Showing posts with label NCCoE. Show all posts
Showing posts with label NCCoE. Show all posts

Sunday, September 26, 2021

Review - Cybersecurity for the Manufacturing Sector – SP 1800-10 (draft)

Earlier this week the National Institute of Standards and Technology (NIST) published a draft of SP 1800-10, Protecting Information and System Integrity in Industrial Control System Environments. The new document provides a practical example solution to help manufacturers protect their Industrial Control Systems (ICS) from data integrity attacks. NIST is soliciting comments on this new document.

NIST is soliciting comments on the Draft of SP 1800-10. Comments should be submitted via email (manufacturing_nccoe@nist.gov) or by filling out the web form. Comments should be submitted by November 7th, 2021.

Commentary

This document provides an important look at how cybersecurity can be successfully engineered into an industrial control system. How useful that example will be for actual manufacturing systems remains to be seen. Looking at this document, it would appear that a high-level of IT knowledge will be required to implement the solutions reported in the document. Whether that level of support is readily available in small manufacturing of chemical facilities remains to be seen.

What is not clear from this document is how much work is needed to implement these tools. A description of the time needed to set up the equipment for these relatively simple control systems would be helpful, but I am not sure how well that would scale to real world control systems with hundreds of control devices and sensors. It is also not clear how much response action would be required by facilities to address the error messages and log files generated by such a system. Is a security operation center necessary or will facilities have to rely on already overstressed operators to deal with these results?

For understandable reasons, these test beds to not address process safety issues that must be taken into account when assessing security risks at a facility; even the Tennessee Eastman simulation fails to address this represents a generic chemical process without considering chemical hazards. I do wish, however, that there had been some discussion about the role process safety has in any process control system risk evaluation.

One final comment. I was really pleased to see that all of the test evaluations showed that the tested systems prevented the design criteria attacks. It shows that cybersecurity controls in a control system environment are possible. I would be surprised, however, to hear that they all did so on the first attempt. It would be helpful if initial testing-failure descriptions and a discussion of remedial actions taken were presented. It would also be helpful if NCCOE were to report on a well-funded red-team attack on the platforms tested.

For more details on the document and the systems evaluated, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/cybersecurity-for-the-manufacturing  - subscription required.

Thursday, March 26, 2020

NIST Publishes NCCoE Notice on Validating the Integrity of Computing Devices


Today the National Institute of Standards and Technology published a notice in the Federal Register (85 FR 17043-17045) on “National Cybersecurity Center of Excellence (NCCoE) Validating the Integrity of Computing Devices Building Block”. NIST is inviting organizations to provide products and technical expertise to support and demonstrate security platforms for the Validating the Integrity of Computing Devices project.

According to the Notice: “The objective of this project is to produce example implementations to demonstrate how organizations can verify that the internal components of their purchased computing devices are genuine and have not been altered during the manufacturing and distribution process.” The components that NCCoE intends to look at in this block include:

• Computing devices, including laptops, servers, and mobile devices
• Configuration management software
○ vulnerability scanning
○ detection
○ patch management
○ version control
○ synchronization
○ firmware
• Asset inventory software
○ asset management
○ asset discovery
• Security information and event management (SIEM)
○ event detection
○ log management
○ exfiltration activity
○ unauthorized activity
○ anomalous activity
• Certificate authority

Organizations wishing to participate will have to submit a letter of intent describing how their products address one or more of the following desired solution characteristics:

• Use verifiable and authentic artifacts that manufacturers produce during the manufacturing and integration process.
• Detect malicious component swaps of the computing device.
• Manage the automation process when accepting the delivery of a computing device and throughout the operational lifecycle of the device.
• Inspect computing devices to verify that the components in a delivered (or in-use) system computing device match the attributes and measurements declared by the manufacturer.

A copy of a letter of intent template may contact Nakia Grayson via email to supplychain-nccoe@nist.gov.

Commentary


While this is primarily an IT related project at this point, it seems clear to me that control system components potentially have the same vulnerability to post design/manufacture modification that could compromise the security of the system in which the compromised component resides. This will be an interesting project to participate in and/or watch.

Tuesday, March 18, 2014

NIST-NCCoE Publish Identity Management Notice

The National Institute of Standards and Technology (NIST) published a notice in today’s Federal Register (79 FR 15100-15102) seeking organizations that are interested in working with the National Cybersecurity Center of Excellence (NCCoE) to address issues related to the physical and logical control of access to  power generation, transmission and distribution facilities and equipment including industrial control systems.

Identity and Access Management

The NCCoE is looking for organizations that might be able to address capabilities or that have products that address:

• Services for authenticating and authorizing users based on identity, role, third-party affiliation (e.g., federation) or other attributes (e.g., attribute-based access control);
• Services for authenticating and authorizing devices;
• Services for whitelisting applications;
• Identity and access governance capability that translates human-readable access needs into machine-readable authorizations;
• Security incident and event management (SIEM) or log analysis software for monitoring access management events;
• ICS equipment, such as Remote Terminal Units (RTUs), programmable logic controllers (PLC), and relays, along with associated software and communications equipment (e.g., radios, encryptors);
• Physical access control devices that use standard communication interfaces; or
• “Bump-in-the-wire” devices for augmenting Operational Technology (OT) with authentication, authorization, access control, encrypted communication and logging capabilities.

Products or processes must meet the following capability requirements:

• Compatibility with various electric utility ICS equipment and software
• Strong authentication of users, devices, and software, based on credentials or attributes, along with appropriate encryption to enable reasonably secure exchange of identity and access management informationShow citation box
• Compatibility with protocols and communication media commonly used by electric utilities
• Federated authorization for communication across security domains
• Ease of use (e.g., installation, configuration, maintenance, provisioning, de-provisioning, credentialing, revoking credentials)

More details can be found here.

Participation


Organizations wishing to participate in this NCCoE project must contact NIST to request a letter of interest. Completed letters of interest will be submitted to NIST no later than April 17, 2014. NCCoE will select participants who have submitted complete letters of interest on a first come, first served basis within each category of product components or capabilities up to the number of participants in each category necessary to carry out this use case.
 
/* Use this with templates/template-twocol.html */