New Security Certification Launched for Industrial Controls

Error message

  • Notice: Undefined index: browser in om_preprocess_html() (line 213 of /var/www/sites/automationworld.com/sites/all/themes/om/core/template.php).
  • Notice: Undefined index: browser in om_preprocess_html() (line 214 of /var/www/sites/automationworld.com/sites/all/themes/om/core/template.php).
  • Notice: Undefined index: version in om_preprocess_html() (line 214 of /var/www/sites/automationworld.com/sites/all/themes/om/core/template.php).

New Security Certification Launched for Industrial Controls

Print
Honeywell’s C300 is the first to achieve the new MUSIC certification, mounting a challenge to Wurldtech’s Achilles.
Until recently, there was only one game in town when it came to security certification for industrial controllers—the Achilles certification provided by Wurldtech Labs, an independent division of Wurldtech Security Technologies, in Vancouver, British Columbia, Canada.  

But that changed on Aug. 13 with the announcement of the Mu Security Industrial Control Certification (MUSIC) program, from Mu Security, a two-year-old Sunnyvale, Calif.-based company. Mu also announced that the Experion Process Knowledge System (PKS) C300 Process Controller, from Honeywell Process Solutions, Phoenix, is the first to achieve MUSIC certification. Honeywell followed up with its own press release on the C300 MUSIC certification the next day.
 

The announcements by Mu and Honeywell may set the stage for a new phase in the drive toward more secure critical infrastructure control systems, not to mention a marketing battle between competing certification providers.  

Wurldtech announced its first Achilles certifications last May. So far, a total of six control products from four vendors—Emerson Process Management, ICS Triplex, Invensys Process Systems, and Yokogawa Electric Corp.—have received Achilles Level 1 certification, which focuses on layers 2 to 4 of the network protocol stack. By contrast, the Honeywell C300 is so far the only MUSIC-certified controller; the C300 achieved Foundation level MUSIC certification, which covers the same network layers as Achilles Level 1. Both Wurldtech and Mu say they have additional controllers in the pipeline, however, and both say additional certification announcements will come this fall.
 

What’s different?  

Both the Achilles and MUSIC certification programs put controllers through a large number of tests designed to determine robustness and resistance to cyber attacks. But during an interview with Automation World, Adam Stein, Mu Security vice president of marketing, emphasized two points that he said make MUSIC different.  

One is the availability of Mu Security’s security appliance for use in on-site testing. The company’s Mu-4000 Security Analyzer appliance is not only being offered for use by vendors for certification testing, but is also being marketed to end-users. “Now you’ve got a way, if you’re a user, to be able to verify that the [certification] test claimed by a vendor has actually been done, and if you’re looking at equipment that is not certified, but a vendor is claiming it’s just as good, you’ve got a way to independently benchmark it,” Stein said.

Vendors can also do certification testing using the Mu-4000 as part of product quality development at their own sites, using their own personnel, as opposed to the traditional need to ship product for testing to a certification authority, Stein added. The Mu-4000 generates digitally signed test reports, which users can then submit to Mu Security or a Mu authorized partner who can provide certification, he said.  

The other point emphasized by Stein is that the MUSIC certification will provide an open transition to industrial cyber security standards currently under development, including the ISA-99 standard being developed by the SP99 committee of the Instrumentation, Systems and Automation Society. “Mu is tied into a lot of standards developments, like ISA SP99 and also the ISA Security Compliance Institute (ICSI), and I do not believe any other developments out there, including Wurldtech, is tied into the standards track,” Stein said.  

In fact, according to Kevin Staggs, engineering fellow and global security architect at Honeywell Process Solutions, that is a primary reason that Honeywell decided to go for MUSIC certification instead of Achilles. “Our interest is in having a certification to the evolving open standards, and we wanted to make sure that our investment lined up with that,” Staggs told Automation World.  

Counterpoint 

At Wurldtech, however, executives are quick to dispute any assertion that Achilles won’t provide mapping to the future ISA-99 standard. “We’ve been at every SP99 meeting, so we’re more than happy to be involved in the ISA process,” said Wurldtech Chief Executive Officer Tyler Williams.  

In addition, according to Nate Kube, Ph.D., Wurldtech chief technology officer, the company has been beta-testing at several customer sites an appliance called the Achilles Assurance Platform that can be used as a quality assurance tool for security testing by controls vendors. And on Aug. 24, Wurldtech announced a new version of the platform code named the Achilles Satellite, which Kube says is geared more for use by end-users.  

The Achilles Satellite will be introduced during the ISA Expo Oct. 2-4 in Houston, Wurldtech said. Both the current version of the Achilles Assurance Platform and the new Satellite version will be commercially available in ...

Pages

Comments(0)

Add new comment

By submitting this form, you accept the Mollom privacy policy.

Follow Us

 

Newsletters

Click on any newsletter to view a sample.

 News Insights 
News & Analysis (2x Month)   Product Insights
Latest Automation Products (2x month)  TalkPoints
Automation Columnists (1x month) Feed Forward
Latest from Gary Mintchell (1x month)  Automation Focus
Sponsored white papers, videos and products (1x month)
Process Automation
Industry Trends & Applications (1x month)  Motion Control 
Machine & Motion Control (6x year)  Automation Skills
Improve Industry Skills (1x month)   Industrial Ethernet Review
Network Application of IE (4x year)
Packaging Automation Review
Trends in Packaging Automation (4x year)  Safety Automation Insights
The How & Why of Safety (6x year)

 

OPConnect Newsletter
OPC Foundation Developments (4x year) PROFInews NA
PI News in North America (6x year)
Totally Integrated Automation
Applications and News from TIA (1x month)  Automation Catalyst
Igniting Ideas to Solve Automation Challenges
 Manufacturing Intelligence
Your Source for Operation Trends (3x year)

Once monthly. Don’t miss intelligence crucial to your job and business! Click on any newsletter to view a sample.

 

Feedback Form