Warning: Unknown: Unable to allocate memory for pool. in Unknown on line 0

Warning: require_once() [function.require-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/index.php on line 12

Warning: session_start() [function.session-start]: Cannot send session cookie - headers already sent in /www/pro/htdocs/community/includes/bootstrap.inc on line 899

Warning: session_start() [function.session-start]: Cannot send session cache limiter - headers already sent in /www/pro/htdocs/community/includes/bootstrap.inc on line 899

Warning: Cannot modify header information - headers already sent in /www/pro/htdocs/community/includes/bootstrap.inc on line 531

Warning: Cannot modify header information - headers already sent in /www/pro/htdocs/community/includes/bootstrap.inc on line 532

Warning: Cannot modify header information - headers already sent in /www/pro/htdocs/community/includes/bootstrap.inc on line 533

Warning: Cannot modify header information - headers already sent in /www/pro/htdocs/community/includes/bootstrap.inc on line 534

Warning: include_once() [function.include-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/sites/all/themes/zen/template.php on line 33

Warning: include_once() [function.include-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/sites/all/themes/zen/template-subtheme.php on line 10

Warning: include_once() [function.include-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/sites/all/themes/zen/controlglobal/template.php on line 56

Warning: array_key_exists() [function.array-key-exists]: The second argument should be either an array or an object in /www/pro/htdocs/community/includes/module.inc on line 217

Warning: array_key_exists() [function.array-key-exists]: The second argument should be either an array or an object in /www/pro/htdocs/community/includes/module.inc on line 217

Warning: include_once() [function.include-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/sites/all/themes/zen/controlglobal/template.php on line 85

Warning: include_once() [function.include-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/sites/all/themes/zen/putman_shared/adcode.php on line 8

Warning: require() [function.require]: Unable to allocate memory for pool. in /www/pro/htdocs/scripts/include.php on line 377

Warning: require_once() [function.require-once]: Unable to allocate memory for pool. in /www/pro/htdocs/scripts/include.php on line 399

Warning: include_once() [function.include-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/sites/all/themes/zen/template.php on line 36

Warning: include_once() [function.include-once]: Unable to allocate memory for pool. in /www/pro/htdocs/community/sites/all/themes/zen/template.php on line 39
Unfettered Blog | ControlGlobal Community

Unfettered Blog

Even former ex-CIA officers don't understand ICS cyber security


Mark Sparkman is a former senior officer with the CIA's National Clandestine Service, and is now a senior international affairs analyst with the RAND Corporation. He wrote this article: The Real Cyber Threat, for CNN http://www.rand.org/commentary/2013/05/21/CNN.html.


ICS Cyber Security is still not understood by the IT community - and it is hurting critical infrastructure


May 8, 2013 Cheri McGuire, Symantec's Vice President, Global Government Affairs & Cybersecurity Policy testified to the Senate Judiciary Subcommittee on Crime and Terrorism hearing. She stated: "In my testimony today, I will provide the Subcommittee with our latest analysis of the threat landscape as detailed in the just-released Symantec Internet Security Threat Report (ISTR), Volume 18. Last year, we saw a significant increase in targeted attacks - up 42 percent from 2011, and it is almost certain that this trend will continue in the coming years.


Medical device and pharmaceuticals - where is ICS cyber security


December 2011, I attended the POLCYB meeting in Los Angeles. A major pharmaceutical manufacturer attended. The pharmaceutical representative mentioned they had not addressed ICS cyber security as they had simply not considered it and there was no regulatory driver.


Counterfeit exida safety certifications discovered


SELLERSVILLE, PA (May 9, 2013) --exida, an accredited global Certification Body, has discovered a counterfeit certificate falsely claiming that a product meets the functional safety requirements for Safety Integrity Level (SIL) 3 capable per IEC 61508.


ICS Cyber Security - People Are Not THE Answer - Yes they are!


Dale Peterson wrote a blog at www.digitalbond.com stating that "People Are Not THE Answer" to ICS cyber security. I disagree with Dale and have frequently stated that the 75% silver bullet for ICS cyber security is appropriate policies, procedures, training, and architecture. I believe the culture clash between IT and Operations is still the number one ICS cyber security problem. Relying on technology can actually exacerbate ICS cyber security problems and reinforce the cultural divide between IT and Operations.


Lesson learned from the utility test bed- the system is broken


Last week, the utility met with one of their major ICS vendors to determine if the vendor would be willing to support the utility's test bed concept. The purpose of the test bed is to maintain or improve reliability with security being a potential impact on reliability not the traditional security for the sake of security paradigm. The attendees at the meeting were the utility's Operational Technology (OT) manager, a utility engineering supervisor, the ICS vendor's security manager (not an ICS expert), and myself.


Medical device and control system cyber security


I attended the San Francisco Electronic Crimes Task Force Medical Device Security Conference. If they didn't continue to repeat the words "medical device", the conference could have been an electric, water, chemical, mass transit, manufacturing, etc control system cyber security conference. The issues presented were:
- Culture (engineers not addressing security)
- Legacy vs future devices (old devices are not secure - not clear new devices are)
- Organizational hand-off (silos)
- System of systems (more than just looking at an individual device)


Lessons learned to date on utility testbed


Even though we are just in the preliminary stages, there have been a number of interesting findings:
- Even though there are a plethora of cyber security solution providers, very few actually understand the unique needs of the ICS community.
- Many of the non-ICS technologies, though not developed for reliability, can provide benefits to the ICS community with "minor" modifications.


Where are the control system cyber security solutions???


About a month ago, I issued a call for control system cyber security solutions to be evaluated by an electric utility in an actual utility setting. The utility has power plants, electric distribution and low level transmission, SCADA, Smart Grid, etc. The purpose of the project is to find solutions that cannot only provide security, but more importantly, maintain or improve system reliability. To date, I have received about 15-20 responses. Considering how many solutions providers claim to be able to help secure control systems, where are the rest?


The threat to industrial control systems (ICSs) from Physical Persistent Design Features (PPDF)


Industrial control systems (ICSs) were designed for reliability and safety and to enable system operability and functionality. Many ICSs were originally designed before networking was commonplace. Consequently, cyber security was not a design consideration. There actually were many design features that would enable the systems to be more operator-friendly and functional, but with networking these features can be exploited and turned into vulnerabilities.