The past two years have been a real wakeup call for the industrial automation industry. For the first time ever it has been the target of sophisticated cyber attacks like Stuxnet, Night Dragon and Duqu.
In addition, an unprecedented number of security vulnerabilities have been exposed in industrial control products and regulatory agencies are demanding compliance to complex and confusing regulations. Cyber security has quickly become a serious issue for professionals in the process and critical infrastructure industries.
If you are a process control engineer, an IT professional in a company with an automation division, or a business manager responsible for safety or security, you may be wondering how your organization can get moving on more robust cyber security practices.
In order to provide you with guidance in this area, Tofino Security and exida Consulting LLC have condensed material from numerous industry standards and best practice documents. They also combined experience in assessing the security of dozens of industrial control systems.
As the Department of Homeland Security (DHS) moves forward with the Chemical Facility Anti-Terrorism Standards (CFATS), the program continues to evolve. This white paper describes the ongoing CFATS compliance process (which is a combination of technical, procedural, and personnel security) and also provides insight regarding how to develop or revise a comprehensive Site Security Plan (SSP) and prepare for a CFATS Authorization Inspection (AI). Recommendations are relevant to SSPs for all tier levels and should be considered for a facility's initial SSP submission and/or any required SSP resubmission. Download this white paper now: Tips for Inspection and Resubmission.
Patching process control system software to remove security vulnerabilities is fraught with risk. System issues can be the result of installing a patch, but a system is also vulnerable without patching. Fortunately, virtual patching can improve the process and raise the system’s security at the same time.
As companies and industries increasingly rely on technology, security risks become greater. With growing numbers of Windows machines and increased scarcity of skilled technical resources, a “perfect storm” of cyber threats in production facilities is looming.
As the security threat landscape continues to evolve, so must your response. With increasing numbers of attempted intrusions, cautionary tales of security breaches and the potential for resulting damages at your site, application whitelisting can be an important addition to your security arsenal.
In the decade before Stuxnet attacked process control systems in Iran, there were just five known supervisory control and data acquisition (SCADA) vulnerabilities for all control systems in the world, according to the U.S. Department of Homeland Security’s Industrial Control Systems Cyber Emergency Response Team (ICS-CERT). In 2011, the year after Stuxnet, that vulnerability count jumped to more than 215. Last year, it reached 248 (Figure 1). No surprise then that Chemical makers are increasingly focusing on protecting their process control systems from intrusion both from the inside and outside. In this Chemical Processing Special Report: Secure plan(t), we take a look at:
How to better protect your control system - “Defense in depth” is crucial, and new and maturing technologies may help
Cyber Security Challenges – learn about countermeasures to protect control systems
Case Study: A vulnerability assessment reveals critical gaps in the security of a natural gas pipeline
How to mitigate security risks in legacy process control systems - several steps can help protect against threats and extend the life of legacy equipment
Learn how to secure your process control systems – and your plant. Download your copy of this Chemical Processing Special Report: Secure plan(t) now.