mr. sayed rabbani - quality assurance - the 80% of industrial control system cyber security

30
Quality Assurance: The 80% of Industrial Control Systems Cybersecurity -Rabbani Syed

Upload: promediakw

Post on 11-Aug-2015

35 views

Category:

Technology


3 download

TRANSCRIPT

Page 1: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance: The 80% of Industrial Control Systems Cybersecurity-Rabbani Syed

Page 2: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance: The 80% of ICS Security

1. The ICS Context

2. The Challenges

3. Technology, People, Processes

4. Quality Assurance Processes & Frameworks

Page 3: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

About me Rabbani Syed Systems Analyst, IT Quality Management, Information Technology, KNPC

Previous: Systems Engineer – Kuwait Controls Co.◦ SCADA, DCS & Telemetry Systems for MEW

Senior Engineer, Bharat Electronics (BEL-India)◦ Design & Development of Real Time Computer Systems for Electronic Warfare

Systems (Anti-Radar and Electronic Counter Measure Systems)

M. Engg. in ECE – Osmania University, B. Tech in ECE – JNTU, India

Certifications: PMP, CISSP, CISA, CISM, CGEIT

Certificates: ISO27001LA, ISA99 Cybersecurity Fundamentals Specialist

Page 4: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context ICS – Industrial Control Systems (SCADA, DCS, PLCs, Telemetry, Building Automation Systems etc.)

OT – Operational Technology

IT – Information Technology

Page 5: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context

ConfidentialityIntegrityAvailability

ConfidentialityIntegrityAvailability

IT

OT

Page 6: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context Differing Performance Requirements:

Page 7: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context Differing Reliability Requirements:

Page 8: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ICS Context Differing Risk Management Approaches

Page 9: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenges: 1. Changes in the ICS Architecture

2. Multi-vendor EPC Contracts

3. Management Expectations

4. Over 20+ Standards

5. SIL Certification does not evaluate Cybersecurity

6. Hackers – No Experience required

7. Unintentional Security Incidents

8. The depth and breadth of ICS Security Tasks

Page 10: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Changes in the ICS Architecture• ICS now use commercial technology

• Highly connected to internet

• Offer remote access

Page 11: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Multi-vendor EPC Contracts

Page 12: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Management Expectations

Page 13: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: SIL Certification does not evaluate Cybersecurity• IEC 61508 Certification (SIL Certification)

does not evaluate security.

Page 14: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The ChallengesOver 20+ Standards

1. ISA 99 / IEC 62443 Cybersecurity Standard for ICS

2. NIST SP800-82 : Guide to Industrial Control Systems Security

3. NERC – CIP 002 through CIP -009

4. Oil & Gas Sector: API Standard 1164 – SCADA Security

5. Water & Waste Water Sector Standards

6. Chemical Sector Standards

7. ……

Page 15: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Hackers – No Experience requiredNessus plugins and Metasploit modules have been publically released enabling anyone to find and exploit these vulnerabilities.

Page 16: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Hackers – No Experience requiredwww.rapid7.com, www. shodan.com; Free code to crash PLCs available on internet.

Page 17: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Hackers – No Experience required

Page 18: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

The Challenge: Unintentional incidents80% of actual control system security incidents were unintentional (www.risidata.com)

Page 19: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

ISA99 / IEC 62443

Page 20: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

ISA99 / IEC 62443 – Zones & Conduits

Page 21: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Technology, People and Processes

1. Technology◦ The Cost-Benefit Analysis

2. People◦ Is security awareness enough?

3. Processes◦ The 80% of ICS Security

Page 22: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance

1. Quality Assurance

2. The Processes

3. Frameworks

Page 23: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

IT Frameworks

1. IT Governance - COBIT 5

2. IT Service Management - ITIL V3.1

3. Enterprise IT Architecture – TOGAF V9.1

Page 24: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

TOGAF 9.1

1. Enterprise IT Architecture

2. Originated from TAFIM of early 1980s, developed by US Dept. of Defense

3. Provides an approach for designing, planning, implementing, and governing an enterprise Information Technology architecture.

Page 25: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

COBIT 5

1. Governance & Management Framework for Enterprise IT – End to End

2. Building on 16 Year History

3. Provides Structure, Practices, Tools for:◦ Proactively deliver value◦ Manage Risk◦ Maximize ROI

Page 26: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

ITIL V3.1

1. IT Service Management Framework

2. Originated in late 1980s by UK Govt’s CCTA

3. Focus on optimal service provisioning at justifiable cost

Page 27: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

NIST Cybersecurity Framework

Page 28: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

NIST Cybersecurity Framework

Page 29: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

NIST Cybersecurity Framework

Page 30: Mr. Sayed Rabbani - Quality Assurance - The 80% of Industrial Control System Cyber security

Quality Assurance Processes & Frameworks: The 80% of ICS Cybersecurity

THANK YOU