ICS Cyber Security: Where to Start

March 31, 2012
If you’re working at or operating a facility where little has been done to implement an effective cyber security plan for the industrial control system (ICS), it’s definitely time to start putting serious thought into the issue. You may wonder why this is so if you’re a company with a low risk of cyber security problems. The answer lies in the supply chain.

As sharing of information between supply chain partners increases and company systems continue to be connected via the Internet, the larger companies you supply—who will likely be very concerned about security—are not likely to share your lack of concern over your potential security issues. Bottom line: a lack of cyber security preparedness can be detrimental to your business beyond the practical reality of an incident ever occurring at your facility.

With that in mind, where should you start?

Joel Langill of SCADAHacker.com suggests starting at the Department of Homeland Security’s ICS-CERT Web site (www.ics-cert.org), and downloading their Cyber Security Evaluation Tool for control systems. “This free download helps you to conduct a non-invasive assessment of your current security posture, and offers some valuable insight into addressing some of the high risk areas,” he says.

Langill also encourages newcomers to spend some time getting to know other areas of the ICS-CERT site, including their section on Information Products. “This area provides valuable best practices for a wide range of security topics, including understanding common ICS vulnerabilities, and cyber security procurement language for ICS,” he says.Langill’s own site, SCADAhacker.com, also contains an extensive reference library of ICS-related security information.

Finally, Langill suggests initiating an awareness and training program within your organization. “The DHS offers some very good training programs for ICS cyber security. The first step to addressing cyber security issues is to become aware of just how serious this is and, from there, how to specifically secure the automation assets within a particular manufacturing facility.”

Ken Modeste, global principal engineer at Underwriters Laboratory (www.ul.com), concurs with Langill’s idea of awareness and training. “A review of the security policies in place today at your facility is a good starting point for investigating cyber security in control systems,” Modeste says. “A gap analysis examining your current security policy and actual implementation should also be performed. The first step in this process should always be to identify the current state of the system. If one doesn’t exist, then your first priority should be to create one for the current system.”

About the Author

David Greenfield, editor in chief | Editor in Chief

David Greenfield joined Automation World in June 2011. Bringing a wealth of industry knowledge and media experience to his position, David’s contributions can be found in AW’s print and online editions and custom projects. Earlier in his career, David was Editorial Director of Design News at UBM Electronics, and prior to joining UBM, he was Editorial Director of Control Engineering at Reed Business Information, where he also worked on Manufacturing Business Technology as Publisher. 

Sponsored Recommendations

Why Go Beyond Traditional HMI/SCADA

Traditional HMI/SCADAs are being reinvented with today's growing dependence on mobile technology. Discover how AVEVA is implementing this software into your everyday devices to...

4 Reasons to move to a subscription model for your HMI/SCADA

Software-as-a-service (SaaS) gives you the technical and financial ability to respond to the changing market and provides efficient control across your entire enterprise—not just...

Is your HMI stuck in the stone age?

What happens when you adopt modern HMI solutions? Learn more about the future of operations control with these six modern HMI must-haves to help you turbocharge operator efficiency...

AVEVA™ System Platform: Smarter, Faster Operations for Enhanced Industrial Performance

AVEVA System Platform (formerly Wonderware) delivers a responsive, modern operations visualization framework designed to enhance performance across all devices with context-aware...