
• Research into how updateability in the distributed
HW could be optimized to account for rapid and
continuous updates to keep up with the pace in
technological developments could provide an en-
hancement in technological lifespan for the next
generation of AMI.
• Considering the proposed recommendation of a
centralized approval authority for information
systems in the energy sector and AMI, further
research could investigate the viability and fea-
sibility of such a solution. Research concern-
ing how to organize and unify the regulation of
information security in such an entity could be
conducted, considering the model from the De-
fense sector. Further, research concerning how the
technical evaluation of implementations should be
conducted during the pre-approval process would
be beneficial to development of structures and
routines in relation to organizing such work.
ACKNOWLEDGEMENTS
This work was supported by the Research Council
of Norway [grant number 310105 ”Norwegian Centre
for Cybersecurity in Critical Sectors - NORCICS”].
REFERENCES
Asplund, M. and Nadjm-Tehrani, S. (2016). Attitudes and
Perceptions of IoT Security in Critical Societal Ser-
vices. IEEE Access, 4:2130–2138.
Energiloven – enl (1990). Lov om produksjon, omform-
ing, overføring, omsetning, fordeling og bruk av en-
ergi m.m. (energiloven).
Frogner, K. P., Lien, E., and Bergh, K. M. G. (2021).
Smart energy metering and its infrastructure – A sur-
vey on vulnerabilities and information security chal-
lenges. Department of Information Security and Com-
munication Technology, NTNU.
Frøystad, C., Jaatun, M. G., Bernsmed, K., and Moe, M.
(2018). Risiko- og s
˚
arbarhetsanalyse for økt inte-
grasjon av AMS-DMS-SCADA. Report 978-82-410-
1789-6, NVE.
Geiger, M., Bauer, J., Masuch, M., and Franke, J. (2020).
An Analysis of Black Energy 3, Crashoverride, and
Trisis, Three Malware Approaches Targeting Opera-
tional Technology Systems. In 2020 25th IEEE Inter-
national Conference on Emerging Technologies and
Factory Automation (ETFA), volume 1, pages 1537–
1543. IEEE.
Gunduz, M. Z. and Das, R. (2020). Cyber-security on smart
grid: Threats and potential solutions. Computer Net-
works, 169.
Hansen, A., Staggs, J., and Shenoi, S. (2017). Security anal-
ysis of an advanced metering infrastructure. Inter-
national journal of critical infrastructure protection,
18:3–19.
Husnoo, M. A., Anwar, A., Hosseinzadeh, N., Islam, S. N.,
Mahmood, A. N., and Doss, R. (2023). False data in-
jection threats in active distribution systems: A com-
prehensive survey. Future Generation Computer Sys-
tems, 140:344–364.
Jesson, J., Matheson, L., and Lacey, F. M. (2011). Do-
ing your literature review: Traditional and systematic
techniques. Sage, London.
Kraftberedskapsforskriften (2012). Forskrift om sikker-
het og beredskap i kraftforsyningen (kraftberedskaps-
forskriften).
Larsen, M. H., Lund, M. S., and Bjørneseth, F. B. (2022). A
model of factors influencing deck officers’ cyber risk
perception in offshore operations. Maritime Transport
Research, 3:100065.
Lien, E. and Bergh, K. M. G. (2023). Attitudes and Percep-
tion of AMI Information Security in the Energy Sector
of Norway. Master thesis, NTNU.
Line, M. B., Johansen, G. I., and Sæle, H. (2012).
Risikovurdering av AMS. Kartlegging av infor-
masjonssikkerhetsmessige s
˚
arbarheter i AMS. Report
8214052807, SINTEF.
Nasjonal sikkerhetsmyndighet (2020). Risiko 2020. Ac-
cessed on 2021-09-20.
Nasjonal sikkerhetsmyndighet (2021). Risiko 2021. Ac-
cessed on 2021-09-20.
Nasjonal sikkerhetsmyndighet (2022). Risiko 2022. Ac-
cessed on 2023-04-02.
NOU 2015:13 (2015). Digital s
˚
arbarhet - sikkert samfunn.
Beskytte enkeltmennesker og samfunn i en digitalisert
verden. Accessed on 2022-12-11.
Politiets sikkerhetstjeneste (2020). Nasjonal trusselvurder-
ing 2020. Accessed on 2022-09-10.
Politiets sikkerhetstjeneste (2021). Nasjonal trusselvurder-
ing 2021. Accessed on 2022-09-11.
Skotnes, R. Ø. (2015). Risk perception regarding the
safety and security of ICT systems in electric power
supply network companies. Safety Science Monitor,
19(1):Article 4.
Sæle, H., Ingebrigtsen, K., and Istad, M. (2019). Fremti-
dens avanserte m
˚
ale og styringssystem (ams): Forven-
tet utvikling 2-5
˚
ar frem i tid. Report 978-82-410-
1921-0, SINTEF Energi AS.
Venjum, A. (2016). Smarte m
˚
alere (AMS): Status og planer
for installasjon per 1. halv
˚
ar 2016. Report 978-82-
410-1532-8, NVE.
Wei, L., Rondon, L. P., Moghadasi, A., and Sarwat, A. I.
Review of cyber-physical attacks and counter defense
mechanisms for advanced metering infrastructure in
smart grid. In 2018 IEEE/PES Transmission and Dis-
tribution Conference and Exposition (T&D), pages 1–
9. IEEE.
Wei, M. and Wang, W. (2016). Data-centric threats and
their impacts to real-time communications in smart
grid. Computer Networks, 104:174–188.
ICISSP 2024 - 10th International Conference on Information Systems Security and Privacy
194