & Acceptance
    • Well Control Equipment
    • Cybersecurity
      • TMECA®
    • Risk Management
  • About Us
    • About Us
    • Our Mission & Core Business Principles
    • Athens Group Services Advantage
    • Surveyor Competency Assurance
    • Integrated Knowledge Management
    • Covid-19 Policy
    • Workplace
    • CyberSecurity Policy
  • News & Resources
    • Projects
    • Newsletters
    • Oil Field Digitalization
  • Contact

Contact


(858) 926-5504

Contact Us

Follow Us


Follow along on social media

  • Twitter
  • LinkedIn

Copyright © 2023 · Athens Group Services · All Rights Reserved

Return to top