Questions for Security Experts

Great discussion

Not questions, but my $.02 on the matter if I was sitting in front of the group.

I would emphasize that IT/OT are one team with different tools and approaches. Then focus on requirements and look at security vulnerabilities and countermeasures from a risk perspective. Discuss the "CIA triangle", Confidentiality, Integrity, and Availability, and that OT often favors Availability whereas IT security is more used to the C and I.

For example, your organization may have PLCs with local HMI stations for status and control. You may have a business network where users are allowed remote access. You might also have a remote access requirement for PLC/HMI programming, which is more strict than remote access to the business network. On the OT/process side, you might have equipment that would be extremely dangerous to run without a safety operator physically in front of it, but business users need regular aggregate production reports with data sourced from it. The point is - there are lots of requirements from many stakeholders - get them out in the open.

You could imagine different ways to meet these requirements. From a security perspective, you might separate or segment your networks. IT can help with that - even providing secure remote access. OT/PLC folks can tackle process safety such as hardware disconnects and such. As a team, you might get crazy and "air gap" (physically separate networks), only transferring historical data through a one way "data diode". It might be enough to segment or layer your networks, with minimal touch points - such as the SCADA server talking to both sides via controlled interfaces. The point here is to agree on the implementation. For example, OT might point out that the super-secure IT solution presents cases that risk locking out users from performing their duties during operations - perhaps a "break glass" backdoor is warranted. IT might point out that the old/current way that OT uses phone dialers or Internet connected PCs is too risky - that VPNs provide more secure access.

In summary - "one team, one fight", and work together to best meet all of the organizational requirements with the best tools for the job. It sounds stupid, but I've seen numerous cases where, for purely political reasons or disagreement, one side tries to do the others' job without their support, which tends to lead to an epic fail.
 

Similar Topics

Hello, I was wondering if anyone remembers how to use the security section of Panelbuilder32. I'm working with a 2711-B6C2L1, PV600. I can't...
Replies
6
Views
2,996
Good day and Happy Holidays! Everytime I restore an .APA or .MER file into project for editing, the accounts and their passwords are replaced...
Replies
1
Views
4,639
Hello everyone, I'm new here. First of all I just want to say that you guys are very knowledgeable and reading your posts on here has saved my...
Replies
4
Views
154
Hello All, Was hoping I could get a little help with Modicon ladder logic. This is the first time I have seen Modicon logic and currently trying...
Replies
6
Views
239
Hello, I am new to Codesys, and am trying to learn about it for a project we're developing. I've got a couple questions, but first a little...
Replies
1
Views
133
Back
Top Bottom