Balancing Security, Compliance and Operational Management
Balancing Security, Compliance and Operational Management
--> The relationship between industrial operations and corporate IT is clearly growing in complexity.
--> Corporate managers and ICS professionals hold very different views about how automation environments will evolve in the future.
--> While many ICS professionals report that their official responsibilities have expanded to include managing security and compliance, their reported day-to-day activities do not reflect this change.
--> Similar management requirements exist across security, compliance and operational functions in the complex automation environments that exist within critical infrastructure.
--> Today, many infrastructure operators are constrained in their ability to effectively manage their overlapping security, compliance and operational requirements.
As industrial control systems become more complex, connectivity with the corporate environment will grow.
Shrinking air gaps: 71% percent of respondents expect either significant or moderate increases in connectivity between industrial endpoints and corporate IT infrastructure over the next 3-5 years.
Explosive growth in industrial endpoints: 23% percent or respondents expect a doubling – or more – of the numbers of industrial endpoints over the next 3-5 years.
It’s a difficult balancing act to manage and prioritize growing responsibilities in operations, security and compliance.
Responsibilities widening: Most respondents hold meaningful (“primary” or “significant”) responsibility for all three functions: security, compliance and operational management.
Time committed to each function: Responses indicate that balancing priorities is a struggle, for these individuals. Nearly three quarters of respondents said they spend less than 25% percent of their time per month dedicated to managing security. 81% spend less than 25% of their time on compliance/audit management; 45% spend less than one-quarter of time on operational management.
Commonalities exist across the activities required to support security, compliance and operational management. The survey evaluated the role of several key activities, including: monitoring critical system performance and health, identifying events and changes collecting and managing configuration data managing industrial asset data; tracking and validating changes; and managing incidents and problems.
Role in security, compliance and operational management: Respondents agree the activities listed above were key to managing security, compliance and operations. More than half believed all of these are “extremely” or “very important.”
Current constraints in managing security, compliance and operations: Although respondents cited these activities are important, many reported they currently have weak abilities to execute on these functions. Challenges are even more evident when respondents considered their ability to take these actions in a unified fashion across their overall ICS environment.
Survey Methodology
Industrial Defender’s survey was conducted online between November 3 and November 18, 2011. The survey polled 134 individuals employed by critical infrastructure operators with responsibility for managing security, compliance and/or operations within industrial automation environments.
To download a copy of the full report, go to www.industrialdefender.com/icsreport/ICSurveyReport.pdf











Comments(0)
Add new comment