Showing posts with label ICSJWG. Show all posts
Showing posts with label ICSJWG. Show all posts

Saturday, June 9, 2012

ICS-CERT Publishes May Monthly Monitor


Yesterday the folks at ICS-CERT published the latest issue of their Monthly Monitor, a newsletter about all things concerning control systems security. Always an interesting read, this issue:

• Describes a thumb-drive incident;

• Explains complexities of international disclosure coordination;

• Discusses the ‘end of life’ for XP; and

• Recaps the ICSJWG Spring Conference.

As usual it includes their standard features:

• Recent ICS-CERT Product Releases;

• Open Source Situational Awareness;

• Up Coming Events; and

• Coordinated Vulnerability Disclosure.

There is one new feature that I would like to see in this newsletter. We all know that there is sensitive and/or classified cybersecurity information that ICS-CERT and US-CERT share with vetted individuals and organizations via their ‘Secure Portal’. It would be interesting to see an unclassified summary of that information included in the Monthly Monitor. I think this would encourage more organizations to try to get cleared for access to that information and it would give the rest of us unwashed individuals a better understanding of the state of the cybersecurity threat.

Thursday, July 28, 2011

ICS Security Posture

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published an interesting announcement on their web page concerning an upcoming project being coordinated by the Industrial Control Systems Joint Working Group (ICSJWG). According to this announcement this project will be a ‘focused effort’ to produce a ‘cross-vendor position paper’ that “discusses the current security challenges and a path forward for a more effective industrywide approach to ICS security".

With more and more security vulnerabilities being identified in industrial control system software, it is becoming clear to anyone that is watching that there are significant shortcomings in the industry’s security posture. It is only a matter of time before someone (a terrorist, a disgruntled ex-employee, a criminal organization, or even a foreign power) takes advantage of one or more of these vulnerabilities to attack an industrial control system in the United States with ‘catastrophic consequences’ (I’m sorry; it is just too nice a phrase. I’ll try to come up with another in the near future).

It is also clear that there is no magic bullet that is going to cure the problem overnight. The responsibility for the current situation is the product of too many variables to enumerate and everyone in the business, vendors and users alike, share a fair measure of the blame for getting here.

It is also clear that the politicians have no clue about the extent of the problem and are focused on the (admittedly) larger cyber security issues of the protection of privacy, financial transactions, and intellectual property.

So, the idea of various members of the community getting together to take an organized look at the problem and come up with suggestions for its resolution is a good one. The ICSJWG is probably as good a venue for this as any. It already has a very open structure in place that can accommodate an evolving level of participation. And most of the major players already have links established to this group.

I’m not sure how detailed a proposal can come out of this group (or any group attempting this type of dialogue) because of rules concerning business competition, collusion and market manipulation. But anything that gets a positive dialogue started will be of benefit to the control system community and the country as a whole.

One warning however, the ‘Green’ community has already targeted the Critical Infrastructure Partnership Advisory Council (CIPAC; the actual parent organization for ICSJWG) as an industry lobbying organization with undue influence on DHS. While this is an exaggerated accusation (in my opinion) it is a very real problem that must be dealt with. Unless ICSJWG takes pains to ensure that this discussion is open and inclusive, the political response to the final product will be colored by these types of accusations.

The ICS-CERT announcement invites interested parties to contact them at ics-cert@dhs.gov. They stress that this includes all “ICS vendors, standards bodies, and ICS partners”. With ‘ICS partners’ obviously including owner and operators, I would like to encourage the participation of organizations like SOCMA, ACC and NPRA (to name just a few) that represent many of those owners and operators. And let’s not forget the security researcher (black, white and gray hat) community; they should be participating as well.

Saturday, February 5, 2011

DHS Control System Security Program Page Update

The DHS Control System Security Program web page was updated yesterday to include links to news about the upcoming Industrial Control System Joint Working Group (ICSJWG) 2011 Spring Meeting in Dallas, Tx and a new ICS-CERT recommended practices document.

ICSJWG Spring Meeting

The 2011 Spring Meeting will be held on May 2nd thru 5th at the Dallas/Addison Marriott Quorum hotel. According to the meeting web page

“The ICSJWG Conference will consist of panel discussions, presentations, training, and working group meetings on various topics such as emerging technologies, standards development, threat and incident reporting, analysis tools and techniques, roadmap development initiatives, workforce development and certification, vulnerability management, research and development, information sharing, and international coordination.”
The page also includes a Call for Papers for this meeting. It provides a non-exclusive list of potential topics, a link to an electronic submission form for sending an abstract for a proposed presentation and a submission deadline of February 18th.

The last day of the Spring Meeting will be the typical ICSJWG all-day training course. For this meeting it will be the Intermediate Industrial Control Systems Cybersecurity training. Prior control system security experience or attendance at the basic-level course is the recommended prerequisite for this class. The training will include:

• The importance of protecting control systems from cyber attacks and why they are susceptible

• Understanding the risks and potential consequences of attacks

• Understanding common vulnerabilities in industrial control systems

• Discussion of system exposures to attacks, various attack scenarios, and associate mitigation strategies

• Control Systems Security Program products and services that are available to asset owners.
Both the Spring Meeting and the all-day training are free. Well, that’s not completely true; no charge for attending, but you do have to pay for travel and accommodations. As I expect that most travel budgets remain tight (I know mine is) I will make my standard recommendation that the organizers of this conference consider providing on-line access to at least some of the presentations. It would certainly expand the potential audience for this valuable information.

Remote Access for ICS

The DHS Control System Security Program and the Center for the Protection of Critical Infrastructure have produced a new best practices document; Configuring and Managing Remote Access for Industrial Control Systems. In a modern industrial setting there are many legitimate reasons to provide remote access to control systems this lengthy and dense document provide a detailed look at how that access can be provided in a secure manner.

This is not a how-to manual, but more of a policy discussion. As is typical for many policy discussion documents this means that the writing can get fairly intense. For example, here is the opening paragraph in the discussion of on ‘password policy’:

“In an ideal deployment, authentication mechanisms should be chosen based on the criticality of the system being accessed and should include not only passwords, but other mechanisms as well (see the section on ‘Two form factor authentication’). When using passwords, a secure remote access system should enforce complex passwords of 8 to 25 characters that are a mixture of upper and lower case letters, numbers and symbols.k In addition, corporate policy should demand that these passwords be changed at a rate that is commensurate with the value of the system being protected and regular audits of the strength of these passwords should be done as part of the organisational [sic] cyber security program. The corporate cyber security policy should dictate that these passwords are never shared and that each user ID is unique across the entire system.”
This seems fairly straightforward until you get down to the footnote referred to in the middle of the paragraph. That footnote (k) reminds the reader that:

“This guideline is a recommended best practice for general ICT security and the authors recognise [sic] that the creation and use of a 25-character complex password (although ideal) for day-to-day human machine interface operations may be inappropriate. The recollection and usage of such a password under duress may create circumstances that are unacceptable from a safety perspective.”
I think that this is a valuable manual to have and review, but I do have on major complaint about the mechanics of the document. There are a large number of high-density graphics included that make navigation through the 66-page document difficult and time consuming if you are using an older system. I had page load times of almost two minutes using my old Windows 2000 based lap top.

Tuesday, May 25, 2010

ICSJWG Page Update 05-24-10

Yesterday, while making one of my periodic checks of the Industrial Control System Joint Working Group web page I noticed that they had updated information available about their fall meeting. Their Fall Conference will be held on October 25-28, 2010 in Seattle, Washington. They have general agenda and Call for Papers information available. On the last day of the Conference there will be an 8-hour Introduction to Industrial Control Systems Cybersecurity training session. Proposals for papers and panels need to be submitted by July 28th via an electronic form that is not yet available. The program committee is looking for presentations in the following topics of interest:
Workforce Development Control Systems Security Research International Coordination Standards Development Incident Response and Handling Vulnerability Management Emerging Technologies Managing Vendor Relations Law Enforcement and Forensics for ICS Integration of Cryptographic Technologies Security Management Metrics Information Sharing Wireless Integration in ICS environments Lessons learned Securing network perimeters Malware and Vulnerabilities Effective Cybersecurity Programs Coordination of Threat Reporting and Determining Attribution
I don’t see a single topic listed here that wouldn’t be a valuable subject for discussion, but I would have liked to see at least one topic that directly addressed government cyber security standards (CIP, CFATS, etc). In fact, it would probably be worth while to have a representative of the various enforcement agencies provide updated information on their programs.

Friday, May 14, 2010

ICSJWG Teleconferences

Today the DHS-CERT Control System Security Program Calendar web page shows a series of teleconferences to be held by various elements of the Industrial Control System Joint Working Group (ICSJWG) over the next two weeks. No real details are available, though I expect that the individuals involved probably understand what is going on. I suspect that it has something to do with the recently announced dates for the 2010 ICSJWG Fall Conference, October 25-28, 2010. The following teleconferences have been announced

ICSJWG Government Coordinating Council Teleconference – 5-20-10

ICSJWG Research and Development Subgroup Teleconference – 5-20-10

ICSJWG Vendor Subgroup Teleconference – 5-24-10

ICSJWG Workforce Development Subgroup Teleconference – 5-25-10

ICSJWG Industrial Control System Roadmap Subgroup Teleconference – 5-27-10

The web site provides an email POC, ICSJWG@dhs.gov, for further information about these teleconferences.

Tuesday, March 2, 2010

ICSJWG Spring Agenda

The DHS CERT’s Industrial Control System Joint Working Group’s (ICSJWG) web page about their spring meeting now provides a link to a draft agenda for that meeting. Since it is prominently labeled draft, I would assume that there are still changes being planned, but it still looks like this meeting will provide a great deal of interesting information. It looks like there will be presentations from just about everybody of consequence in the ICS Cyber Security Community. The topics range from analysis of actual cyber security incidents, to defeating malicious code, to managing patch management. While there is not time to cover every possible topic, it looks like the organizers have done a good job at trying to accomplish just that.

The one topic that is missing that I am disappointed in is that there is no presentation on the implementation of the cyber security requirements for the chemical facility anti-terrorism standards (CFATS). As this program is just now hitting the actual enforcement stage of its implementation, I would have thought that some practical coverage of this program would be important for this group. Maybe it will show up in a later version of the agenda.

Wednesday, January 6, 2010

ICSJWG January 2010 Newsletter

Thanks to the SCADASEC list at Infracritical.com for a link to the latest newsletter from the Industrial Control System Joint Working Group (part of the DHS-CERT Control System Security Program). Anyone working with industrial control systems (especially those in use at high-risk chemical facilities) should follow the workings of this group and reading their monthly newsletter is a good way to start. It is interesting though that we have to get this from Infracritical.com instead of DHS-CERT CSSP. If you go to their ICSJWG web site the latest issue of the ICSJWG Newsletter available there is September 2009. Something is wrong there.

Wednesday, December 23, 2009

CSSP Web Page Update 12-23-09

The DHS-CERT Control Systems Security Program (CSSP) web page has been updated. There is now a link to the Industrial Control Systems Joint Working Group’s (ICSJWG) announcement of their spring meeting in Austin, TX, as well as a link to a new publication about the use of encryption to protect industrial control systems. ICSJWG Spring Meeting The ICSJWG is a part of Critical Infrastructure Partnership Advisory Council (CIPAC). According to the meeting announcement web page the “goal of the ICSJWG is to continue and enhance the collaborative efforts of the industrial control systems stakeholder community in securing CIKR by accelerating the design, development, and deployment of secure industrial control systems.” The spring meeting will be held over April 6th thru 8th in Austin, TX. The conference will include presentations by industry leaders in control systems cybersecurity, updates from the ICSJWG Subgroups, and the Introduction to Industrial Control Systems Cybersecurity training course. Further details, including a call for papers, will be forthcoming. ICS Encryption The CSSP has introduced a new publication, the Control Systems Communications Encryption Primer. According to the Abstract the “primer addresses the use of encryption systems within control systems environments”. It addresses the problems of applying encryption techniques to industrial control systems, acknowledging that these techniques “can introduce significant design challenges as they add complexities and operational limitations to the environment”. There will be more on this Primer in a future blog.

Monday, August 10, 2009

Control System Security Conference November 2009

The Industrial Control Systems Joint Working Group (ICSJWG) will be holding their 2009 Fall Conference this November in Idaho Falls, ID. This will be a networking and educational event for control systems stakeholders from industry, government, academia, international, vendor, and research and development communities. There is no charge for attending the conference. According to the Secure.INL.gov web site:
“The ICSJWG Conference will consist of panel discussions, presentations, training, and working group meetings on various topics such as emerging technologies, standards development, threat and incident reporting, analysis tools and techniques, roadmap development initiatives, workforce development and certification, vulnerability management, research and development, information sharing, and international coordination.”
The Program Committee is still accepting proposal abstracts for presentations or panels. Proposals must be submitted via the electronic form prior to August 17, 2009. According to the Call for Papers: “Marketing or sales presentations aimed at gaining the audience’s interest in services, capabilities, or products will NOT be approved.” Topics will include:
Workforce Development Control Systems Security Research International Coordination Standards Development Incident Handling Vulnerability Management Emerging Technologies Managing Vendor Relations Integration of Cryptographic Technologies Security Management Metrics Wireless Integration in ICS environments Coordination of Threat Reporting
This is being billed as an opportunity for government professionals, control systems vendors and systems integrators, research and development and academic professionals, and owners and operators to interface with cyber security peers and stay abreast with the latest initiatives impacting security for industrial control systems.
 
/* Use this with templates/template-twocol.html */