Showing posts with label ICS. Show all posts
Showing posts with label ICS. Show all posts

Tuesday, April 25, 2017

Monday, April 17, 2017

Definitions matter

There is a need to revise CIP language to clarify “programmable” due to differences between the current NERC CIP definition of Cyber Asset, the language in Section 215 of the Energy Policy Act of 2005 that discusses Cyber Assets as Electronic Programmable Devices, and commonly understood security standards and definitions of computers or cyber devices.

There is a perception that the particular wording of “Cyber Asset” is a deliberate, well-thought-out, and legally binding definition. However, there are multiple inconsistencies between NERC CIP Standards, the Energy Policy Act, and FERC Orders which have not been legally challenged and have not prevented progress from being made to security standards. This being so, there is no practical benefit in objecting to modifications based on a presumption of precision in the original wording.

These varying definitions have caused some confusion in categorizing Cyber Assets as in-scope. There may be gains to be achieved by modifying the definition to be more consistent both internally and with cross-sector IT security practices that are more technically in line with the way devices are designed by vendors and intended to be operated. When the parsing of the grammar becomes too circular, the utility of the definition is lost. The main goal of NERC CIP standards MUST be usefulness of the standard.

Some commenters have made the point that NIST does not use the term “Cyber Asset” and recommend using the term “computer”. However “computer” also has connotations of server/workstation to many people and is not inclusive of other information processing devices such as network and security appliances, cyber-physical industrial control system devices, etc. “Cyber Asset” is a workable, comprehensible and inclusive term that provides benefit to the security discussion and therefore should be retained.

Cyber Assets are platforms which can accept variable sets of encoded instructions known as operating systems and software programs. They use these instructions to manipulate data inputs to create outputs in the form of processed data or in the case of Cyber-Physical devices, control signals. This programming is stored in either volatile or non-volatile memory, and may reside in the device or on other devices in the overall Cyber System that provides storage services to the device.

Conversely, dedicated devices which perform a function defined purely by the physical configuration of the device (dip switches, jumper connectors, or EEPROM) and not in a changeable, encoded set of logic-based instructions are not generally considered to be Cyber Assets, but rather microprocessors. The modification of that dedicated function (control plane logic) is not programmable via a human or network-accessible communications interface (management plane) that can be interacted with logically by other Cyber Assets. Re-programming requires physical modifications to the micro-processor device, often by a vendor technician at a factory using tools that change the physical or electrical properties of the device. These devices are not in any practical way “programmable” by the user and the risk of them being re-programmed maliciously or covertly are mitigated by physical access controls.


Additionally, devices which have a stored firmware not accessible unless installed in another device (such as but not limited to internal/external hard drives, flash drives, Ethernet or Wireless NICs cards or USB, Security dongles, serial adapters, etc.) are not Cyber Assets in themselves because they are not capable of being re-programmed or executing code without being installed (permanently or temporarily) in a Cyber Asset. These types of devices are peripheral components of a Cyber Asset or removable media. While these devices may pose a risk of carrying mal-ware, the means of mitigating that risk is separately covered by removable media controls and supply chain requirements.

Thursday, March 30, 2017

Free Training Opportunity

U.S. Department of Homeland Security Seal. ICS-CERT. Industrial Control Systems Cyber Emergency Response Team.



ICS-CERT maintains a training portal with a mix of online CBTs and announcements for instructor-led training with locations and dates. The Virtual Learning Portal is easy to navigate and has some interesting content. Particularly useful for maintaining those career certifications through continuing education.

Tuesday, March 28, 2017



ICSJWG 2017 Spring Meeting 

 Minneapolis, MN   April 11 - 13, 2017
Loews Minneapolis Hotel
MEETING OVERVIEW
The 2017 Spring ICSJWG Meeting in Minneapolis, Minnesota will provide a forum for all control systems stakeholders to gather and exchange ideas about critical issues in ICS cybersecurity. This meeting will foster an opportunity for stakeholders to interface with peers, network with industry leaders, and stay abreast of the latest initiatives impacting security for industrial control systems and our critical infrastructure. The Spring Meeting will include three full days of interactions and discussions in the form of keynote speakers, practical demonstrations, presentations, and panels. The Vendor Expo will return, as will the popular "Ask Me Anything" session by ICS-CERT leadership. 
Meeting Registration Information
To register for the 2017 Spring Meeting, please use the following registration link. Note that this registration is for the meeting, not for accommodations.
Please register no later than April 6, 2017.

Venue and Accommodation Information

Loews Minneapolis Hotel
601 1st Avenue North
Minneapolis, Minnesota 55403
For room block reservations, call 1-877-878-5670 or use the following Room Block Link(link is external). If you call, please refer to the ICSJWG 2017 Spring Meeting when making a reservation. The room block ends March 15, 2017.

Draft Agenda

We thank all who provided abstracts for presentations, demonstrations, lightning rounds, panels, and vendor booths!  Based on the mix of topics, we anticipate a great meeting. Please find the draft agenda here.
Additionally, the draft abstract-agenda has been developed to provide insight into the subject matter which will be discussed during the meeting. Please find the draft abstract-agenda here.
Additional Information
The Vendor Expo has been filled and no additional booth spaces are available.