•“How to better understand the convergence between Industrial Control Systems (ICS) and general IT systems •“Insight into educational needs and certifications •“How to conduct Risk and Vulnerability Assessments •“Descriptions and observations from malicious and unintentional ICS cyber incidents •“Recommendations for securing ICS”The book will be available in both soft-cover and electronic versions. Advance orders are being accepted.
Showing posts with label Joe Weiss. Show all posts
Showing posts with label Joe Weiss. Show all posts
Tuesday, February 9, 2010
ICS Security Book
This last weekend Joe Weiss, a vocal expert on industrial control system (ICS) security issues, announced that his new book on ICS security has an announced publication date of April 10th, 2010.
According to the publisher’s web site the book, Protecting Industrial Control Systems from Electronic Threats, will be aimed “at both the novice and expert in IT security and industrial control systems (ICS), this book will help readers gain a better understanding of protecting ICSs from electronic threats[emphasis added]”. I think that it is interesting that both Joe and his publisher are avoiding the claim that this is directed at terrorist threats. Joe has long been vocal in noting that both deliberate and accidental electronic threats exist against which ICS systems must be protected.
The publisher, Momentum Press, also notes that the book addresses:
Thursday, August 20, 2009
Reader Comment 08-18-09 More on ‘Dr. Joe’
Sometimes I am surprised at what ‘issues’ get the most reader response. Tuesday night John left a post about the ‘Dr Joe’ issue. John wrote:
“If you made an error in referring to Joe Weiss as Dr. Weiss you are in good company. His name plaque read, "Dr. Weiss" when he testified before the Senate Commerce, Science and Transportation Committee. Here's the photo to prove it... http://www.controlglobal.com/multimedia/2009/WeissTestifies0903.html”Looking back at my records I did not get a chance to watch Joe’s testimony before the Senate Committee so I did not get my information there. In fact, I cannot find any where in my records that includes any reference to ‘Dr. Weiss’. So when I referred to ‘Dr. Weiss’ in my posting last week, it was entirely an assumption on my part that Joe had received an PhD at some point in his illustrious career. Now, I am not a person that is overly impressed with a ‘piled higher and deeper’ certificate from an institution of higher learning. In too many instances as a practical matter it is not much more than a ‘you were there’ badge. But there are many people that do worship at that church and they get highly offended when the honorifics are not used or used inappropriately. I am reminded of the Professor at the Frie Universitie in West Berlin with two PhDs who insisted that his students refer to him as ‘Herr Doktor Doktor’. In any case, I just want to make sure that everyone understands that the misuse of the honorific was entirely my fault and was not the result of a misrepresentation on the part of Joe Weiss or anyone associated with him. While my readers are free to continue posting comments on the subject, this will be my last word….
Friday, April 3, 2009
Cyber Security Standards
There is an interesting blog post by Joe Weiss over on ControlGlobal.com about what cyber security legislation should look like. Joe is one of the few people that well known for his interest and expertise in control system security and recently testified before the Senate Committee on Commerce, Science, and Transportation about control system security issues.
Joe recommends that regulatory scheme for control system security should include “NIST SP800-53 or a close derivative”. Unfortunately, I am not familiar with the details of this standard (though I suppose that will probably change in the near future). What I do know is that the first real attempt at a federally regulated security program for private industry where electronic control systems are widely used will not include this standard.
Risk-Based Performance Standards
DHS, as all of the readers of this blog are aware, is prohibited from requiring any ‘standard’ in their review of Site Security Plans. They can only used ‘risk-based performance standards’ to evaluate how well each high-risk chemical facility is doing at reducing or controlling the risk at their specific facility. The Risk-Based Performance Standards Guidance (Guidance) document that is soon (hopefully) to be published by DHS will only provide loosely worded suggestions for strategies that facilities might want to consider employing as part of their layered plan to protect their facility (I hope I got enough qualifiers in there).
To make matters worse the Draft Guidance that we had a chance to look at last fall did little to provide even loosely worded suggestions for control system security. In fact, the cyber security section of the draft seemed to imply that DHS was looking for standard IT security procedures to protect control systems. Many of those IT security techniques would, in effect, be attacks on control systems.
Perhaps the final version of the Guidance will better address the issue of control system security, but I doubt it. There was only one comment that addressed the control system security issues. While that comment from the ISA99 Committee on Industrial Systems Security was very detailed, most observers (myself included) do not expect significant changes to the Guidance document.
Require Cyber Security Standards
Joe’s blog posting yesterday expressed the opinion that there ought to be industry wide legislation. He said that: “there is a need for legislation to mandate its [NIST SP800-53] use in all critical infrastructure industries. This will not only provide the best existing standard, it is also the best chance for interoperability across all industries”. Joe may be getting his wish in S 773, a bill introduced in the Senate on Wednesday by Senator Rockefeller, Chairman of the Senate Committee on Commerce, Science, and Transportation. We won’t know for sure until the GPO publishes the text of the proposed bill, probably today.
The problem with any industry wide requirement is trying to figure out how it will be enforced. With the White House apparently becoming the head office for Cyber Security, it will be difficult to see how there could be effective enforcement. On the other hand, for high-risk chemical facilities there is already an enforcement mechanism in place, CFATS. Of course, this would require modifying the authorizing language to allow the Secretary to specify NIST SP800-53 compliance. Of course, that authorizing language is due for update this spring, so this is a good time to start talking cyber security requirements.
Subscribe to:
Posts (Atom)