Five Steps to Achieve Defense-in-Depth

Feb. 3, 2014
Take these actions to establish and maintain industrial security capabilities.

Note: This is a sidebar to the January feature, "Practical Steps to Secure Industrial Networks."

Rockwell Automation’s Gregory Wilcox and Cisco Systems’ Paul Didier suggest these actions to get the operational process required to establish and maintain the security capability:

  1. Identify the automation and control-system asset device types and locations within the plant-wide/site-wide network infrastructure.
  2. Identify the potential and external vulnerabilities and threats to those assets—and assess the associated risks.
  3. Understand application and functional requirements of automation and control-system assets, such as 24/7 operations, communication patterns, topology, required resiliency and traffic types.
  4. Understand the associated risks of balancing the application needs and functional needs.
  5. Understand and balance the requirements of the assets with the need to protect the availability, integrity and confidentiality of automation and control-system asset data.

Sponsored Recommendations

From robotic arms to high-speed conveyors, accuracy matters. Discover how encoders transform motor control by turning motion into real-time data?delivering tighter speed control...
Safety in automation goes beyond fences and emergency stops. Learn how functional safety actively monitors and controls motion?delivering smarter protection, greater flexibility...
Inductive Automation offers multiple editions of Ignition created for specific use cases. See what differentiates Ignition, Ignition Edge, Ignition Cloud Edition, and Ignition...
Castle & Key brought new life to a historic Kentucky distillery by blending 140 years of heritage with cutting-edge automation. With help from Gray AES, they replaced outdated...