Showing posts with label Cyber Security Evaluation Tool. Show all posts
Showing posts with label Cyber Security Evaluation Tool. Show all posts

Saturday, April 30, 2011

Chemical Sector Training and Resources Page Updated

The DHS Chemical Sector Specific Agency (Chemical SSA) updated their Chemical Sector Training and Resources web page on Friday. They added a new section that deals with information concerning the security of industrial control systems.

The new ‘Industrial Control Systems (ICS) Security’ section at the bottom of the page provides a link to a new document produced by the Chemical Sector Coordinating Council; “Securing Industrial Control Systems in the Chemical Sector: A Case for Action”. This document is part of an awareness campaign being conducted to make chemical manufacturing facilities aware of the ongoing implementation of the ten year ICS security program outlined in the Roadmap to Secure Control Systems in the Chemical Sector, a document available upon request to the Chemical SSA (ChemicalSector@DHS.gov).

The new section on this web page also briefly describes a DVD that is available from the Chemical SSA that provides additional resources available to help facilities to increase the security of their ICS. The web site indicates that the following information is included in the DVD:

• ICS Security Training Resource – A guide of available training designed for professionals who work in areas relevant to the process control and automation industries.

• Standards and Guidelines - A guide designed to facilitate research on existing standards in the area of control systems security.

• Incident Response and Reporting - A document that illustrates the importance of a chemical company reporting a cyber incident to ICS-CERT, and how this can positively impact the Chemical Sector.

• ICS Procurement Language - A document that provides example language to incorporate into procurement specifications.

• Cybersecurity Tabletop Exercise – This resource is scalable and includes all materials and templates needed to conduct a tabletop exercise with minimal planning.
The Case for Action document also notes that the DVD contains a copy of the Cyber Security Evaluation Tool that I have previously described in this blog.

It would seem to me that any cyber security officer responsible for industrial control system security ought to email the Chemical SSA and request a copy of this DVD, It would be an invaluable resource. That and downloading the Case for Action document are two simple steps that could lead to increased ICS security awareness.

Tuesday, February 8, 2011

DHS ICS-CERT Upgrades Access to CSET

Yesterday the DHS Industrial Control System Cyber Emergency Response Team web site upgraded the access for their Cyber Security Evaluation Tool. Readers might remember that I described this program in a blog post last fall. Well, yesterday, ICS-CERT made it possible to download a copy of the tool so that they could conduct the security evaluation of their ICS without the direct assistance of ICS-CERT.

One short warning; this is not a simple one-click download process, like getting a .PDF document. You will be downloading a piece of complex software in the .ISO format which requires saving to a CD or ‘mounting’ the program to your hard-drive. The instructions on the ‘Download’ page should be read carefully.

Unless you have a time-critical need to conduct the CSET, I would probably recommend taking the alternative course and request a copy of the CSET DVD from ICS-CERT. This is done by sending a relatively simple email to ICS-CERT (see the CSET web page for detailed instructions).

Facilities should probably only consider either of these two options if they have a high internal (or hired) level of control system expertise. If a facility has any doubts about the potential adequacy of their knowledge base, they should probably avail themselves of the free ICS-CERT on-site support for this tool. I think that it would provide a better outside look at the facility ICS security situation.

In any case, every CFATS covered facility with an industrial control system should absolutely take advantage of one of these CSET options to review their ICS security program. If I were a chemical facility security inspector (CFSI) the first cyber security question I would ask is to see the results of the CSET evaluation.

Thursday, October 14, 2010

Cyber Security Evaluation Tool

In yesterday’s blog about the 2010 Water Security Congress I noted that a presenter had mentioned an ICS security assessment program conducted by DHS ICS-CERT. Today I would like to take a brief look at this program offered by the Control Systems Security Program of DHS-CERT.

According to the available fact sheet the Cyber Security Evaluation Tool (CSET) is a computer based question and answer tool that “provides users with a systematic and repeatable approach for assessing the cyber security posture of their industrial control system networks”. The tool takes the facility supplied answers to questions about their control systems, facility IT systems and associated procedures and provides “a prioritized list of recommendations for improving the cybersecurity posture of an organization’s ICS or enterprise network”.

DHS provides facilities two different options for completing this voluntary program. Facilities can request a DVD copy of the program and conduct the evaluation on their own or they can conduct the evaluation using on-site ICS-CERT assistance. Organizations with a stronger computer support staff will probably want to use the DVD option.

The program helps facilities evaluate their cyber security program against a variety of established standards with the facility picking which standard best applies to their operation. Standards include:

• National Institute of Standards and Technology (NIST),
• North American Electric Reliability Corporation (NERC),
• International Organization for Standardization (ISO), and
• U.S. Department of Defense (DoD).
Will this help facilities with their CFATS cyber security requirements? Since there are no specifically delineated requirements for a cyber security system under CFATS, that is a hard question to answer. I think that a tool like this will help facilities identify current security issues and provide suggestions on how to deal with them. Having used this system to identify and correct system shortcomings certainly would provide a good basis for justifying a facility’s program to inspectors.
 
/* Use this with templates/template-twocol.html */