Assuring Industrial Control System (ICS) Cyber Security
نویسنده
چکیده
Industrial Control Systems (ICS) are an integral part of the industrial infrastructure providing for the national good. These systems include Distributed Control Systems (DCS) Supervisory Control and Data Acquisition systems (SCADA), Programmable Logic Controllers (PLC), and devices such as remote telemetry units (RTU), smart meters, and intelligent field instruments including remotely programmable valves and intelligent electronic relays. While sharing basic constructs with Information Technology (IT) business systems, ICSs are technically, administratively, and functionally more complex and unique than business IT systems. There have been more than 100 intentional and unintentional ICS cyber incidents, ranging from trivial impacts, to significant environmental damage, to serious equipment damage, to deaths. Efforts to secure these critical systems are too diffuse and do not specifically target the unique ICS aspects. The following recommendations provide steps to improve the security and reliability of these very critical systems: Develop a clear understanding of ICS cyber security Develop a clear understanding of the associated impacts on system reliability and safety on the part of industry, government and private citizens Define “cyber” threats in the broadest possible terms including intentional, unintentional, natural and other electronic threats such as Electro Magnetic Pulse (EMP) Develop security technologies and best practices for the field devices based upon actual and expected ICS cyber incidents Develop academic curricula in ICS cyber security Leverage appropriate IT technologies and best practices for securing workstations using commercial off-the-shelf (COTS) operating systems Establish standard certification metrics for ICS processes, systems, personnel, and cyber security Promote/mandate adoption of the NIST Risk Management Framework for all critical infrastructures or at least the industrial infrastructure subset Establish a global, non-governmental Cyber Incident Response Team (CIRT) for Control Systems staffed with control system expertise for information sharing Establish a means for vetting ICS experts rather than using traditional security clearances Provide regulation and incentives for cyber security of critical infrastructure industries Establish, promote, and support an open demonstration facility dedicated to best practices for ICS systems Include Subject Matter Experts with control system experience at high level cyber security planning sessions Change the culture of manufacturing in critical industries so that security is considered as important as performance and safety
منابع مشابه
Risk Assessment For Industrial Control Systems Quantifying Availability Using Mean Failure Cost (MFC)
1 Industrial Control Systems (ICS) are commonly used in industries such as oil and natural gas, transportation, electric, water and wastewater, chemical, pharmaceutical, pulp and paper, food and beverage, as well as discrete manufacturing (e.g., automotive, aerospace, and durable goods.) SCADA systems are generally used to control dispersed assets using centralized data acquisition and supervis...
متن کاملA Distributed IDS for Industrial Control Systems
Cyber-threats are one of the most significant problems faced by modern Industrial Control Systems (ICS), such as SCADA (Supervisory Control and Data Acquisition) systems, as the vulnerabilities of ICS technology become serious threats that can ultimately compromise human lives. This situation demands a domainspecific approach to cyber threat detection within ICS, which is one of the most import...
متن کاملRuntime-Monitoring for Industrial Control Systems
Industrial Control Systems (ICS) are widely deployed in nation’s critical national infrastructures such as utilities, transport, banking and health-care. Whilst Supervisory Control and Data Acquisition (SCADA) systems are commonly deployed to monitor real-time data and operations taking place in the ICS they are typically not equipped to monitor the functional behaviour of individual components...
متن کاملTowards Real-Time Assessment of Industrial Control Systems (ICSs): A Framework for Future Research
According to a report on industrial control system (ICS) security by ICS-CERT (2012), the number of incident reports in 2012 had multiplied to five times their 2010 level. The etiology of this rise is the integration of open and standardised technologies that are traditionally found in IT environments into ICS components, and the interconnection of ICSs to corporate networks and the internet. A...
متن کاملCybernetic modeling of Industrial Control Systems: Towards threat analysis of critical infrastructure
Industrial Control Systems (ICS) encompassing resources for process automation are subjected to a wide variety of security threats. The threat landscape is arising due to increased adoption of Commercial-of-the-shelf (COTS) products as well as the convergence of Internet and legacy systems. Prevalent security approaches for protection of critical infrastructure are scattered among various subsy...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2008