I Want to Secure My Industrial Control System – What’s the First Step

Industrial Control System (ICS) operators recognize the need to improve cybersecurity, but many lack the understanding on how to start the process.  End users attend cybersecurity conferences, webinars, or read articles in the trade press and learn about specific cybersecurity topics – like threat detection or defense in depth architectures.  Many are tempted to start to take steps to improve security – but it is critical to first create a plan prior to taking action.  Schneider Electric has issued a white paper designed to provide guidance to operators who are initiating projects to secure industrial control systems.

The whitepaper introduces the cybersecurity lifecycle which consists of four phases; Assessment, Implementation, Maintenance, and Auditing.  The white paper focuses on the Assessment Phase, and provides a detailed overview of the steps required to create a security plan.  The Assessment Phase is divided into 4 major steps:

  • Documenting the System – Discovering all devices in the targeted system and mapping them to illustrate location and connectivity. A detailed asset inventory is then created that provides configuration details for system components.
  • Vulnerability Assessment – Designed to enable operators to identify and document potential vulnerabilities. The vulnerability assessment utilizes accepted cybersecurity frameworks and tools to identity vulnerabilities.
  • Implementing Zone/Conduit Architecture – Segmenting the network into zones and conduits. Equipment is grouped based on the criticality of the assets, operational function, physical/logical location, or access requirements.
  • Risk Assessment – Risk assessment prioritizes activities to secure a system. Risk assessment allows the organization to select countermeasures that will have the greatest impact on system security.

The threat of cyber-attack is real and will continue to be an issue plaguing ICS for the foreseeable future.  Following the steps outlined in this paper will enable operators to create a security plan.  The key is to stop waiting, it is critical to analyze your system and create a security plan.

The post I Want to Secure My Industrial Control System – What’s the First Step appeared first on Schneider Electric Blog.

Visit Toronto Wiring
from Schneider Electric Blog


Visit Toronto Wiring

Comments

Popular posts from this blog

Living on the (IT) Edge: Schneider Electric at HPE Discover 2018

EFF: How to Identify Visible (and Invisible) Surveillance at Protests

EFF: The False Teeth of Chrome’s Ad Filter