Top Banner
Quality Assurance: The 80% of Industrial Control Systems (ICS) Cybersecurity -Rabbani Syed
37

Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Aug 11, 2015

Download

Technology

promediakw
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance: The 80% of Industrial Control Systems (ICS) Cybersecurity-Rabbani Syed

Page 2: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

About me Rabbani Syed 27 years of wide range of experience in Defense, Manufacturing, Energy, Oil & Gas industries

Systems Analyst, IT Quality Management, Information Technology, Kuwait National Petroleum Company.

Previous: Systems Engineer – Kuwait Controls Co.◦ SCADA, DCS & Telemetry Systems for Ministry of Electricity & Water (MEW) – Kuwait.

Senior Engineer, Bharat Electronics (BEL-India)◦ Design & Development of Real Time Computer Systems for Electronic Warfare Systems (Anti-

Radar and Electronic Counter Measure Systems)

M. Engg. in ECE – Osmania University, B. Tech in ECE – JNTU, India

Certifications: PMP, CISSP, CISA, CISM, CGEIT

Certificates: ISO27001LA, ISA99 Cybersecurity Fundamentals Specialist

Page 3: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance: The 80% of Industrial Control Systems (ICS) Cybersecurity

Overview: 1. The ICS Context

2. The Challenges

3. Technology, People, Processes

4. Quality Assurance: ◦ Processes & Frameworks

Page 4: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Changes in the ICS Architecture• ICS now use commercial technology

• Highly connected to internet

• Offer remote access

In past few years, there has been an increase in number ofCyberattacks on ICS

Page 5: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context ICS – Industrial Control Systems (SCADA, DCS, PLCs, Telemetry, Building Automation Systems etc.)

OT – Operational Technology

IT – Information Technology

Page 6: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context

Inversion of importance in Core Security Goals:

Confidentiality

Integrity

AvailabilityConfidentiality

Integrity

Availability

IT

OT

Page 7: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context, in Contrast with IT Context Differing Performance Requirements:

Page 8: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context Differing Reliability Requirements:

IT Network ICS Network

Scheduled Operations Continuous Operations

Occasional Failures tolerated Outages Intolerable

Beta testing in field acceptable Thorough QC testing expected in non-production environment

Modifications possible with little paperwork

Formal Certifications may be required after any change

Page 9: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context Differing Risk Management Approaches

Page 10: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context Differing Security Architectures:

IT World ICS World

Critical Systems to Protect: Servers, Storage etc.– reside in Computer Room

Critical Systems to Protect: PLC and Smart Instruments – reside in the field

Page 11: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Challenges: 1. Multi-vendor EPC Contracts

2. Increasing Management Expectations

3. Over 20+ ICS Cybersecurity Standards

4. SIL Certification does not evaluate Cybersecurity

5. Hackers – No Experience required

6. Unintentional Security Incidents

7. Expanding depth and breadth of ICS Security Tasks

Page 12: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Multi-vendor EPC Contracts

Page 13: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Management Expectations

Page 14: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: SIL Certification does not evaluate Cybersecurity• IEC 61508 Certification (SIL Certification)

does not evaluate Cybersecurity.

Page 15: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ChallengesOver 20+ Standards

1. ISA 99 / IEC 62443 Cybersecurity Standard for ICS

2. NIST SP800-82 : Guide to Industrial Control Systems Security

3. NERC – CIP 002 through CIP -009

4. Oil & Gas Sector: API Standard 1164 – SCADA Security

5. Water & Waste Water Sector Standards

6. Chemical Sector Standards

7. ……

Page 16: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Hackers – No Experience requiredNessus plugins and Metasploit modules have been publically released enabling anyone to find and exploit these vulnerabilities.

Page 17: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Hackers – No Experience requiredwww.rapid7.com, www. shodan.com; Free code to crash PLCs available on internet.

Page 18: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Hackers – No Experience required

Page 19: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Unintentional incidents80% of actual control system security incidents were unintentional (www.risidata.com)

Page 20: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Addressing ICS Cybersecurity:

1. Should controls be taken away from Smart Instruments?

2. Why can’t we build secure systems?

3. Is 100% Cybersecurity ever possible?

Page 21: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Addressing ICS Cybersecurity:

Learning from History

Page 22: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Addressing ICS Cybersecurity:

Technology, People and Processes 1. Technology

◦ The Cost-Benefit Analysis

2. People◦ Is Cybersecurity awareness & training enough?

3. Processes◦ Where is the end?

Page 23: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Addressing ICS Cybersecurity: Technology, People and Processes

TECHNOLOGY

•Hardening Servers, Workstations, Networks, DCS Systems, PLCs, Instruments…•Implement technical monitoring & controls

PEO

PLE

•Awareness•Training•Cybersecurity drills

PRO

CESSES

•Implement Processes•Monitor Performance•Review•Improve

Page 24: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Addressing ICS Cybersecurity: Technology, People and Processes

TECHNOLOGY

•The Cost-Benefit Analysis•Constraint:•COST

PEO

PLE

•The Human Factor •The End: •TRUST

PRO

CESSES

•Quality Assurance•Sky is the Limit

Page 25: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance

1. QA/QC – Definitions

2. The Processes

3. Standards & Frameworks◦ The ICS Standards & Frameworks

◦ ISA99◦ …..

◦ The IT Standards & Frameworks◦ TOGAF◦ COBIT◦ ITIL◦ ….

Page 26: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

ICS Standards & Frameworks ISA99 / IEC 62443

Relevant part to End-Users: ISA 62443-2 Series Policies & Procedures

Page 27: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

ICS Standards & FrameworksISA99 / IEC 62443 – Zones & Conduits

Page 28: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

IT Standards & Frameworks

1. ISO 27001

2. IT Governance - COBIT 5

2. IT Service Management - ITIL V3.1

3. Enterprise IT Architecture – TOGAF V9.1

Page 29: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ContrastIT & ICS Standards & Frameworks

1. Technology Focus ICS

2. Business Enablement IT

Page 30: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

TOGAF 9.1

1. Enterprise IT Architecture

2. Originated from TAFIM of early 1980s, developed by US Dept. of Defense

3. Provides an approach for designing, planning, implementing, and governing an enterprise Information Technology architecture.

Page 31: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

COBIT 5

1. Governance & Management Framework for Enterprise IT – End to End

2. Building on 16 Year History

3. Provides Structure, Practices, Tools for:◦ Proactively deliver value◦ Manage Risk◦ Maximize ROI

Page 32: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

ITIL V3.1

1. IT Service Management Framework

2. Originated in late 1980s by UK Govt’s CCTA

3. Focus on optimal service provisioning at justifiable cost

Page 33: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

NIST Cybersecurity Framework

Page 34: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

NIST Cybersecurity Framework

Page 35: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

NIST Cybersecurity Framework

Page 36: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

IT Frameworks : Enabling ICS Security

1. ICS Security - Purchase Specifications

2. ICS Security Portfolio Management

3. Business Justification

4. Compliance to Regulations

5. Business Risk Management

Page 37: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance: The 80% of ICS Cybersecurity

THANK YOU