1/187
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the purpose of assigning a Target Security Level (SL-T) during the Assess phase of ICS security implementation?
To determine the existing vulnerabilities of the system.
What happens during the Develop & Implement phase of ICS security implementation?
Countermeasures are implemented to meet the Target Security Level (SL-T).
What is the primary goal of the Maintain phase in ICS security implementation?
To ensure the Achieved Security Level (SL-A) is equal to or better than the Target Security Level (SL-T).*
What is phase 1 of the IACS Cybersecurity Life Cycle?
Assess
What is phase 2 of the IACS Cybersecurity Life Cycle?
Develop & Implement
What is phase 3 of the IACS Cybersecurity Life Cycle?
Maintain phase
What is step 1 of the IACS Cybersecurity Life Cycle (Assess Phase)?
High-Level Cyber Risk Assessment
What is step 2 of the IACS Cybersecurity Life Cycle (Assess Phase)?
Allocation of IACS Assets to Security Zones or Conduits
What is step 3 of the IACS Cybersecurity Life Cycle (Assess Phase)?
Detail Cyber Risk Assessment
What is step 4 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?
Cybersecurity Requirements Specification
What is step 5 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?
Design and engineering of Cybersecurity countermeasures
What is step 6 of the IACS Cybersecurity Life Cycle (Develop & Implement Phase)?
Installation, commissioning and validation of Cybersecurity countermeasures
What is step 7 of the IACS Cybersecurity Life Cycle (Maintain)?
Cybersecurity Maintenance, Monitoring and Management of Change
What is step 8 of the IACS Cybersecurity Life Cycle (Maintain)?
Cyber Incident Response & Recovery
What are the continuous processes activities of the IACS Cybersecurity Life Cycle?
Cybersecurity Management System: Policies, Procedures, Training & Awareness, Periodic Cybersecurity Audits
What must be done before an assessment can be started?
Create a Project Plan
ID Steps of the Project to perform the assessment
ID the System Under Assessment
System Under Consideration (SUC)
The system or systems within an Industrial Automation and Control System environment that are being evaluated or designed for security enhancements.
System Under Assessment (SUA)
The system that is being evaluated for compliance with standards.
What are some required information gathering items before the assessment can begin?
Goals of the Assessment
IACS asset inventory
Understanding of the IACS
Regulations, requirements, and governance of relevance (Government, Industry, Company)
Architecture diagrams
Configuration Files
Known vulnerabilities
Define roles and responsibilities
Establish training requirements
System Architecture Diagrams
Depiction of system components, their connectivity, and physical locations.
Physical System Architecture Diagram
A diagram that provides a visual representation of the physical components within a system and their interconnections. It focuses on hardware elements such as servers, network devices, control systems, and terminals, showing how these components are arranged and connected.
Functional System Architecture Diagram
A diagram that describes the functions of a system and their relationships without focusing on physical details. It presents a logical view of the system, emphasizing software elements, data flows, and interactions between different functions or modules within the system.
(True/False) IACS functionality should be graphically represented on at least one IACS Architecture drawing
True
ISA-95 Functional Layer Level 0
The physical process — This level defines the physical processes showing data flowing from sensors and actuators into the control level.
ISA-95 Functional Layer Level 1
Intelligent devices — Devices in this level sense and manipule the physical processes. Process, sensors, analyzers, actuators and related instrumentation. This layer shows how PLCs receive field device data, process it, and then send commands back to the field devices.
ISA-95 Functional Layer Level 2
Control systems — Supervising, monitoring and controlling the physical processes. Real-time controls and software; DCS, human-machine interface (HMI); supervisory and data acquisition (SCADA) software. This level represents how the control systems manage PLCs, how operator commands are processed, and how alarm conditions are handled.
ISA-95 Functional Layer Level 3
Manufacturing operations systems — Managing production workflow to produce the desired products. Batch management; manufacturing execution/operations management systems (MES/MOMS); laboratory, maintenance and plant performance management systems; data historians and related middleware. Time frame: shifts, hours, minutes, seconds.
ISA-95 Functional Layer Level 4
Business logistics systems — Managing the business-related activities of the manufacturing operation. ERP is the primary system; establishes the basic plant production schedule, material use, shipping and inventory levels. Time frame: months, weeks, days, shifts. This level shows how enterprise systems deal with production planning and overall business logistics, and how this information is sent down to lower levels.
(True/False) ISA-95 functional layers are the same thing as the Purdue Enterprise Reference Architecture (PERA)
False
(True/False) ISA-95 functional layers speak to functionality - NOT systems or network layers.
True
ISA-95 Control Domain
Level 3, 2, 1, 0
ISA-95 Enterprise Domain
Level 4
What ISA-95 levels are critical to safety, reliability, efficiency, and quality
Levels 3, 2, 1, 0 (The Control Domain)
At a minimum, Network Diagrams should include...
Physical or Logical connections
Individual network devices represented symbollically
Switch port assignments
VLANs
Hosts (optional)
Host Device
Computing systems that host data or applications, such as servers, workstations, and user devices.
Embedded Devices
Computer systems with a dedicated function within IACS, like PLCs, RTUs, or IEDs.
Network Device
Components that facilitate data transmission within an IACS, including switches, routers, and firewalls.
Software Applications
Software systems used to control, monitor, or manage industrial processes, such as SCADA, HMI, MES, and ERP systems.
What is an Asset Inventory for IACS and SCADA Systems?
A list or database of all hardware (physical and virtual) and software within an IACS or SCADA environment, compiled through documentation and site surveys. Automated tools can be used for data gathering, but should be tested to avoid system impact or security vulnerabilities.
Why must automated tools for compiling an asset inventory in IACS and SCADA systems be carefully tested?
To ensure they do not impact system availability or integrity and do not introduce security vulnerabilities while gathering asset information.
What should the hardware asset inventory in an IACS should include?
Computers (e.g., servers, workstations), network equipment (e.g., switches, routers, firewalls), and automation devices (e.g., PLCs, DCSs, VFDs, RTUs).
What types of devices should be included in the hardware asset inventory in an IACS?
All devices with an Ethernet connection and an IP address, as well as devices with routable serial protocols like ControlNet, Profibus, Modbus TCP, etc.
What attributes of devices should be documented in an asset inventory?
Device or System Name
Asset ID
Device Type
Function
Network interface(s)
Network address(es)
Manufacturer
Model
Serial Number
Operating system and version (if applicable)
Firmware versions (if applicable)
Responsible organization/individual
Physical Location
Logging Features (if applicable)
Notes
What attributes of virtualized devices should be documented in an asset inventory?
VM name
VM Type
Function
Network interface(s)
Network address(es)
Host Name/ID
Host type
Operating system and version
Responsible organization/individual
Custodian(s) (Admin)
Logging Features
Notes
What categories of software should a software asset inventory include?
Operating systems
Applications
Databases
Firmware
What attributes of software devices should be documented in a software asset inventory?
Software Name
Software type (e.g. OS, application, database, firmware, etc.)
Function
Host Name
Host type (physical or virtual, server or workstation, network device, controller, etc.)
Vendor
Version
Responsible organization/person
License information
-# of Licenses
-Location of License
-License Expiration Date
Update/Patch Process
What are the three methods that should be used together to make a comprehensive asset inventory?
Document Analysis
Assisted Analysis with Tools
Plant Walk through
What is the risk equation?
Risk = Threat x Vulnerability
What is a threat source?
Person, group, or environment that can present a threat
What are common threat sources?
Authorized internal personnel
Authorized 3rd party
Unauthorized internal personnel
Unauthorized external person (hacker)
Malware
Equipment
Environment
Other
Any
What is a threat vector?
Potential medium that a threat source may leverage to compromise a zone or conduit
What is Spoofing?
Deliberate act to assume an identity in order to gain unauthorized access.
What is Tampering?
Unauthorized changes to a program, configuration, or data
What is Information Disclosure?
Unauthorized redirection of data
What is a Denial-of-Service attack?
Deny, degrade, or destroy access to data or resources
What is a Threat Catalog?
An organized list of potential threats to a system that includes information about the nature of each threat, related vulnerabilities, affected assets, potential impacts, and possible mitigation strategies. It's a crucial tool for risk management in IACS cybersecurity.
What ISA/IEC 62443 standard establishes criteria for threat sources and actions?
ISA/IEC-62443-3-2
Vulnerability
Any flaw or weakness in a system's design
(True/False) Vulnerability Analysis is the same thing as Cyber Risk Analysis.
False
(True/False) Not all vulnerabilities represent risk to an IACS network.
True
(True/False) All vulnerabilities lead to a consequence.
False
What are the types of Cybersecurity Vulnerability Assessments
High-level vulnerability assessment
Passive vulnerability assessment
Active vulnerability assessment
Penetration test (hunting for vulnerabilities)
What is a High-level Vulnerability assessment?
An evaluation of an organization's cybersecurity practices against industry standards and best practices, involving interviews, site walk-throughs, examination of configurations and documents, and policy reviews. Often referred to as a "Gap Assessment".
What is a Passive Cybersecurity Vulnerability Assessment?
A non-intrusive evaluation technique to discover network devices and vulnerabilities using methods like documentation review, system walk-throughs, traffic analysis, log collection, configuration review, and vulnerability database research. It aids in understanding the system, the industrial process, and helps in creating or updating documentation.
What is an Active Cybersecurity Vulnerability Assessment?
A proactive evaluation method to discover network devices and vulnerabilities using active network scanning tools like Nmap, Ping Sweep, and vulnerability scanners like OpenVAS, Nessus. It enhances the understanding of the system, the industrial process, and assists in creating or updating documentation.
What is Penetration Testing?
A method that starts with an active cybersecurity vulnerability assessment, simulates a malicious actor's perspective, and attempts to exploit known and unknown security vulnerabilities to validate the effectiveness of security countermeasures.
Conducting a High-Level Vulnerability Assessment
A process that involves identifying benchmark standards, gathering information via interviews, questionnaires, drawings, and site visits, comparing performance with benchmarks across people, processes, and technology, and documenting and reporting the results.
What is CSET (Cyber Security Evaluation Tool)?
A software tool by the U.S. Department of Homeland Security's ICS-CERT, designed to assist organizations in assessing their control systems and network security practices against recognized industry standards. It provides a systematic approach for evaluating cybersecurity posture.
What are some benefits of CSET?
CSET provides a repeatable and systematic approach for assessing cybersecurity posture, comparing it to industry standards, involving various organizational experts, identifying potential vulnerabilities in control systems and policies, and offering guidelines for IACS cybersecurity solutions and mitigations.
Policy Vulnerabilities
Weaknesses in established security policies that can include inadequate security objectives, weak access controls, or insufficient incident response procedures.
Procedural Vulnerabilities
Flaws in the implementation or execution of security procedures, such as improper change management, lack of security training, or neglecting regular security assessments.
Configuration & Maintenance Vulnerabilities
Weaknesses in the setup and ongoing management of industrial automation and control systems (IACS), including insecure configurations, improper maintenance practices, and lack of monitoring and control mechanisms.
Architecture & Design Vulnerabilities
Weaknesses or flaws in the foundational structure and conceptual design of industrial automation and control systems (IACS), including inadequate security considerations, flawed architecture choices, and insufficient protection mechanisms.
Configuration & Maintenance Vulnerabilities
Weaknesses in the setup and ongoing management of industrial automation and control systems (IACS), including insecure configurations, improper maintenance practices, and lack of monitoring and control mechanisms.
Physical Vulnerabilities
Weaknesses or susceptibilities in the physical aspects of industrial automation and control systems (IACS), including inadequate physical security measures, vulnerabilities in infrastructure, and potential threats from physical access.
Software Vulnerabilities
Weaknesses or flaws in software that can be exploited by attackers due to coding errors, design flaws, or insecure configurations. Addressing software vulnerabilities is crucial for maintaining the security and integrity of systems.
Communication & Network Vulnerabilities
Weaknesses or susceptibilities in the communication and networking components of industrial automation and control systems (IACS), including insecure protocols, inadequate segmentation, and lack of encryption. Addressing these vulnerabilities is crucial for maintaining secure and reliable communication within IACS.
Consequence
The undesirable result of an incident, usually described in terms of health and safety effects, environmental impacts, loss of property, and business interruption costs result that occurs from a particular incident
Impact
A measure of the ultimate loss or harm associated with a consequence. Impact may be expressed in terms of numbers of injuries and/or fatalities, extent of environmental damage and/or magnitude of losses such as property damage, material loss, loss of intellectual property, lost production, market share loss, and recovery costs.
Cyber Criticality Assessment
measuring the potential negative impact if information becomes unavailable, unreliable, or compromised. It communicates to employees/contractors and serves as an important input for risk assessment. It provides a methodology to identify worst-case consequences.
Simplified Risk Equation
Risk = Likelihood x Consequence
Full Risk Equation
Risk = Threat x Vulnerability x Consequence
Factors of Likelihood
Frequency and Probability
Risk Matrix
A tool used to assess and visualize risk in an IACS by classifying it based on the likelihood of a threat exploiting a vulnerability and the impact if it occurs. This helps prioritize mitigation efforts according to the risk level.
Vulnerability Assessment
A process of identifying, quantifying, and prioritizing system vulnerabilities. It uses various tools and techniques to identify potential weaknesses that need to be addressed, providing insights into the system's security gaps.
Risk Assessment
A broader process that identifies vulnerabilities, considers potential threats that might exploit these vulnerabilities, and the potential impact. It provides an understanding of the overall risk associated with vulnerabilities, guiding decisions on risk management and mitigation prioritization.
What is the difference between a cyber-incident and an intolerable consequence?
A cyber-incident refers to an event or action, malicious or not, that threatens the integrity, confidentiality, or availability of cyber systems. An intolerable consequence, on the other hand, is a result of a cyber-incident that exceeds an organization's predefined threshold of acceptable risk or impact, potentially causing significant harm to operations, safety, or reputation.
Understanding Cybersecurity Risk
The process of comprehending cybersecurity risk involves determining realistic threats, identifying existing vulnerabilities and critical assets, understanding the potential consequences of compromise, and assessing the effectiveness of current safeguards.
Developing a Plan to Address Unacceptable Risk
This involves evaluating existing countermeasures, recommending additional ones and changes to current policies, prioritizing recommendations based on relative risk, and assessing the balance between cost/complexity and effectiveness.
Benefits of Cyber Risk Assessments
Helps determine priority plants/processes, understand threats and vulnerabilities, intelligently design and apply countermeasures to reduce risk, prioritize activities and resources, and evaluate countermeasures based on their effectiveness versus cost/complexity.
Balancing Security and Cost
Perfect security is unaffordable. Thus, risk reduction is balanced against the cost of security measures intended to mitigate the risk.
4.2.3.1 Select a risk assessment methodology
The organization shall select a particular risk assessment and analysis approach and methodology that identifies and prioritizes risks based upon security threats, vulnerabilities and consequences related to their IACS assets.
4.2.3.2 Provide risk assessment background
Information
The organization should provide participants in the
risk assessment activity with appropriate
information including methodology training, before
beginning to identify the risks.
4.2.3.3 Conduct a high-level risk assessment
A high-level system risk assessment shall be performed to understand the financial and HS&E consequences in the event that availability, integrity, or confidentiality of the IACS is compromised.
4.2.3.4 Identify the industrial automation and control systems
The organization shall identify the various IACS, gather data about the devices to characterize the nature of the security risk, and group the devices into logically integrated systems.
Risk Identification, Classification, and Assessment
A systematic process to identify and assess the severity of IACS cyber risks an organization faces. It involves prioritizing and analyzing potential threats, vulnerabilities, and consequences. The objective is to guide cybersecurity investments to lower risk.
4.2.3.5 Develop simple network diagrams
The organization shall develop simple network diagrams for each of the logically integrated systems showing the major devices, network types, and general locations of the equipment.
4.2.3.6 Prioritize systems
The organization shall develop the criteria and assign a priority rating for mitigating the risk of each logical control system.
4.2.3.7 Perform a detailed vulnerability assessment
The organization shall perform a detailed vulnerability assessment of its individual logical IACS, which may be scoped based on the high-level risk assessment results and prioritization of IACS subject to these risks.
4.2.3.8 Identify a detailed risk assessment methodology
The organization's risk assessment methodology shall include methods for prioritizing detailed vulnerabilities identified in the detailed vulnerability assessment.