Showing posts with label Industrial Controls Security. Show all posts
Showing posts with label Industrial Controls Security. Show all posts

Monday, August 10, 2015

Pervasive Sensing and Risk Implications

For the past four years I have been talking one class a quarter towards a Masters in Infrastructure Planning and Management offered by the College of Built Environments at the University of Washington in Seattle.

This program is very unique, the classes are entirely online, and I've not seen one like it in my global travels.  It is a fantastic program covering a broad range of critical infrastructure issues (e.g., transportation, water systems, emergency management, etc.) and also offers supporting training in areas such as capital budgeting/finance for government.  Overall I was very impressed with the faculty and level of education.

Well, the end is in sight!  The final assignment due this week is to submit the final Capstone and also prepare a summary presentation on YouTube the  Capstone contents (in 10 minutes!).

The title of my Capstone is: Pervasive Sensing and Industrial Control System Risk Implications.

https://www.youtube.com/watch?v=yyQbUBIVWIo


The YouTube link for the 10-minute narrated PowerPoint is at:  https://www.youtube.com/watch?v=yyQbUBIVWIo

I hope you will find this presentation informative and though-provoking.

Lastly, apologies to those of you made aware of this presentation via a separate Twitter and LinkedIN announcement a few days ago.

Cheers!

###

Thursday, July 9, 2015

Insurance and a US Electric Grid Blackout - A Compelling Read

On July 8, 2015, Lloyd's of London published an excellent report Business Blackout - The insurance implications of a cyber attack on the US power grid.  

(The same day as the United Airlines, Wall Street Journal and New York Stock Exchange cyber events...hmmm, any coincidence?)



This 65-page report is an excellent analysis of the insurance and economic impact on the US following a theoretical cyber attack on the US Northeastern corridor affecting Boston to Washington, DC.  The report is a compelling read for anyone in the cyber security or critical infrastructure domains -- at a minimum the analysis by Lloyd's and the Cambridge Center for Risk Studies Team (University of Cambridge Judge Business School) causes you to take pause to a) better understand the interdependency of infrastructures and b) better learn ways to consider economic impacts of such events.

Key sections of the report include:

  • Executive Summary
  • Introduction to the Scenario
  • The Erebos Cyber Blackout Scenario
  • Direct Impacts to the Economy**
  • Macroeconomic Analysis**
  • Cyber as an Emerging Insurance Risk**
  • Insurance Industry Loss Estimation
  • Annex A:  Cyber Attacks Against Industrial Control Systems since 1999
  • Annex B:  The US Electricity Grid and Cyber Risk to Critical Infrastructure
  • Annex C:  Constructing the Scenario - Threats and Vulnerabilities
** = Focus your reading here...

For some key "bullets" on the report and the scenario, the following were extracted from the Lloyd's web page:


  1. The attackers are able to inflict physical damage on 50 electric generators which supply electrical power in the Northeastern USA, including New York City and Washington, DC.
  2. While the attack is relatively limited in scope (nearly 700 generators supply electricity across the region) it triggers wider blackouts which leaves 93 million people without power.
  3. The total impact to the US economy is estimated at $243B, rising to more than $1T in the most extreme version of the scenario.
  4. Insurance claims arise in over 30 lines of insurance.  The total insured losses are estimated at $21.4B, rising to $71.1B in the most extreme version of the scenario.
  5. A key requirement for an insurance response to cyber risks will be to enhance the quality of data available and to continue the development of probabilistic modelling.
  6. The sharing of cyber attack data is a complex issue, but could be an important element for enabling the insurance solutions required for this key emerging risk.


Hat tip to Eireann Leverett, Senior Risk Researcher and member of the ENISA ICS Security Stakeholders Group for passing along this analysis.

CONCLUSION

If you are involved with critical infrastructure -- especially the electric grid -- take time to read this report cover-to-cover.  If you are worried about the economic impacts of cyber on your business -- read this report to understand the interdependencies.

###




Tuesday, June 30, 2015

Control Engineering 2015 Cyber Security Study

Yesterday I posted a review of the recent SANS State of Industrial Control Systems Survey.  You can find that posting here.

Today I'd like to tell you about another interesting and equally disconcerting survey about the status of today's industrial control system security posture.

Each year Control Engineering Magazine conducts a survey of its readers to evaluate cyber security implementation, resources and training for industrial control systems.  Their 2015 Cyber Security report was issued this June.  A summary of the study posted by Control Engineering is located here.


The Control Engineering report is essentially in presentation format and has a collection of graphs and data relative to the data collected.  It is a pretty easy and quick read and offers similar data to the SANS Survey.

Statistics and Findings

The Control Engineering analysis included data collected from 284 respondents in the first quarter of 2015.  The report includes the following summary findings:

1.  Threat Levels:  47% of respondents perceive their control systems to be "moderately" threatened by cyber attacks.  25% say theirs is "highly" threatened and 8% are at the "severe" threat level.

2.  Most Concerning Threat:  Their responses included:

  • 35% view the most concerning threat is malware from a random source
  • 18% worried about loss of intellectual property
  • 8% fear attacks from "hacktivists" with political or environmental agendas.
3.  Most Vulnerable System Components:  The components of most concern include:
  • Connections to other internal systems (SANS is similar)
  • Computer assets running commercial operating systems (Same as SANS)
  • Network devices
  • Wireless communication devices and protocols
  • Connections to the field SCADA networks
4.  Vulnerability Assessments:  39% of those surveyed said their last vulnerability assessment was performed within the last six months (Good!); while 16% have never executed one (Not So Good).

5.  Publicly Reporting Incidents:  66% of those surveyed say publicly reporting cyber-related incidents would benefit the industry.  36% agree that the biggest problem with public reporting is the fear of losing consumer confidence.

6.  Resources Used to Monitor Control System Cyber Security Events:
  • Anti-virus software (99%)
  • Network logs (89%)
  • Firewall logs (89%)
  • Intrusion Detection/Prevention (84%)
  • Whitelisting (76%)
Overall....

Overall this is a useful survey to examine and as I noted for the SANS ICS Security Survey, these reports should be reviewed and digested by security professionals responsible for ICS security and shared with their executive management to show them that security is a concern and should be theirs, too.

###










Monday, June 29, 2015

State of Industrial Control Systems Security - A SANS Survey

This month the SANS Institute published its annual State of Security in Control Systems Today.  The results were prepared by Messrs. Derek Harp (SANS) and Bengt Gregory-Brown (Sable Lion Ventures LLC).



You can download the report from the SANS Reading Room at:  https://www.sans.org/reading-room/whitepapers/analyst/state-security-control-systems-today-36042 

Some Thoughts...

The report is a quick and useful read.  I'd highly recommend that not only ICS Security Professionals read and digest this report but also it be shown to the skeptical executives in their organization.

So, here are some key bullets gleaned from my read:

  • Top four concerns by those surveyed include:
    • Ensuring reliability and availability (68%)
    • Lowering risk/improving security (40%)
    • Preventing damage (28%)
    • Ensuring health and safety (27%)
  • Rapid detection of security incidents on ICS is key because the longer the breaches remain unknown, the greater the potential impact.
  • The integration of IT into control system networks was chosen by 19% of respondents as the single greatest threat vector.  The top three threat vectors were a) External Threat, b) Internal Threat, and c) Integration of IT into the Control System Networks.
  • 74% of respondents believe that their external connections are not fully documented.  (Ugh!)  Simply identifying and detailing connections and attached devices in a network is a key step to securing it.
  • Another challenge highlighted in the survey is a lack of visibility into control system equipment and network activity.  Thus this inhibits progress in securing assets and decreases activity in accuracy of self-evaluations.
Read the Margin Notes!

One editorial and formatting aspect of the report I liked was inclusion of marginal notes called TAKEAWAYs.  These notes are useful helpful ideas for the ICS security person to implement -- or at least consider -- when trying to protect their ICS systems.  A few examples of the TAKEAWAYs are:
  • Know what is normal.  Lack of visibility into control system networks is one of the greatest barriers to securing these resources.  Without awareness of normal communications and activity, it's impossible to properly evaluate or improve security of assets.  Operations and security staff must be able to visualize and verify normal network operations to detect and assess possible abnormalities and respond to potential breaches.
  • Gain visibility into control system networks.  Map all devices, physical interconnections, logical data channels and implemented ICS protocols among devices, including read coils, write registers, scans and time stamps.  Establish a fingerprint of normal control network activity and communication, including communication patterns, schedules and protocols.  Then, establish device logging, strict change management and automated log analysis based on your baseline data.
  • Integrate security into procurement and decommissioning processes.  Establishing security of software or devices is cheaper, easier and more effective prior to deployment.  The burden of maintaining security is lighter when you start from a secure state.  And, security should be included in the decommissioning and removal of devices to avoid opening serious vulnerabilities.
Again, a great job by SANS, Derek and Bengt!  Take the time to download and read this report and take advantage of the ideas to improve the security of your ICS networks.

###

Friday, June 5, 2015

NIST Publishes Updated ICS Security Guide (Rev 2)

Just a quick note...

NIST Announced today that they have published Rev 2 of the Guide to Industrial Control Systems (ICS) Security SP 800-82!

Great news!  This is a super document to use as a daily reference for ICS security and general knowledge and a great starting point for those who want to learn more about ICS.


You can read more about this release at:  http://www.nist.gov/el/isd/201506_ics_security.cfm

You can download the document (for Free) at:  http://dx.doi.org/10.6028/NIST.SP.800-82r2

CONGRATULATIONS TO KEITH STOUFFER AND HIS TEAM!  WELL DONE!

###





Tuesday, May 26, 2015

New ICS Primer from ISACA

Industrial Control Systems (ICS) security continues to gain momentum and awareness in the cyber community.  ISACA has recently published its own version of ICS security awareness (cover of the document is below).



ISACA has published Industrial Control Systems: A Primer for the Rest of Us which can be obtained for no charge (registration is required) at www.isaca.org/ics 

If you are not familiar with ISACA (www.isaca.org) it has been around since 1969 and has about 115,000 constituents in 180 countries.  You may recognize ISACA as supporting COBIT and also the Certified Information Systems Auditor (CISA) and Certified Information Security Manager (CISM) certifications.

As you glance through the 19-page document you will recognize most of the graphics used come from either NIST 800-82, Guide to Industrial Control Systems (ICS) Security by Keith Stouffer, et al, or adapted from the ICS-CERT Advisories located at: https://ics-cert.us-cert.gov/advisories-by-vendor

One graphic that I especially liked was on page 13, Figure 7, showing a mind-map of Cybersecurity Threat Agents developed by our friends at the European Union Network and Information Security Agency (ENISA).  A copy of the graphic is below and can also be located at http://www.enisa.europa.eu/activities/risk-management/evolving-threat-environment/enisa-threat-landscape/enisa-threat-landscape-2014
























So, the good news is we have another primer to pass along to our bosses and IT managers/technicians  to help them better understand what ICS security involves.  There are a few good ideas in the document such as a list of ICS Components (Pages 4-5) and other references back to the NIST 800-82 document for more details.

###

Tuesday, February 10, 2015

NIST SP800-82 R2 (2nd Draft) Out for Comment

NIST SP800-82, Guide to Industrial Control Systems (ICS) Security, has been a key, seminal guide for those of us working in ICS security.  The original guide was published as a "final" version in June 2011.  Revision 1 to the 800-82 series went final in May 2013.  In May 2014 the Initial Public Draft of Revision 2 was promulgated for comment.  I wrote a blog about this initial public draft on May 20, 2014 and encouraged interested parties to submit their comments.


Brief History of SP800-82

A few months ago I wrote an article for SearchSecurity on the Evolution of SP 800-82.  As part of this article I researched the history of this document and its development and ultimately prepared the Visio timeline shown below.  One thing I was sure to do was to obtain Keith Stouffer's (principal author of SP800-82 series) approval on the timeline accuracy.

(Apologies for the overlay with the right margin; however, if the chart goes too small then it is hard to read.  Thanks for understanding.)


What are the Revisions?

The new document out for comment is the second revision to NIST SP800-82.  From the NIST Website, updates in this new revision include:

  • Updates to ICS threats and vulnerabilities
  • Updates to ICS risk management recommended practices and architectures
  • Updates to current activities in ICS security
  • Updates to security capabilities and tools for ICS
  • Additional alignment with other ICS security standards and guidelines
  • New tailoring guidance for NIST SP800-53, Revision 4 security controls including the introduction of overlays, and
  • An ICS overlay for NIST SP800-53, Revision 4 security controls that provides tailored security control baselines for Low, Moderate, and High Impact ICS.

When are Comments Due?

The public comment period is from February 9th to March 9th, 2015 (on month).  You can email your comments to nist800-82rev2comments@nist.gov.  You are encouraged to use a comment template form (Excel File) to collect your feedback for submittal.

Your comments are requested to make this a better, more thorough document for the industry.  Thank you!

COMMENTS DUE MARCH 9, 2015

###




Tuesday, January 27, 2015

ENISA Publishes Cyber Threat Analysis of 2014

Our friends at the European Union Agency for Network and Information Security (ENISA) has published the ENISA Threat Landscape 2014 on 27 January 2015.  The report includes some details on developments made in 2014 relative to the top cyber threats and emerging threat trends - mainly in the cyber arena.

You can download a copy of the report (Free) at:  http://www.enisa.europa.eu/activities/risk-management/evolving-threat-environment/enisa-threat-landscape/enisa-threat-landscape-2014




From the Executive Summary of the report, below are some of the "positives and negatives" of today's cyber threat landscape from ENISA's point of view.

Many of the changes in the top threats can be attributed to successful law enforcement operations and mobilisation of the cyber-security community (bolding by Ernie Hayden):

  • The take down of GameOver Zeus botnet has almost immediately stopped infection campaigns and Command and Control communication with infected machines.
  • Last year’s arrest of the developers of Blackhole has shown its effect in 2014 when use of the exploit kit has been massively reduced.
  • NTP-based reflection within DDoS attacks are declining as a result of a reduction of infected servers. This in turn was due to awareness raising efforts within the security community.
  • SQL injection, one of the main tools used to compromise web sites, is on the decline due to a broader understanding of the issue in the web development community.
  • Taking off-line Silk Road 2 and another 400 hidden services in the dark net has created a shock in TOR community, both at the attackers and TOR users ends.

But there is a dark side of the threat landscape of 2014:

  • SSL and TLS, the core security protocols of the internet have been under massive stress, after a number of incidents have unveiled significant flaws in their implementation .
  • 2014 can be called the year of data breach. The massive data breaches that have been identified demonstrate how effectively cyber threat agents abuse security weaknesses of businesses and governments.
  • A vulnerability found in the BASH shell may have a long term impact on a large number of components using older versions, often implemented as embedded software.
  • Privacy violations, revealed through media reports on surveillance practices have weakened the trust of users in the internet and e-services in general.
  • Increased sophistication and advances in targeted campaigns have demonstrated new qualities of attacks, thus increasing efficiency and evasion through security defences.
The report does include a summary table of trends (Page 4) that the reader may find useful.  A copy of the table is shown below with some highlights on the areas declining and a note about ransomware.



Lastly, one area the report raises as a new focus is "Cyber-Physical Systems."  These are engineered systems that interact with computing equipment and integrated to control, manage and optimize physical processes.  The areas they mention of concern are power supply, medical systems/healthcare, industrial systems and manufacturing, transportation, telecommunication, etc.  The report includes a table (below) of the Top Emerging (Preliminary) Threats to CPS (Page 67):



Overall, the report is of excellent quality and is a useful summary of the cyber issues of 2014.

###


Sunday, November 30, 2014

Hazards of Decommissioned Equipment

In my global travels while performing inspections of power plants, factories and other critical infrastructure I often see equipment that is "decommissioned."  It is understandable that the cost of removing large, heavy equipment is expensive; however, I have often wondered aloud why the factory managers do not tag or identify the equipment as decommissioned.



One idea I've proposed is to place a large hot orange/hot pink tag on the decommissioned equipment so that personnel will recognize its status.  Even the occasional auditor or inspector may even declare it as a "Good Practice."

In the November 2014 issue of Control Engineering magazine J. B. Titus wrote a short but useful article about the "12 hazards of unused machinery." (Page 24)

J. B. notes the following:

"Even though a machine may no longer be active in the production process, this does not mean that the machine has been rendered hazard free..."

J. B. continues to observe that a decommissioned machine may pose one or more of the following hazards:

  1. Live electrical connections
  2. Compressed gases or fluids
  3. Charged tie rods
  4. Compressed springs
  5. Gravity
  6. Hazardous materials
  7. Rust
  8. Flammable or combustible material
  9. Abandoned conduit as a route for hazardous vapors
  10. Leakage
  11. Blocking emergency access
  12. Other machine, application, or environmental considerations
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjffgGx0KzYJBYDXyIbjYlduJ0uQhDP0eZxrKay1hFkWbohlFA0aMGsK0MMVsHNYXBcFhPc2r1AAG0XFl5QmtEGWBUnB-bUWRVkNokS0XTcTAGFFSiimlSf80YHNKIKxC53RtA7qI4YVgo/s640/P1030603.JPG 



I heartily agree with JP and wished I had his article handy during my previous inspections where I've highlighted concerns about decommissioned equipment and the hazards posed. The plant or factory management needs to recognize the risks with these "turned off pieces of equipment" and mitigation actions taken.

Thanks to J. P. Titus for the brief article and thanks for giving more support for my arguements that decommissioned equipment is not a trivial issue.

### END ###

Tuesday, May 20, 2014

NIST SP800-82 Rev 2 - Guide to ICS Security -- Comments Requested

Last week the National Institute of Standards and Technology (NIST) published the initial public draft of Special Publication 800-82, Revision 2, Guide to Industrial Control Systems (ICS) Security.  This particular revision to the highly popular 800-82 versions 0 and 1 is a positive step change in the volume of information contained in the document.



In summary -- and extracted from page iv of the 255-page report -- the updates to this revision include:

  • Updates to ICS threats and vulnerabilities
  • Updates to ICS risk management, recommended practices, and architectures
  • Updates to current activities in ICS security
  • Updates to security capabilities and tools for ICS
  • Additional alignment with other ICS security standards and guidelines
The report also has added new tailoring guidance for NIST SP800-53, Rev 4, Security and Privacy Controls for Federal Information Systems and Organizationssecurity controls including the introduction of overlays.  Also, the report has added an ICS overlay for NIST SP800-53, Rev $, security controls that provides tailored security controls for Low, Moderate, and High impact ICS.

As a member of the Industrial Controls Security Joint Working Group (ICSJWG) Standards Committee I had the opportunity to review chapter 3, "ICS Risk Management and Assessment," which is a new expansion from the earlier versions.  This chapter alone provides some expanded views of the risks posed by ICS environments.

Appendix C, "Threat Sources, Vulnerabilities and Incidents," is a useful compilation of text and tables covering such topics as ICS Threat Sources, Vulnerabilities and Predisposing Conditions, System Vulnerabilities and a list of documented incidents.

Of note, Appendix F, "References," is an excellent list of 80 different references not only used in developing the document but also would be an excellent resource for the ICS security student or practitioner. However, I am a bit surprised and disappointed that Eric Knapp's Industrial Network Security book was not included since it is one of the best resources published on this topic.

Call to Action

First, if you are interested in Industrial Controls Security, download this new version and put it on your reference shelf for your ICS projects.  It is free and provides even more insight into the ICS arena.

Secondly, if you are an IT Security instructor be sure to show this to your students and perhaps include ICS security as part of your curriculum.  SP800-82 would be an excellent textbook and again it is no charge except for the cost to print.

Thirdly, SP800-82 R2 is out for public comment until July 18, 2014.  If you are so inclined take some time to read the new document and offer your comments via email at nist800-82rev2comments@nist.gov or you can mail them to:

National Institute of Standards and Technololgy
Attn: Computer Security Division, Information Technology Laboratory
100 Bureau Drive (Mail Stop 8930)
Gaithersburg, MD  20899-8930

Thanks again and happy reading!

 


Thursday, April 17, 2014

Two Views of Today's Cyber Risks

This week I've had the chance to view two reports that gave me -- and I expect others -- a powerful view of the cyber challenges we face.  One report was a global view our reliance on the Web and the "...increasing danger of global shocks initiated and amplified by the interconnected nature of the internet."

The second article was a survey done by Control Engineering magazine on the global views of cyber security of the industrial controls domain.  The survey revealed that almost 50% of the respondents perceive the control system threat in their organizations to be at a moderate level, but 25% cite a "high" or "severe" threat level in their systems.

So, rather than provide detailed reviews of each document, let me help aim you to the appropriate links with some summary notes added:

Risk Nexus - Beyond Data Breaches: Global Interconnections of Cyber Risk -- Zurich and Atlantic Council

(LINK) 
This well-written report (30 pages) consistently raises the bar of the global risk relative to our reliance on the Internet and ecommerce in a manner similar to the annual World Economic Forum's Risk Reports.  Perhaps we are so closely connected to the Internet that we put our selves in harm's way relative to our economic -- and maybe even mental well being (?).

One quote that I find especially telling is:

"The internet of tomorrow will both initiate and amplify global shocks in ways for which risk managers, corporate executives, board directors, and government officials may not be adequately prepared."

Finally, take a look at Page 8 of the report...they include 7 aggregations of cyber risk that certainly made me think:


  1. Internal IT enterprise (hardware, software, servers, and related people and processes)
  2. Counterparties and partners (relationship between competing/cooperating entities, etc.)
  3. Outsourced and contract (IT and cloud providers, contract manufacturing)
  4. Supply chain (Exposure to a single country, counterfeit or tampered products, risks of disrupted supply chain)
  5. Disruptive technologies (internet of things, smart grid, embedded medical devices, driverless cars...)
  6. Upstream infrastructure (submarine cables, internet governance and operation)
  7. External shocks (major international conflicts, malware pandemics)

At a minimum I'd suggest you pass this report to your Board of Directors and Executive Management so they get a sense of another view of risks that need to be addressed and mitigated.


Control Engineering Cyber Security Study - April 2014 (Registration Required)

(LINK)
Compliments to the Director of Research for Control Engineering, Ms. Amanda McLeman and her colleague Mark Hoske for this summary report.  The report is based on a survey of about 190 respondents from February 7 to March 2, 2014.  So the data is fairly contemporary.

This summary report is a collection of graphs showing the demographics of the respondents as well as the summary results of the questions.

A good summary graph of the Threats considered by the respondents is below:


If you cannot adequately read the graphic above the top three system components the respondents are most concerned about are:

  1. Computer assets that are running commercial operating systems
  2. Connections to other internal systems
  3. Network devices
Finally a summary of key "bullets" from the report include:
  • 24% of respondents said they had NEVER performed a systems security vulnerability test
  • 25% of those surveyed indicated their computer emergency response team appears well trained and capable
  • 41% agreed having industry-required standards without government involvement would improve or enable their efforts to implement proper control system cybersecurity.  (So, maybe the NIST Cyber Security Framework has some hope?)
Thanks for taking the time to read my comments and have a good week!

###








Thursday, April 3, 2014

A Month-Long View of Industrial Controls Security Training

For the past four weeks I have been immersed in Industrial Controls Systems (ICS ) security training.  My journey began on March 12th where I spent five days in the SANS ICS training in Orlando followed by about 15 hours of web-based ICS training from ICS-CERT then two days in Burbank, California attending the ISA training on the ANSI/ISA-62443 Standards.  (By the way, the 62443 standard used to be called the ISA99 standard.)

What I'd like to do is offer a view of these different training options to give you a sense of why some professionals will need this training and how the ICS-CERT training can be especially helpful for managers and supervisors overseeing work on ICS.  Also, I'll let you know about free training that does not require travel or substantial resources.

Why am I Taking These Classes?

Right now my employer -- Securicon -- is focusing on industrial control security and the SANS certification program -- GICSP - discussed later -- may be a key cert to have in the company for future work at some select global energy/oil/gas companies.  Secondly, one vendor we work with has asked us to complete the ISA training on the ISA-62443 standards.  Therefore, I'm the designated player for the company and have been sent to these courses - not that I'm complaining!  I love this stuff and I'm up for another security certification in this domain.

SANS ICS410 ICS/SCADA Security Essentials (~$4,395 + $599 for GICSP test)



This course is offered in a classroom (and now as an online option) by SANS.  I was privileged to be in a class in Orlando with about 57 other students from literally around the globe.  The instructor was Mr. Justin Searle who is by far one of the best IT security instructors I have ever experienced as either a student or co-instructor.

The course runs for five consecutive days with class beginning at 9 AM and ending at 5 PM with breaks and a lunch in between.  The days were broken down into the following:


  • Day 1 - Industrial Control Systems (ICS) Overview
  • Day 2 - ICS Attack Surface
  • Day 3 - Defending ICS Servers and Workstations
  • Day 4 - Defending ICS Networks and Devices
  • Day 5 - ICS Governance and Resources 
Each day some hands-on exercises were included.  

At the end of the training you receive a certificate of completion; however, the true goal for myself and many others is to pass the Global Industrial Controls Security Professional (GICSP) certification from SANS.



The GICSP certification involves a separate test which requires the student pass with a minimum passing score of 69%.  I hope to take this test before the end of April.

For more details on the GICSP and the class please go to these links:  GICSP, ICS410, SANS ICS Security.

ISA - Using the ANSI/ISA-62443 Standards to Secure Your Control System (~$1,510)



I just finished this course on April 2nd in Burbank, CA.  The class is a two-day event and this recent course was taught by Mr. John Cusimano -- again, another very good and knowledgeable instructor.  The class size was very conducive to open dialogue with the instructor and other students.

The focus of these two days was on the following key topics:

Day 1:
  • Introduction to Control Systems Security and ISA/IEC62443 Standards
  • Terminology, Concepts, Models and Metrics
  • Networking Basics (Do you know your OSI Model??)
  • Network Security Basics
Day 2:
  • Creating an ICS Security Management Program
  • Designing/Validating Secure Systems
  • Developing Secure Products and Systems
And like the SANS Course, some hands-on exercises were included using tools such as Wireshark and the command line (e.g., Netstat -a).

Upon completion of this test you are eligible to take a proctored test called the ISA99 Exam.  Passing this test will give you the ISA99 certificate from ISA that demonstrates your knowledge and capabilities with the ISA standards used to secure industrial control systems.

For more information you can go the ISA Cybersecurity site.

I hope to take this test before the end of April.

ICS-CERT Online Training -- Excellent Resource! (Free)



Finally, for my "spare time" between the SANS and ISA training I've been working on two courses offered at no charge by the US Department of Homeland Security ICS-CERT organization.

The two courses are both web-based and only require that you register with the Training Portal.

The first class I took was 100W - Operational Security (OPSEC) for Control Systems.  This is a one-hour on-line class that is focused on ways to protect your industrial control systems by being cautious about releasing network information outside the company or to those who don't have a need to know.  The course also addresses phishing attacks, etc.  You get a certificate "...suitable for framing..." at the end of the course.

The second course -- which I highly recommend to executives, managers, supervisors and engineers interested in learning more about ICS security -- was 210W - Cybersecurity for Industrial Control Systems.  This course was excellent and took about 15-20 hours to complete.  

There are 10 separate modules that are listed below:
  • Differences in Deployments of ICS
  • Influence of Common IT Components on ICS
  • Common ICS Components
  • Cybersecurity within IT and ICS Domains
  • Cybersecurity Risk
  • Current Trends (Threats)
  • Current Trends (Vulnerabilities)
  • Determining the Impacts of a Cybersecurity Incident
  • Attack Methodologies in IT and ICS
  • Mapping IT Defense-in-Depth Security Solutions for ICS (longest but best module!)
Again, this training does not require any money but only requires your time to take the modules (which you can stagger over time).

Conclusion

ICS security continues to get focus from the industry and government.  That is why SANS, ISA and ICS-CERT are continuing to bring in training modules for a broad range of players from journeymen electricians to utility executives.  Take advantage of the training -- at least the free classes -- so you better understand how to best defend your Industrial Control systems.

###





Monday, February 24, 2014

Useful Industrial Control Security References from ENISA

ENISA - the European Union Agency for Network and Information Security has been quietly building a collection of useful references for industrial control system (ICS) security.  Since 2011 with their publication of Protecting Industrial Control Systems.Recommendations for Europe and Member States, Dr. Konstantinos Moulianos and his staff have done a nice job facilitating development of useful publications for those of us in this domain.



What I'd like to do is to continue to tell you of the other ICS-security-related products that have been published that may be useful references for students and practitioners of ICS security.

In 2011 as ENISA was publishing the referenced document above (and shown in the photo) they also produced five separate Annexes as part of the Recommendations document.  These documents were certainly foundational to the continued expansion of the ENISA ICS Security "product line."  One document I found to be a useful introductory discussion of ICS security was the ENISA document Protecting Industrial Control Systems, Annex I: Desktop Research Results.  Similar to NIST 800-82, Guide to Industrial Control System (ICS) Security, this document is a helpful background "textbook" on the basic issues associated with ICS security, emerging issues, the challenges with securing ICS systems, and known good practices as of 2011.

Later in 2013, ENISA was very busy publishing several useful documents to aid in improving cybersecurity in Europe but of course helping the rest of the world with its guidance and studies.  In particular ENISA facilitated and funded a study on identifying ways to improve on ICS component and system testing in the EU. (I was honored to have been included in the interview process for this study.)  The result was the ENISA document Good Practices for an EU ICS Testing Coordination Capability.  This document certainly raised some awareness on how to proceed in Europe with development of an ICS testing capability but it can also be used in other nations just beginning to  examine their ICS security reviews.

One very useful desk reference that came out of the EU ICS Testing Coordination project was publication of ICS Security Related Working Groups, Standardsand Initiatives (2013).  This particular document is an excellent collection of the various global standards, guidelines and studies conducted that focus on ICS security issues.  This one is a "keeper!"



Finally, in late 2013 the ENISA team was very busy with some white papers and briefings on ICS security issues we are all facing.  The documents and their links are listed below:
I trust you found this an enlightening review of the ENISA ICS Security work since 2011 and I'd suggest you keep them on your mind when looking for ICS security resources and references to help improve and harden your security programs.



Thursday, February 6, 2014

Industrial Control Security -- More Awareness Needed

I am an active reader of various blogs, e-magazines, websites, etc. regarding industrial control system (ICS) security.  This week I came across a rather disturbing survey that indicates more work is needed in the ICS security domain to raise awareness of the availability of useful ICS security resources.

This week I was looking at Control Engineering e-magazine and noted that they had a survey on ICS security.  The question posed was:

Do you follow cyber security resources to check for security vulnerabilities in the devices in your industrial networks, such as PLCs, RTUs, Ethernet switches, HMIs, DCSs, etc.?

The poll result is shown in the graphic below and you can add your own vote at Link.




What disturbs me about the poll results is the majority of those responding to this unscientific survey have "...no idea such a resource was available."  This tells me that the ICS security community needs to do more work publicizing its resources in order to help the field engineers make their ICS systems more secure.

So, to help in this regard, here are some resources you will find extremely useful in helping to better understand the current ICS security vulnerabilities and how to better defend your ICS networks:

Excellent "Textbooks" and Desk References:

Excellent Resources on ICS Security Vulnerabilities, Protective Actions

** ICS-CERT encourages U.S. asset owners and operators to join the Control Systems compartment of the US-CERT secure portal. Send your name, e-mail address, and company affiliation to ics-cert@hq.dhs.gov.

What Else?

There are many other resources that include vendor notifications and alerts as well as other resources from standards organizations such as ISA but the above list of links is an excellent starting point for you to gather references and subscribe to data feeds from ICS-CERT.

Overall, though, it is our job in the Security Community to help everyone realize what resources exist in the world to provide guidance on securing critical infrastructure and industrial control systems.

###

Friday, January 10, 2014

SANS White Paper -- Cybersecurity Response to Physical Breaches of Unmanned Critical Infrastructure Sites

Our friend Mike Assante -- formerly of Idaho National Labs/National SCADA Test Bed, NERC, and now with SANS -- has coauthored an interesting and informative white paper on responses to physical breaches of unmanned critical infrastructure sites. The cover is shown below.



The whitepaper can be located at: http://tinyurl.com/ldfnzxq

One of the most interesting graphics in the paper (Appendix A, Page 12) is a collection of photos showing the ways/means of the miscreants to tap into the systems with such tools as keystroke loggers, etc.  The page is shown below to whet your appetite for this paper.


Nicely done and "attaboys" to Mike Assante, Scott D. Swartz and the SANS ICS team!

Also, my good friend Andy Bochman wrote about this at his Smart Grid Security Blog.  Thanks, Andy!!

####################





Thursday, January 2, 2014

2014 -- And What It Brings...

Happy New Year!  Welcome to 2014 and all the opportunities it brings!

Wow, 2013 has flown by!  For this year I will continue to focus this Blog on Critical Infrastructure issues and augment it with some discussions focused on some of the key questions and topics I think will affect all of us this year.

So, for a “bulletized” recap of the topical areas I’ll ponder please consider the following:

·         Critical Infrastructure Protection
o   What will happen with the NIST Cybersecurity Framework?
o   What news and events will surface for the 16 critical infrastructure areas designated by PDD-21?

o   How will the electric industry react to the new NERC CIP Version 5 mandates? And the NIST Cybersecurity Framework?

·         Industrial Controls Systems Security
o   This is a continuation of the areas reviewed last year including the SANS Global Industrial Cyber Security Professional (GICSP) certification activities and new ICS-security emphasis from other cyber-security agencies outside of the US ICS-CERT and even overseas with ENISA, etc.

·         Supply Chain Security
o   I find this a fascinating topic that is finally getting to the front pages of many business journals
o   Again, I will be examining ideas for both physical and cyber protection as well as new legislation impacting cyber defense and threat mitigation

·         Cyberwar
o   This area is particularly intriguing with continued stories about nation-state attacks and defenses
o   Added discussions about “hack-back” and “Active Defense” will be included

·         Cyber Risk Issues and Psychology of Security/Risk
o   The annual meeting in Davos for the WorldEconomic Forum surfaces some very interesting discussions about threats to the digital economy that are not part of the mainstream IT press

So, this should be an interesting year and one that keeps us all busy.  Overall, though, my objectives for this Blog are to a) educate, b) entertain and c) make you think about today’s new challenges to our security and critical infrastructure resilience.

Lastly, I’ll also be busy with Twitter forwarding news items that follow the themes above.  Feel free to follow me @ErnieHayden

I look forward to your comments, ideas and feedback and if you hear of some news items that fit into my list above, I’d love to hear about it at enhayden1321@gmail.com

Happy New Year and all the best!


Ernie

Wednesday, November 6, 2013

"The Bits and Bytes ... have been Weaponized"

In a fascinating article published yesterday in Automation World the author reviewed the opening remarks and panel conversations being held at the ISA Automation Week conference in Nashville.

Retired USAF Brigadier General Rudolf Peksens was quoted as saying:

“The bits and bytes in our systems have been weaponized, and your systems are being penetrated at will.” 

http://misteriosdomundo.com/wp-content/uploads/2012/05/Bits.jpg

In the Industrial Controls Security space as well as the enterprise domain there are many concerns about how the cyber "bad guys" are causing problems with theft of intellectual property, financial information and instruments, etc.  Even Stuxnet has been declared to be a cyber weapon -- and don't forget Shamoon and its impact in the Middle East.


Anyway, the article is a good read if you are into critical infrastructure protection with emphasis on cyber security of both IT and Operations Technology (OT) systems.  The point is that the "battle space" is expanding with the expansion of digital devices and systems and we need to pay attention and take defensive action.

Cheers!