0% found this document useful (0 votes)
13 views59 pages

IC33M Module Two v3.11 Notes

The IC33M Module Two v3.11 Notes provide an overview of navigating the module and outline the course learning objectives based on ISA/IEC 62443 standards. It discusses risk elements, including the risk equation, threat sources, and vulnerabilities, emphasizing the importance of comprehensive threat catalogs and vulnerability assessments. Additionally, it details various types of cybersecurity assessments and the significance of understanding consequences and impacts in risk analysis.

Uploaded by

shadowz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
13 views59 pages

IC33M Module Two v3.11 Notes

The IC33M Module Two v3.11 Notes provide an overview of navigating the module and outline the course learning objectives based on ISA/IEC 62443 standards. It discusses risk elements, including the risk equation, threat sources, and vulnerabilities, emphasizing the importance of comprehensive threat catalogs and vulnerability assessments. Additionally, it details various types of cybersecurity assessments and the significance of understanding consequences and impacts in risk analysis.

Uploaded by

shadowz
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

IC33M Module Two v3.

11 Notes

©2024 International Society of Automation


1.3 Instructions

Notes:

Let's take a minute to learn how to navigate this module.


Previous and Next buttons are found at the bottom right of the screen. Here you will also find the
Replay button and volume control.
On the bottom left, you will find the Play/Pause toggle.
The sidebar on the left, includes tabs for the Menu, Transcript and Resources.

©2024 International Society of Automation


1.4 Course Learning Objectives

Notes:

The overall course goals are listed below. Take a moment to review these learning objectives which
are based on the ISA/IEC 62443 standards and industry best practices.

©2024 International Society of Automation


2.1 Risk Elements

©2024 International Society of Automation


2.2 Section Three Learning Objectives

Notes:

After completing this section, you should be able to:


• Discuss the different elements of risk.
• Explain how risk can be calculated.
according to the ISA 62443 standards and industry best practices.

©2024 International Society of Automation


2.3 The Risk Equation

Notes:

In this module, we will take a closer look at risk components. You may be familiar with the risk
equation. Risk equals threat times vulnerability times consequence. Threats consider who is trying
to compromise a system, what methods are being used, and how the system is affected. Threats
exploit a system’s vulnerabilities or weaknesses resulting in consequences.

©2024 International Society of Automation


2.4 Threat Source

Notes:

The threat source is the entity that can manifest a threat.

It may be a person or a group of people or it may be an object such as hardware or software.

It may even be an environmental event such as a fire or flood.

When identifying the threat source, it is helpful to identify some of the characteristics of the source
such as its location, capability and motivation.

It is important to prepare a comprehensive and realistic list of threats in order to perform a security
risk assessment.

©2024 International Society of Automation


2.5 Threat Environment

Notes:

There are a number of factors that may affect the threat environment of the SUC. Threat sources,
threat vectors, physical environments, geo-political climate and the sensitivity of the system should
all be considered.

How do you find these threats?

You may find threat intelligence from a variety of resources. The US Cybersecurity & Infrastructure
Security Agency (CISA) and The European Union Agency for Cybersecurity (ENISA) have websites
dedicated to advisories and alerts. Other threat intelligence resources include IACS product
suppliers, malware vendors, industry advisory groups and local government.

©2024 International Society of Automation


2.6 Threat Vector

Notes:

The Threat Vector is the means the threat source may utilize to compromise the zone or conduit.

Examples of threat vectors include spoofing, tampering, information disclosure and denial of
service.

For documentation purposes, Threat vectors do not need to describe the precise details of how an
attacker or malware might compromise a cyber node.

©2024 International Society of Automation


2.7 Example Threat Statements

Notes:

So what is an example of a threat statement?

Click each icon discover possible threat scenarios.

Example A: A non-malicious employee opens a phishing e-mail, compromising its access


credentials, enabling a threat vector for an outside attacker to access sensitive data.
Example B: A non-malicious employee physically accesses the process control zone and plugs a USB
memory stick into one of the PCs.
Example C: Authorized support personnel logically assesses the process control zone using an
infected laptop that results in a threat vector for a virus infection.

©2024 International Society of Automation


2.8 Threat Catalog

Notes:

In order to make good decisions, the asset owner should have a threat catalog with the criteria for
choosing the correct scenarios that need to be evaluated by the multidisciplinary team during a
detailed cybersecurity risk analysis.
Each plant has unique situations due to its location, history, potential consequences, business,
competitors, risk culture, technology, and more. The threat catalog must be used consistently with
the ISA/IEC-6243 methodology, scope, and definitions. IT catalogs might not work well.
A set of realistic scenarios must be evaluated during a detailed cybersecurity risk assessment in
order to determine how to effectively and efficiently mitigate the intolerable risk. This will be
necessary to avoid improvisation and gain confidence in taking the maximum benefit from the
exclusive ISA/IEC-62443-3-2 methodology.

©2024 International Society of Automation


3.1 Vulnerabilities

©2024 International Society of Automation


3.2 Vulnerability

Notes:

A vulnerability is any flaw or weakness in a system's design, implementation, or operation that could
be exploited to compromise the system.

In order for threats to be successful they must exploit one or more vulnerabilities in an asset.
Therefore, it is necessary to identify known vulnerabilities in assets to better understand threat
vectors.

©2024 International Society of Automation


3.3 Classes of Vulnerabilities

Notes:

Broad classes of vulnerabilities include:

· Policy & Procedural


· Architecture & Design
· Configuration & Maintenance
· Physical
· Software and
· Communication & Network

Click on each icon to view examples of each.

©2024 International Society of Automation


P6 (Slide Layer)

P5 (Slide Layer)

©2024 International Society of Automation


P4 (Slide Layer)

P3 (Slide Layer)

©2024 International Society of Automation


P2 (Slide Layer)

P1 (Slide Layer)

©2024 International Society of Automation


4.1 Assessing Vulnerabilities

©2024 International Society of Automation


4.2 IACS Cybersecurity Vulnerability Assessments

Notes:

The purpose of an IACS Vulnerability Assessment is multifold.


It is an exercise to define, identify, and classify the security vulnerabilities in an industrial control
system and its related network infrastructure.
The assessment can be used to evaluate the IACS design, implementation, configuration as well as
its operation and management.
It can be used to determine the adequacy of security measures and identify security deficiencies.
The assessment can also be used to determine known vulnerabilities for the used components.

©2024 International Society of Automation


4.3 Assessing for Vulnerabilities

Notes:

Vulnerability analysis is all about finding procedural weaknesses within governance, best practices,
technological vulnerabilities within the various systems under consideration, and physical
vulnerabilities within the installation and process.
Cyber Risk Analysis is about preventing intolerable consequences. Not all vulnerabilities represent a
risk to the operational environment as there are different ways to mitigate the risk other than fixing
weaknesses or just patching vulnerabilities.
Many people are tempted to believe that all weaknesses have to be fixed and all vulnerabilities need
to be patched. But this is not correct since exploiting vulnerabilities does not necessarily lead to a
potential consequence. A deep understanding of the SUC components and their essential functions
over the industrial processes being operated and controlled is necessary.
Vulnerabilities alone without visualizing the consequences does not represent a risk to operational
environments.
Some people believe that technology has all the answers, however, technology alone cannot ensure
safety. To guarantee safety at a plant or a production site sound processes and procedures must be
established by senior management. It is our experience that senior management is not always
aware of this responsibility.

©2024 International Society of Automation


4.4 Types of Cybersecurity Vulnerability Assessments

Notes:

There are four types of Cybersecurity Vulnerability Assessments.

• High level vulnerability assessments are also known as gap assessments. These are the least
invasive on the system.
• Passive vulnerability assessments
• Active vulnerability assessments
• Penetration tests, which are the most invasive on the system

When selecting an assessment type, Be aware of the cost and risk to the system. Also consider the
benefits gained by conducting the assessment.

Let’s take a closer look at each of these assessment types.

©2024 International Society of Automation


4.5 High-level Vulnerability Assessment*

Notes:

The initial assessment evaluates an organization’s existing operational and technical cybersecurity
practices.

It should provide a comparison of the system to industry regulations, standards and best practices,
as well as feedback on performance relative to industry peers.

This assessments typically involves:


· Interviews with key personnel
· Site walk-throughs
· Examination of drawings and sample configurations
· Review of existing policies and procedures
And perhaps, completing a questionnaire.

The Initial assessment is also referred to as a High-Level or Gap Assessment.

©2024 International Society of Automation


4.6 Passive Vulnerability Assessment

Notes:

Passive vulnerability assessments discover network devices using passive means. This includes:
• Reviewing drawings,
• System walk throughs
• Traffic analysis
• ARP or Address Resolution Protocol tables

Passive means can also be used to discover vulnerabilities such as :


• Capture and study actual network traffic
• Collect data from devices
• Review configurations
• Research using vulnerability databases

This requires understanding the system and processes, and creating or updating documentation.

©2024 International Society of Automation


4.7 Active Assessment

Notes:

Active assessments are invasive vulnerability assessments.

Software tools are used to do a deep dive into the system to identify network devices and network
vulnerabilities.

N-map, Ping Sweep or ARP Scan, Advanced I P Scanner, Superscan, and Shodan are commonly used
to identify network devices.

Vulnerabilities can be discovered with tools such as Open VAS, Nessus, and Nexpose.

This process develops an understanding of the system and may require the creation or update of
documentation.

©2024 International Society of Automation


4.8 Penetration Testing

Notes:

Penetration Testing is the most invasive cybersecurity vulnerability assessment.

It begins with an active cybersecurity vulnerability assessment and it is conducted using the
prospective of a potential attacker.

A Pen Test attempts to exploit known and unknown security vulnerabilities using exploit tools and
techniques.

Penetration testing also validates the effectiveness of security countermeasures.

You should never do pen testing on live systems.

©2024 International Society of Automation


4.9 Vulnerability Assessment vs. Penetration Testing

Notes:

How do vulnerability assessments compare to penetration testing?

Vulnerability assessments: define, identify, and classify, vulnerabilities. Tools are used to identify
weaknesses, and discoveries are reported.

Pen testing exploits vulnerabilities of the system by attempting to gain non-authorized access.
Aggressive tools and techniques mimic a real attack.

©2024 International Society of Automation


4.10 Conducting High Level Assessment

Notes:

How do we start an IACS high-level assessment?

First, identify benchmark standards.

Next, gather information about the system through interviews, questionnaires, drawings and site
visits.

Then, compare performance with the benchmarked standards. Are the people, processes and
technology meeting standards?

Finally, document and report results.

©2024 International Society of Automation


5.1 Assessment Tools

©2024 International Society of Automation


5.2 IACS Cybersecurity Assessment Tools

Notes:

IACS assessment tools include:

• The Department of Homeland Security’s Cyber Security Evaluation Tool, known as CSET.
• Custom spreadsheets, and
• Custom databases

©2024 International Society of Automation


5.3 Benefits of CSET

Notes:

CSET offers many benefits to organizations using the tool.

It is a repeatable and systematic approach for assessing an organizations cybersecurity posture.

It provides an evaluation and comparison to existing industry standards and regulations.

It facilitates discussion and input from subject matter experts throughout the organization.

It identifies potential vulnerabilities in the control system design and security policies.

It also offers guidelines for IACS cybersecurity solutions and mitigation.

©2024 International Society of Automation


5.4 Limitations of CSET

Notes:

CSET offers many benefits to the assessment of IACS systems. However, there are limitations.

CSET is only one component of a comprehensive control system security program.

It will not provide a detailed architectural analysis of the network or a detailed network
hardware/software configuration review.

CSET is component focused rather than system focused.

It is not a risk analysis tool. Therefore, it will not create detailed risk assessment.

CSET is not intended as a substitute for in-depth analysis of control system vulnerabilities as
performed by trained professionals.

Data and reports generated by the CSET should be managed securely and marked, stored, and
distributed in a manner appropriate to their sensitivity.

Even with these limitations, CSET is an excellent first step in an analysis.

©2024 International Society of Automation


5.5 CSET Reference Standards

Notes:

This table lists the standards referenced in CSET. Take a moment to review the standards. Click
Next when you are ready to continue.

©2024 International Society of Automation


5.6 CSET Process

Notes:

The CYBERSECURITY EVALUATION TOOL or CSET is a great free desktop software tool developed by
the United States government that guides asset owners and operators through a step-by-step
process to evaluate industrial control system (ICS) and information technology (IT) network security
practices.
The C-Set process has seven steps.
1. Form a team.
2. Add assessment information.
3. Select mode and standards.
4. Determine the security level.
5. Build a network diagram.
6. Answer questions, and,
7. Analyze the results.
The CSET tool is not an Industrial Cybersecurity Assessment tool, and it does not meet ISA/IEC-
62443-3-2 requirements in determining how to mitigate risk. It does not replace the need for a High-
Level Risk Analysis and Detailed Cybersecurity Risk Analysis as we are going to see during the rest of
this course.

©2024 International Society of Automation


5.7 Complimentary Methods

Notes:

There are many other tools that can be used for evaluating governance, policies, procedures, and
best practices. The result will be an input to the detailed risk assessment.

©2024 International Society of Automation


6.1 Consequence

©2024 International Society of Automation


6.2 Consequence

Notes:

Consequence is a statement of the worst-case scenario or results if the threat scenario was to occur.

Our consequence categories extend to HSE, health, safety and environment. However,
consequences are not limited to HSE.

For example: If a hacker compromises your warehouse software and deletes all data: no
consequences to HSE but you can not deliver goods to your customers. This will lead to loss of
revenue and reputation. If your customers has alternative suppliers, they might not come back.

Consequences are scored per category but only the highest is used in risk ranking.

©2024 International Society of Automation


6.3 Definitions of Consequence & Impact

Notes:

According to our standard, each threat identified shall be evaluated to determine the consequence
and the impact of the consequence should the threat be realized. Document impact in terms of the
worst-case impact on risk areas such as personnel safety, financial loss, business interruption, and
environment.

• Consequence is the undesirable result of an incident, usually described in terms of health and
safety effects, environmental impacts, loss of property, and business interruption costs result that
occurs from a particular incident.

• Impact measures of the ultimate loss or harm associated with a consequence. Impact may be
expressed in terms of numbers of injuries and/or fatalities, extent of environmental damage
and/or magnitude of losses such as property damage, material loss, loss of intellectual property,
lost production, market share loss, and recovery costs.

As an example, consider an incident on a job site. The consequence of the incident was a spill. The
impact of the spill was a $100,000 fine and $25,000 in clean-up expenses.

©2024 International Society of Automation


6.4 Example Consequence Scale

Notes:

This an example of a consequence scale.

Every organization determines their own- Not only in categories but also impact. Consequence
values are determined by the company's risk appetite.

Impact values on the same row in a consequence table are typically valued equally.

Information security is not a big consequence for all organizations (wastewater treatment comes to
mind).

In some organizations $100K is trivial in others it is considered high.

After, creating a statement of the worst-case consequence if a threat scenario was to occur, assign
an impact rating per the Consequence Scale. Assume worst case with no countermeasures in place.
Each category (people, environment, assets, reputation) should be scored. Use only the highest to
determine risk ranking for each scenario.

©2024 International Society of Automation


6.5 Cyber Criticality Assessment

Notes:

The criticality assessment is a technique or method for finding and discovering danger to the
operational environments if the SUC components are compromised.
A deep understating of the essential functions of the SUC components and the industrial processes
is required to find these dangers, hazards, and potential business consequences.
The criticality analysis provides a measure of the negative impact on the plant and becomes an
essential method for understanding risk and creating a list of potential consequences. You cannot
make good decisions if you can’t visualize and understand the risk.

©2024 International Society of Automation


6.6 Criticality Business Value

Notes:

An existing Process Hazards Analysis or PHA provides invaluable input for understanding the
criticality of the many different assets or components within the system under consideration (SUC).
Some of these potential consequences could affect and create harm or impacts to:
• Workers and other people’s health,
• Process safety,
• Environmental safety,
• Industrial process flow, such as delays, interruptions, plant shut down, out of specifications,
and many more;
• The flow of data and confidentiality of information such as in information security or IT, and
finally
• Impact the business value, the reputation of the company, and business continuity.
Some people believe that technology has all the answers, but technology alone cannot ensure
safety.
Good safety is good business. If the factory doesn’t run, it doesn’t make money. Catastrophe is not
just about the loss of life or harm to the environment, it can affect the production capacity and
capability of your plant or system. This represents a loss in value.
Insurance premiums do reflect the safety culture of the company. When you look for safety and
security early in the process, you have a great opportunity to influence the design of the system and
the plant. There is an opportunity to save significant investment costs if you optimize the CAPEX and
you optimize the OPEX.
For high-performance companies, understanding the need to invest in the future means to invest in
safety and security.
The international standards ISA/IEC-62443’s basic idea is to take the best of both safety and security.
When the damage is done, it’s too late.
In production environments, safety and security must be integrated and analyzed consistently
together.

©2024 International Society of Automation


6.7 Criticality CAI Method

Notes:

The AIC method for analyzing the criticality of the many SUC components complies with a few
requirements listed on the ISA/IEC-62443-3-2.
Basically, this method requires that a multidisciplinary and knowledgeable team visualizes and
identifies the consequences that might occur if the components get compromised. This method for
finding potential danger or hazards is also called “initial risk”, or “high-level risk assessment”.
Don’t confuse “High-Level Vulnerability Assessment” with “High-Level Risk Assessment” as these two
are frequently misinterpreted.
A deep understanding of each component’s essential functions within the multiple zones and
conduits of a certain SUC, and all automation solutions (AS) within the IACS is needed. A deep
knowledge and understanding of the industrial processes being operated and controlled is required
as well.
We cannot manage a risk that we don’t understand, we cannot see or visualize. This is a key activity
within the ISA/IEC-62443-3-2 standard.
The knowledgeable team must find out what the consequences would be under the assumption that
the components are already completely compromised. There is no need to discuss how this
happened, which vulnerability has been exploited, or who did it to determine the consequences.
In this process, the team must answer three questions.
Question number one.
Assuming that the confidentiality of the component has been compromised, what are the potential
consequences of that cyber incident?
The team should discuss and list all potential consequences and their impact related to that cyber
incident.

©2024 International Society of Automation


Question number two.
Assuming that the availability of the component has been compromised, what are the potential
consequences of that cyber incident?
The team should discuss and list all potential consequences and their impact related to that cyber
incident.
Question number three.
Assuming that the integrity of the component has been compromised, what are the potential
consequences of that cyber-incident?
The team should discuss and list all potential consequences and their impact related to that cyber
incident.
By doing this we are analyzing and finding out the worst-case consequences.
Think about flipping a coin. What is the chance for you to choose the correct answer before flipping
the coin? The answer to that will be 50%, right?
What is the chance for you to choose the correct answer after flipping the coin? The chance is now
is100%.
What changed? … the state of knowledge!
So. You cannot make good and sound decisions without knowledge.
When dealing with industrial cybersecurity, consequence-based decisions must become the same as
knowledge-based decisions.

©2024 International Society of Automation


6.8 Recap

Notes:

As a result of this key activity, we must produce a list of all potential consequences organized by
each three cyber-incidents associated with every single component within the SUC.
Most likely the plant is already aware of these potential consequences, maybe not.
What if we discover new potential consequences that the plant is not aware of?
Safety and security is a big responsibility and it cannot be overlooked.

©2024 International Society of Automation


7.1 Risk Equation

©2024 International Society of Automation


7.2 Risk Equation

Notes:

Here we have the equation for calculating risk. Risk equals threat times vulnerability times
consequence. It is easier to work with 2 factors instead of 3. We can simplify this equation by
converting -threat times vulnerability to likelihood. Likelihood is the quantitative chance that an
action, event or incident may occur. Now we have Risk equals likelihood times consequence.

©2024 International Society of Automation


7.3 Determine Likelihood

Notes:

Determination of likelihood is an important step in determining risk. Each threat and vulnerability
pair identified shall be evaluated to determine the likelihood that the threat will be realized. The
measure of likelihood may be quantitative, such as probability or it may be qualitative, such as low,
medium, or high.
Likelihood is influenced by several factors. One of these is Frequency. How often does the threat
arise? This can depend on the target’s attractiveness and the attack surface.
Probability is another factor. What is the likelihood that an attack will be successful? The answer
depends on the
capability of the threat actor, known vulnerabilities and the motivation or intent of the threat actor.

©2024 International Society of Automation


7.4 Likelihood Scale

Notes:

The measure of likelihood is typically qualitative and is determined using a likelihood scale which is
determined by the organization. This is an example. Organizations must define a likelihood scale
which is appropriate for their environment.

©2024 International Society of Automation


7.5 Calculate Risk

Notes:

For simplicity, let’s look at a bi-dimensional square symmetric numerical linear risk matrix.
In this example, the matrix has two variables. One variable for measuring the Impact of the
consequences and a second variable for measuring the likelihood.
Sometimes the likelihood can be represented or understood as “chances”, “probability”, or
‘frequencies”.
The operational risk matrix by itself is useless without a set of rules. There is knowledge behind the
matrix, and that knowledge belongs to the plant. The operational risk matrix is usually explained in a
document. This document can have a few or many pages. That knowledge has been accumulated
for decades.
Every listed consequence identified through the high-level risk assessment, must be measured in
terms of its impacts.
In the figure below the example shows a consequence with its highest impact to the economic and
financial, impact 3.
The likelihood assigned to the event on this case is also 3. So, three times three returns a risk of
nine.

©2024 International Society of Automation


7.6 Tolerable Risk

Notes:

Tolerable risk is the level of risk deemed acceptable to an organization. It is sometimes called
“appetite for risk”. Management is responsible for defining the risk tolerance for their organization.
Organizations should include consideration of legal requirements when establishing tolerable risk.

If risk is found to be below Tolerable risk, the organization will accept the risk.

If risk is above the established tolerable risk level, the organization will need to take action to
reduce or eliminate the risk.

There are four ways to mitigate risk to the organization, which are collectively known as the 4 T’s.
The organization must decide, based on the results of the risk assessment, if they are going to
tolerate, transfer, terminate or treat the risk. Ultimately the decision is up to the organization how
to manage the risk.

Click each red box to learn more about that way of managing the risk.

Additional guidance on establishing tolerable risk can be found in ISO 31000 and NIST 800-39.

©2024 International Society of Automation


8.1 Module Summary

©2024 International Society of Automation


8.2 Summary

Notes:

What are the different types of threats that can compromise SUC Assets?

What is the difference between Vulnerability Assessment and Risk Assessment?

What is the difference between a cyber-incident and an intolerable consequence?

©2024 International Society of Automation


8.3 Cyber Check Review Q1

8.4 Review Q2

©2024 International Society of Automation


8.5 Review Q3

8.6 Review Q4

©2024 International Society of Automation


8.7 Review Q5

8.8 Review Finish

©2024 International Society of Automation


9.1 Module Two Quiz

9.2 Module Two Quiz : Risk Components

Notes:

©2024 International Society of Automation


2. Quiz

Q2.2

©2024 International Society of Automation


Q2.3

Q2.4 Which of the following is a simplified risk equation?

©2024 International Society of Automation


Q2.5

©2024 International Society of Automation


9.5 Thank you

©2024 International Society of Automation

You might also like