SCADA Risk Management Framework Guide
SCADA Risk Management Framework Guide
Disclaimer: To the extent permitted by law, this document is provided without any liability
or warranty. Accordingly it is to be used only for the purposes specified and the reliability
of any assessment or evaluation arising from it are matters for the independent judgement
of users. This document is intended as a general guide only and users should seek
professional advice as to their specific risks and needs.
UNCLASSIFIED
Page 2 of 48
UNCLASSIFIED
Table of Contents
1 Introduction ........................................................................................................................... 5
1.1 Background ...................................................................................................................... 5
1.2 Scope ............................................................................................................................... 5
1.3 Key Terms and Definitions ................................................................................................ 6
1.4 References ....................................................................................................................... 7
1.5 Acknowledgements........................................................................................................... 7
2 Tailoring the Risk Management Framework ........................................................................ 8
3 Risk Management Methodology ........................................................................................... 9
3.1 Overview .......................................................................................................................... 9
3.2 Framework........................................................................................................................ 9
3.3 Establish Context ............................................................................................................ 11
3.4 Identify Risks .................................................................................................................. 13
3.5 Analyse Risks ................................................................................................................. 15
3.6 Evaluate Risk.................................................................................................................. 17
3.7 Treat the Risk ................................................................................................................. 18
3.8 Communication and Consultation ................................................................................... 19
3.9 Monitor and Review ........................................................................................................ 19
3.10 Risk Assessment Terms and Conventions .................................................................. 21
4 Generic SCADA Assets ...................................................................................................... 22
4.1 Generic SCADA Process Model ..................................................................................... 22
4.2 Generic SCADA Enablers - Example .............................................................................. 23
5 Worked Example of Threat and Risk Assessment Framework ........................................ 24
6 Example SCADA Threat and Risk Assessment ................................................................ 26
7 Example SCADA Risk Treatment Plan (RTP) .................................................................... 33
8 Presentation of Results to Senior Management ............................................................... 43
8.1 Overview ........................................................................................................................ 43
8.2 Sample Radar Chart ....................................................................................................... 44
8.3 Sample Executive Summary Risk Status Table .............................................................. 44
9 Ongoing Monitoring and Review........................................................................................ 47
9.1 Overview ........................................................................................................................ 47
9.2 SRMF Reviews ............................................................................................................... 47
9.3 Communicating Risk Exposures ..................................................................................... 48
9.4 Risk Assessment Updates .............................................................................................. 48
Page 3 of 48
UNCLASSIFIED
Preface
SCADA systems have traditionally been viewed as being isolated and therefore
safe and less exposed to remote cyber attacks. Risk assessment and
management methodologies, correspondingly, have largely been directed at
legacy SCADA systems in which underlying protocols were designed without
modern security requirements in mind.
Recent incidents such as Aurora and Stuxnet demonstrate that a directed cyber
attack can cause physical harm to critical infrastructure. Traditional threat
sources have evolved to now include focused foreign nation cyber intrusions
and industrial espionage capabilities.
Such changes and attitudes require a new all hazards approach to risk
management one that takes into account Industrial Control Systems, IT,
Communications, physical security, supply chains and services and the
interconnection of SCADA systems with corporate, partner and service provider
networks and the Internet. Organisations are encouraged to foster a culture of
security for SCADA system management, operations and procedures.
1
The ITSEAG is part of the Trusted Information Sharing Network (TISN) for critical infrastructure
resilience which enables the owners and operators of critical infrastructure to share vital information on
security issues. The TISN consists of a number of Sector Groups (SGs) and Expert Advisory Groups
(EAGs) which are overseen by the Critical Infrastructure Advisory Council (CIAC). One of the expert
advisory groups is the ITSEAG providing advice to the TISN on IT security issues relating to critical
infrastructure. The ITSEAG consists of academic specialists, vendors and government representatives
who are leaders in the information technology/e-security field. More information on the TISN can be found
at [Link] For more information on the ITSEAG, please contact the Secretariat in the
Department of Broadband, Communications and the Digital Economy (DBCDE) on (02) 6271 1595 or
SCADA@[Link].
Page 4 of 48
UNCLASSIFIED
1 Introduction
1.1 Background
1.1.2 Sector Groups (SGs), cover key industry sectors across Australia. The IT
Security Expert Advisory Group (ITSEAG) advises all SGs on IT Security
matters affecting all industry sectors.
1.1.3 This report has been commissioned via the ITSEAGs SCADA working
group that contributes to the TISN objective of enhancing the resilience of
critical infrastructure (CI) and systems of national importance by assisting
with the assessment and implementation of security for SCADA systems
across industry sectors.
1.2 Scope
1.2.2 SCADA systems considered within the scope of the report comprise
distributed control systems designed to deliver essential and stabilising
services within the Australian economy.
Page 5 of 48
UNCLASSIFIED
Page 6 of 48
UNCLASSIFIED
1.4 References
International Critical Information Infrastructure Protection (CIIP) Handbook
2008/2009.
ISM 2012 Australian Government Information Security Manual, Defence
Signals Directorate.
Defence Signals Directorate Top 35 Mitigations July 2011.
IEC 60870.1 Telecontrol Equipment and Systems General Considerations.
IEC 60870.5 101 to 104 Telecontrol Equipment and Systems Transmission
Protocols.
AS/NZS 31000:2009 Risk Management Principles and Guidelines, Standards
Australia.
ISO/IEC 27005:2011 Information Security Risk Management, Standards
Australia.
AS/NZS ISO/IEC 27001:2006 Information Security Management systems
requirements, Standards Australia.
AS/NZS ISO/IEC 27002:2006 Code of practice for information security
management, Standards Australia.
Australian Government Protective Security Policy Framework 2010, Attorney
Generals Department, June 2010.
Australian Government Information Security Management Protocols and
guidelines 2011, Attorney Generals Department, July 2011.
System Protection Profile Industrial Control Systems, National Institute of
Standards and Technology (NIST), Version 1.0.
The Cross-Sector Roadmap for Cyber Security of Control Systems, 30
September, 2011(developed by the Industrial Control Systems Joint Working
Group (ICSJWG), with facilitation by the US Department of Homeland Securitys
National Cybersecurity Division (NCSD)).
1.5 Acknowledgements
Saltbush would like to acknowledge those who contributed to the 2012 review of
this framework:
Page 7 of 48
UNCLASSIFIED
2.1.2 In accordance with the definitions in Section 3.4, the Current Risk columns in
the Section 6 TRA will need to be updated should these values be altered.
2.1.4 Finally, the determination of information security risk exposures, and the level
to which they are reported to senior management, often results in the
confusion of security issues with technical and operational details. Section 8 of
this framework suggests a mechanism by which such information can be
summarised and presented.
Page 8 of 48
UNCLASSIFIED
3.1.1 The methodology is adopted for the generic SCADA risk management
process is detailed in the following subsections.
3.2 Framework
Page 9 of 48
UNCLASSIFIED
3.2.2 Establishment of the context for the Generic SCADA RMF involves
defining the framework scope and identifying the assets that are
potentially at risk.
Page 10 of 48
UNCLASSIFIED
3.2.5 There are two Risk Decision points that ensure sufficient and accurate
information has been obtained or that another iteration of risk assessment
or risk treatment is initiated.
3.2.6 The risk acceptance activity ensures that residual risks are explicitly
accepted by the SCADA stakeholders and senior management of the
organisation.
3.2.7 During the whole security risk management process it is important that
communication and consultation with stakeholders and operational staff
associated with the secure implementation and operation of the SCADA
system under consideration.
3.2.8 The monitor and review component of the process comprises the controls
put in place specifically to ensure that the Generic SCADA RMF operates
effectively over time.
3.3.1 The scope of the Generic SCADA RMF encompasses the core
components of a distributed SCADA network that would be expected to be
found in the majority of critical infrastructure service provider
organisations.
Data Communications
Front-End Processing
Page 11 of 48
UNCLASSIFIED
3.3.3 The assets that are likely to be threatened can therefore be derived by
considering the enablers2 that allow the identified processes in Figure 3-2
to occur.
3.3.4 These enablers can be derived by identifying the people, the places, and
the products required to ensure the processes can be carried out.
3.3.5 Each enabler is owned. The owner is the responsible authority within
operational sections of the organisation for ensuring that mitigating
controls are appropriately implemented.
3.3.6 The typical authority responsible for the enablers is contained in the
Owner column; however each organisation using this guide ultimately
determines who the responsible authority is.
3.3.7 The owner and description should be modified to suit the positions in each
organisation.
Owner Description
2
Enablers are those assets that support the delivery of in-scope business processes
Page 12 of 48
UNCLASSIFIED
3.4.1 Having identified the assets required to enable generic SCADA processing
to occur, the next activity is to identify the vulnerabilities to which each
asset is exposed.
3.4.5 The following subsections list the general categories for threat sources
that may lead to the realisation of a threat to the identified assets under
consideration.
Trusted Sources with Malicious Intent T1
3.4.6 Such sources comprise individuals or organisations with which the system
owner shares some level of trust, but wish to deliberately cause harm to
the in-scope control system.
Page 13 of 48
UNCLASSIFIED
3.4.8 Sources will generally be individuals or business partners with whom the
system owner shares some level of trust, but who unknowingly cause
harm to the in-scope system.
3.4.11 Examples could include industrial spies, hackers, activist groups, criminal
elements, foreign government agencies.
External Sources without Malicious Intent T4
3.4.12 Such sources will have neither an implied level of trust within the in-
scope assets nor the desire to cause harm to the system.
3.4.14 Such sources are usually disruptive natural events, or significant man-
made accidents such as an aircraft crash, or oil refinery explosion.
3.4.15 Examples could include fire, flood or storm and additionally the potential
effect on control system assets from dangerous goods (e.g. a nearby
chemical factory) and epidemics (bird flu, swine flu etc).
Page 14 of 48
UNCLASSIFIED
Likelihood
Likelihood Description Statements
Descriptor
Possible The event MIGHT occur at some time but is not expected.
Page 15 of 48
UNCLASSIFIED
Extended media
Supply disrupted > coverage; major Loss of operating
Permanent 2,000,000 customers government licence or
Possible loss Catastrophic impact on
Catastrophic injuries/ Major Failure to entire embarrassment or loss directors/senior
>$40M operations
deaths Grid of public support; public management charged
Black Start enquiry and convicted
Removal of CEO
Supply disrupted >
Heavy media coverage; Inquest in to business
Failure of one or more key 1,000,000 customers
Possible loss Permanent injury government resulting in an
Major organisational objectives Major Failure to parts of
$16M - $40M /stress embarrassment or loss enforcement order fine
leading to major disruption the Grid
of public support. and court conviction
Injury requiring
No threat to achievement Customer comments Likely fine or
medical treatment Supply disrupted >
Possible loss of objectives but could escalated to prosecution.
Moderate / 200,000 customers
$4M - $16M result in some moderate management; minor Administrative
long term From a single event
disruption media coverage. undertaking
incapacity.
Injury requiring Supply disrupted to <
Minor reduction in
Possible loss first aid treatment / 1000 customers for less Adverse customer Warning issued by
Minor effectiveness and
$1M - $4M temporary loss of than 1 week comments regulator
efficiency for a short period
time.
Supply disrupted to <
Negligible impact to
Possible loss Injury resulting in 100 customers for less Manageable adverse No legal or regulatory
Insignificant effectiveness and
<$1M no loss of time than 1 day customer comments consequence.
efficiency
Table 3-3 Consequence of Realisation
Page 16 of 48
UNCLASSIFIED
3.6.2 Current risk exposure, in terms of likelihood and consequence values, can be
determined using the risk matrix table below:
Consequence
Almost
Medium High High Extreme Extreme
Certain
Table 3-4 Risk Calculation Matrix
Page 17 of 48
UNCLASSIFIED
3.6.4 Risk exposure levels and responsibility for acceptance or residual risk are as
follows:
3.7.1 Once risk exposure has been determined all risks must be treated. Treatment
options include:
a) Accept: - do nothing and accept the current level of evaluated risk;
b) Avoid: - cease doing the business activity that brings about the possibility of
the threat occurring;
c) Transfer: - pass the responsibility for implementing mitigating controls to
another entity. Responsibility for threat and risk management remains the
responsibility of the organisation, and
d) Reduce: - implement controls to reduce risk to an acceptable level.
3.7.2 The risk table provided in Section 5 contains a column for recording risk
treatment. It also contains a cross-reference to the Risk Treatment Plan (RTP)
which is shown in Section 6.
3.7.3 This plan details the controls that may be used to reduce risk to an acceptable
level. Organisations may interpret these controls for their own use and
Page 18 of 48
UNCLASSIFIED
3.7.4 The RTP provides for a reassessment of risk, once controls have been
selected and implemented. The RTP can also act as a management plan to
provide a status of implementation.
3.7.5 An example work through is provided in Section 4, illustrating the process flow
used in this risk framework.
3.8.3 The manner in which this environment is implemented will be highly dependent
on the operation of each affected organisation, and is therefore considered to
be outside the scope of this report, however suggested management reporting
techniques are included in section 8.
3.9.1 The monitoring and review component needs to be implemented to ensure that:
a) Risk exposures are monitored, re-evaluated and revised as appropriate over
time;
b) Risk exposures are updated in a timely fashion in response to significant
events such as changes to the organisations operations and influencing
external events;
c) Ensuring that identified remediation controls are effective and efficient in both
design and operation;
d) Identification of emerging risks; and
e) The risk management framework itself is operating effectively.
Page 19 of 48
UNCLASSIFIED
3.9.3 The following diagram and table provides a guide to successful implementation
and ongoing effectiveness.
Plan
Design of
SRMF
Monitor and
review the SRMF
Check
SCADA
Security Risk Managed
Requirements SCADA
And expectations Security
Figure 3-3 PDCA model applied to SCADA Security Risk Management System
Page 20 of 48
UNCLASSIFIED
3.10.1 Terms
Risk levels referred to throughout this Generic SCADA RMF(and which are
recommended for use in any Security risk management plans) are:
Current Risk is the level of risk posed to system assets with existing and
implemented risk mitigation controls;
Residual Risk is the level of risk remaining after additional risk treatment.
Page 21 of 48
UNCLASSIFIED
4.1.1 The following diagram illustrates the generic nature whereby the SCADA-
related processes have been decomposed in order to implement a generic risk
management framework.
Management
SCADA Control
Assets Monitoring
People Policy
Product
Processes
Reputation
Page 22 of 48
UNCLASSIFIED
4.2.1 As partially identified in the previous subsection, the following table identifies
the enablers likely to be found in a generic SCADA system:
Category Enabler Owner Asset ID
Products
SCADA Hardware and Operating System (OS) Senior Engineer P.4
Page 23 of 48
UNCLASSIFIED
SCADA Application
Product P.3 SCADA Application that monitors and manages SCADA assets
Software
Step 3 Threat and Risk Assessment Assess risk against the threat of the Loss of Confidentiality, Availability or Integrity. This gives the Current Risk,
which is the level of risk with existing and implemented controls in place. (NB: only loss of confidentiality is demonstrated in this example.)
P.3
(SCADA Reduce
Lack of security hardening C T1,T2, T3,T4 Moderate Likely High
Application F1
Software)
Step 4 Risk Treatment Plan as the current risk rating in this example is High, treat the risk by selecting the Reduce option. How this risk reduction is
realised is detailed in the Risk Treatment Plan at C2. An extract from the RTP is provided below
Controlled Risk
Residual
Control Selection of controls to achieve objectives
Risk
Ref
Page 24 of 48
UNCLASSIFIED
To ensure software
F1 can withstand
Secure SCADA software configuration aligned with (ISO 27002), (CIP Standards) Moderate Unlikely Medium
unauthorised access
Attempts
Table 5-1: linkage between the Asset Register, TRA and RTP
Step 5 once the control can be proven to be in place, the controls are assessed for effectiveness and the risk level for that threat can be re-evaluated. In
this example, risk has been reduced from High to Medium because the likelihood has been reduced from Likely to Unlikely.
A reference to a control identified in a standard is included to demonstrate compliance and linkage to the standard.
Page 25 of 48
UNCLASSIFIED
Pr.1 Inappropriate management structure, lack of security framework, poor allocation of T1, T2, T3, Catastrop
C Likely Extreme Reduce B1
(Management security roles and responsibilities T4, T5 hic
Page 26 of 48
UNCLASSIFIED
Current Risk
Treatment
Threat Threat
Asset ID Common potential points of failure and known vulnerabilities Option &
Type sources Con- Likeli- Risk
reference
sequence hood Rating
Control & Ineffective change/configuration/release management introduction of unapproved, T1, T2, T3,
Feedback) untested hardware or software T4, T5
Ineffective management forum/committee, limited stakeholder participation or
T1, T2, T3,
leadership, poor corrective and preventative actions for security issues, increased
T4, T5
severity of incidents
Ineffective or lack of defined service level agreements (SLAs) with business owners, T1, T2, T3,
ICT Teams and service providers T4, T5
Catastrop
Incident management poor evidence gathering, preservation and inability to identify I T1, T2, T3, Likely Extreme Reduce B2
hic
that a compromise has actually occurred T4, T5
Business functionality driven initiatives verses security - introduce vulnerable systems
T1, T2
and applications
T1, T2, T3,
Failure in duty of care, lack of security policy and direction
T4, T5
Project management lack of security and/or system considerations during project
T1, T2, T3,
planning, implementation, operation and review resulting in avoidable issues and/or
T4, T5
incidents
Business Continuity Management (BCM) lack of resiliency and redundancy, lack of Catastrop
A T1, T2, T3, Likely Extreme Reduce B3
identification of Maximum Acceptable Outage, Recovery Point Objectives, Recovery hic
T4, T5
Time Objectives resulting in variable business continuity responses
Ineffective and/or one-way communication no security committee to manage and T1, T2, T3,
provide oversight of security T4, T5
Degraded security environment through site isolation C T1, T2 Minor Possible Medium Reduce C1
Vandalism T1, T2
P.1 Poor maintenance I T1, T2 Minor Possible Medium Reduce C2
Building / Site Environmental disaster T1, T2
Natural disaster T1, T2
A Moderate Unlikely Medium Reduce C3
DR process failure T1, T2
Page 27 of 48
UNCLASSIFIED
Current Risk
Treatment
Threat Threat
Asset ID Common potential points of failure and known vulnerabilities Option &
Type sources Con- Likeli- Risk
reference
sequence hood Rating
Page 28 of 48
UNCLASSIFIED
Current Risk
Treatment
Threat Threat
Asset ID Common potential points of failure and known vulnerabilities Option &
Type sources Con- Likeli- Risk
reference
sequence hood Rating
Page 29 of 48
UNCLASSIFIED
Current Risk
Treatment
Threat Threat
Asset ID Common potential points of failure and known vulnerabilities Option &
Type sources Con- Likeli- Risk
reference
sequence hood Rating
Page 30 of 48
UNCLASSIFIED
Current Risk
Treatment
Threat Threat
Asset ID Common potential points of failure and known vulnerabilities Option &
Type sources Con- Likeli- Risk
reference
sequence hood Rating
Devices Open access security issues including access back to central systems
T1, T2
Default security configuration retention of default user names and passwords T1, T2
Lack of security hardening also inability to security harden T1, T2
As for SCADA HW, SW App
T1, T2
Introduction of open technology field devices (inc unstable operating Systems, less
T1, T2
robust hardware)
As for SCADA HW, SW App
T1, T2
Page 31 of 48
UNCLASSIFIED
Current Risk
Treatment
Threat Threat
Asset ID Common potential points of failure and known vulnerabilities Option &
Type sources Con- Likeli- Risk
reference
sequence hood Rating
Page 32 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
Page 33 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
and account use is within the information security policy requirements. (ISO 27002 Section 11.2 User
access management).
Defined Entry and Exit procedures.
Different levels of briefing/interviews depending on the job performed. Exit interviews are particularly
important for staff & management in operational areas (ISO 27001 8.3 Termination or change of
employment, ISM Personnel Security).
Fully documented operating procedures.
Operating procedures should be in place to supplement training and reduce the risk of accidents.
To ensure that Training environments should be established to support learning objectives (ISO 27001 10.1
A3
appropriate resources are Operational procedures and responsibilities, ISM System Security Plans, Standard Operating
People Moderate Unlikely Medium
available to manage and Procedures).
Availability rd
operate SCADA systems Implement a combination of resource types including contractors, 3 parties.
Have a different type of resource to backup primary resourcing.
Implement cross-skilling for critical areas.
Develop Security Framework set security direction, objectives, allocate roles and responsibilities,
reporting requirements, steering committee to provide oversight of security (ISO27001 Section 4.2.1).
B1 Establish a data classification schema - (ISO 27002 7.2 Information Classification, ISM Media
Management Security)
Control & To control SCADA Develop and implement change and configuration management process ISO27001 12.5.1 change Minor Unlikely Low
Feedback Management information control procedures. - (ITIL Change Management), NIST 800-128.
Confidentiality
Formal procedures for publication of SCADA management information.
Information is often incorrectly published to web sites when it should be for internal use only often as
a result of confusing internal unclassified documents with information intended for the general public
-.(ISO 27001 Section 7.2 Information Classification).
B2 To provide correct and Controlled repository for SCADA related information.
Management controlled access to An information/knowledge management system may assist with achieving a controlled and secure
Control & SCADA information storage - (ISO 27002 Section 10.1.1 Documented operating procedures). Minor Unlikely Low
Feedback To provide incident Formal Incident response and readiness procedures are developed and implemented - NIST SP800-
Integrity response and readiness 61 Incident handling guide.
Page 34 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
processes Forensic readiness is the ability of an organisation to maximise its evidence collection capability whilst
minimising the cost of doing so. (draft ISO 27037 identification, collection, acquisition and preservation
of digital evidence) (Aus Standards HB 171 Management of IT Evidence)
To provide competent Documented Management Outcomes
and effective These should be endorsed with executive support (ISO 27002 Section 6 Organisation of Information
management support Security)
Establish Key Performance Indicators for Management
To assess management
These should be reportable, repeatable and achievable (ISO 27001 Section Management review of
effectiveness
the Information Management System ISMS) (ISO 27001 Section 0.2b)
Approved and documented Roles and Responsibilities for Management (ISO 27001 Management
To ensure that required Responsibility) (ISM Roles and Responsibilities)
B3 management controls are Approved Management Framework and Charter
Management defined Quality Management procedures provide guidance on how a management framework should function
Control &
(ISO 27001 Section 4.2 Establishing and managing ISMS) Moderate Unlikely Medium
Feedback
Availability To provide dedicated and
Documented SCADA management policies and procedures
effective Management
These document should be brief and not change significantly over time (ISO 27001 Section 4.3
support for SCADA
Documentation Requirements) (ISM Information Security Documentation)
systems
Equipment site standards for remote devices
C1 To prevent compromise
Suitable racks/cabinets may be identified for remote servers/switches. Do not allow unprotected, live
Building / Site of assets and interruption Minor Unlikely Low
network access points (ISO 27002 Section 9 Physical and Environmental Security) (ISM Physical
Confidentiality to business activities
Security)
Disaster Recovery and Business Continuity Plans
C2
To minimise impact of These site specific strategies should be aligned with the whole of organisation DR strategy
Building / Site Minor Unlikely Low
Site loss and damage (ISO 27002 Sections 13 Security Incident Management, 14 Business Continuity Management) (ISM
Integrity
Incident Response and Emergency Procedures)
C3 To prevent loss of assets Defined security perimeters
Building / Site and interruption to Restrict access to sites do not allow broad access simply for convenience (ISO 27002 Section 9 Moderate Unlikely Medium
Availability SCADA operations Physical and Environmental Security) (ISM Physical Security)
Page 35 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
Page 36 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
Information availability of information Often only certain types of systems are backed up. Organisations should ensure that ALL critical
Management processing information is backed up and that effectiveness is tested on a regular basis (ISO 27002 10.5
Availability Backup)
Capacity monitoring and forecasting
Network monitoring and service delivery reports from vendors may effectively provide these
controls(ISO 27002 10.3.1 Capacity Management)
Change Management
All SCADA systems, applications and communications infrastructure should be subject to formal
change management control (ISO 27002 Change Management Sections10.1.2, 12.5.1, 13.2) (ITIL
Change Management)
Encrypt transmission of SCADA information
E1 To protect the Ensure that appropriate encryption protocols are applied (ISM Cryptography, ISO 27001 Section
Communications transmission of SCADA 12.3 Cryptographic controls, NIST FIP Encryption Standards)
Minor Unlikely Low
& Networks information broadcast Perform vulnerability assessments on a periodic basis on all access points into the SCADA network
Confidentiality over Public Networks Regular scenarios should be defined and tested to identify network vulnerabilities (ISO 27002 12.6
Technical Vulnerability Management, (ISM Vulnerability Management)
E2
Communications To verify SCADA network
Deploy network monitoring services to identify and localise network trouble spots Moderate Unlikely Medium
& Networks configurations
Integrity
E3 For key services, route communications lines via multiple exchanges / mediums
Communications To maintain SCADA Deploy intelligent networking devices to handle peak loads Moderate Unlikely Medium
& Networks network connectivity Routing devices and modern switching equipment can be tailored to meet specific load patterns and
Availability provide alerts for unusual activity
F1 To ensure that such Secure SCADA software configuration
SCADA software utilises Where possible, computerised systems should be hardened to minimise the opportunity for
Application recognised best practice unauthorised access. Hardening should also ensure that any vendor application software support is Moderate Unlikely Medium
Software security mechanisms and maintained throughout the life of the product whilst the underlying system is hardened.
Confidentiality is able to withstand Access control mechanisms should also exist to ensure that centralised system access controls are
Page 37 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
unauthorised access protected in accordance with corporate password and account usage policies.
attempts. Minimisation of user access rights
Users should only be granted the minimum access required in order to perform their duties. Such
access, and the functionality assigned to SCADA system roles, should also be regularly reviewed and
updated. (ISO 27002 Section Access Control)
Logging of access attempts and user actions - All access attempts, whether they are successful or not,
should be logged to a protected audit trail.
The audit trail should be regularly backed up and kept as long term evidence (12mths) to prevent
erasure or tampering of evidence.
In addition, significant activities (such as the changing of state of SCADA devices and updates to
access lists) should also be logged. (ISO 27002 Section 10.10 Monitoring)
The audit trail should be periodically reviewed for suspicious activity.
It is desirable that suspicious activity be alerted to operational personnel in near real-time.
Implement patch management process (DSD 35 Mitigations, ISO 27001 Section 12.6 Technical
vulnerability management, ISM - Vulnerability Management)
Vendor support arrangements
Contractual arrangements should be in place with the software vendor to ensure that:
F2 Software patches are made available in a timely manner
SCADA To maintain the correct Support arrangements such as subcontracting and off-shoring do not occur without the agreement of
Application operation of the software all contracted parties Major Unlikely Medium
Software over time. The customer is to be notified of any takeover or merger activities that may affect the level or manner
Integrity in which the vendor support arrangements are provided (ISO 27002 Section 6.2 External Parties)
Critical software escrow arrangements
Where a SCADA system comprises a vendor-specific software package, an escrow agreement should
be entered into with the vendor to ensure product availability should the vendor organisation fail to be
able to support the product into the future. (ISO 27002 Section 10.8.2 Exchange agreements)
F3 Capacity planning
SCADA SCADA systems should be designed to provide scalability for future growth and information storage
Major Unlikely Medium
Application requirements. Collection and retention of audit trails should also be addressed.
Software (ISO 27002 Section 10.3.1 Capacity Management)
Page 38 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
Page 39 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
Hardware SCADA computing state, and that changes are appropriately analysed, tested and authorised.
including platform is in a known
operating and approved state. Vendor support arrangements
System Contractual support arrangements should be in place with the SCADA software vendor to ensure that
Integrity timely installation of security patches to supported hardware and OS is possible.
System redundancy
Critical system components should be designed to withstand single points of failure.
Business Continuity Plans (and/or if necessary, Disaster Recovery Plans) should be updated and
tested to ensure that systems are able to withstand loss of single physical, personnel and procedural
dependencies.
Spares holdings
Adequate spares should be held (or covered by vendor support arrangements) for timely recovery
from component failures.
Protection against malware
Antivirus measures should be implemented on SCADA networks as they would with other corporate IT
G3 To ensure that the
environments.
SCADA SCADA computing
Malware protection should be applied and updated in a timely manner on SCADA server, FEP, field
Hardware platform is reliable in the
device and workstation platforms.
including event of component Moderate Possible High
NOTE: it is becoming increasingly common to find field devices operating via well-known operating
operating failure, environmental
systems. Any virus attack on the system can therefore also have major repercussions on field devices
System disturbance, or attempted
and they should therefore be brought into the corporate AV regime.
Availability malicious disruption.
ISO 27002 Section 10.4 Protection against malicious and mobile code
Page 40 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
Practitioners Guide to Business Continuity Management, ISM Business Continuity and Disaster
Recovery)
Encrypted data communications
Where communications with field devices occurs over a communications line susceptible to external
interception and / or compromise, information should be encrypted to minimise the opportunity for
H1 external parties to compromise the communications channel. (ISO 27002 Section 12.3
To prevent unauthorised Cryptographic Controls, ISM Section Cryptography, NIST FIPS encryption standards)
SCADA Field
monitoring and control of Moderate Unlikely Medium
Devices Deactivation of default configuration accounts where technically feasible default configuration
these devices.
Confidentiality accounts should be deactivated
Private communications channels
Where possible, sensitive communications with field devices should be performed over dedicated
leased-line services rather than using a public communications infrastructure.
H2
To ensure that these Periodic device polling
SCADA Field
devices are in a stable Field devices should be periodically polled to ensure that their status is verified to the central control Minor Unlikely Low
Devices
and known state system and, if necessary, that discrepancies are investigated and verified.
Integrity
Device maintenance
A maintenance regime should be in place to ensure that all peripheral devices are regularly tested
H3 To ensure that these
SCADA Field devices can be monitored Alternate communications channels
Critical field establishments and devices should be connected to the SCADA system via redundant Moderate Unlikely Medium
Devices and controlled as
Availability required. communications channels.
The central control station should also be configured such that it has control over the communications
channel(s) available to the field device. (ISO 27002 9.2.2 Supporting utilities)
I1 To ensure that power
Backup power source
Supporting failures do not lead to a
Critical system components should be fed through both mains and backup power supplies. (ISO Minor Rare Low
Utilities security compromise of
27002 9.2.2 Supporting utilities)
Confidentiality the SCADA system.
I2 To ensure that SCADA Backup power source
Moderate Unlikely Medium
Supporting systems operate as A medium-to-long term power supply alternative (such as a long term diesel power unit) should be
Page 41 of 48
UNCLASSIFIED
Controlled Risk
Residual
Selection of controls to achieve objectives
Risk
Ref Control Objectives
(Control Reference) Con- Likeli-
sequence hood
Utilities expected during power available to power critical SCADA system components during power interruptions.
Integrity supply disruptions. Should core SCADA components be installed in dedicated control environments, power supply should
also be capable of powering support environments such as air conditioning and fire detection. (ISO
27002 9.2.2 Supporting utilities)
Power conditioning
System-critical devices should be connected to a conditioned and uninterruptible power supply.(ISO
27002 9.2.2 Supporting utilities)
Backup power source
Critical system components should be fed through both mains and backup power supplies.(ISO 27002
9.2.2 Supporting utilities)
Redundant control centres
There should be redundancy built into centralised control sites to mitigate against damage to, or loss
I3 of availability of, critical establishments.(ISO 27001 Section 14 Business Continuity)
To prevent disruption to
Supporting
SCADA operations during Contingency planning Major Unlikely Medium
Utilities
power failure conditions. Contingency plans should ensure that centralised services can be transitioned to alternative
Availability arrangements during such interruptions and be able to be transitioned back into service once central
sites are restored to normal operations. (ISO 27001 Section 14 Business Continuity)
Disaster recovery testing
Contingency plans should be tested periodically. Where a physical failover test is not able to be
performed, formal scenario testing should be undertaken, with results and lessons learned
documented, analysed and actioned as appropriate. (ISO 27001 Section 14 Business Continuity)
Page 42 of 48
UNCLASSIFIED
8.1.3 A number of organisations already use a traffic light approach to present such
data to senior management, where each risk is assigned a green, amber or red
status depending on the current health of risk management measures.
8.1.4 The following subsection presents the use of a radar chart to display risk
management status to an organisations senior management. It can be a
highly effective mechanism in cases where identified SCADA process enablers
are not overly complex and it has a number of advantages as follows:
The entire risk management story is presented via a single graphic
diagram
It is easy to explain and intuitive to understand
It can be used to show risk management progress over time by including
historical data to demonstrate the organisations risk profile over time.
[Link] The radar chart is a standard Microsoft charting option. Applications such as
PowerPoint or Visio can be used to create the background colour scheme
onto which the chart can be overlayed for presentation purposes.
Page 43 of 48
UNCLASSIFIED
8.2.1 Figure 8-1 provides a sample radar chart based on the enablers identified in
this report and arbitrary treated risk exposure data.
8.3.1 Table 8-1 provides a sample executive risk status obtained by taking the
highest likelihood and consequence from each enabler as a high level overview
It should be noted that the colour in the current columns refer to the current
level of risk described in section 3.10.2 Conventions Risk Assessment
The colour in the controlled columns refers to the effective implementation of
controls documented see section 3.10.3 Conventions Risk Treatment
Plan.
Page 44 of 48
UNCLASSIFIED
Users and
Operators
Information Buildings
Management and Sites
SCADA
Power Supply
Software
Page 45 of 48
UNCLASSIFIED
Asset
Treatment
Consequence Likelihood Risk Rating Consequence Likelihood Risk Rating
Option
Pe.1 - People Moderate Almost Certain High Reduce A1-3 Moderate Unlikely Medium
Pr.1 - Management Control & Catastrophic Likely Extreme Reduce B1-3 Moderate Unlikely Medium
Feedback
P.1 - Building Site Moderate Possible Medium Reduce C1-3 Moderate Unlikely Medium
Pr.2 - Information Management Moderate Almost Certain High Reduce D1-3 Moderate Unlikely Medium
P.2 - Communication & Networks Moderate Almost Certain Very High Reduce E1-3 Moderate Unlikely Medium
P.3 - SCADA Application Software Major Likely High Reduce F1-3 Major Unlikely Medium
P.4 - SCADA Hardware including Moderate Almost Certain High Reduce G1-3 Moderate Possible High
Operating System
P.5 - SCADA Field Devices Moderate Likely High Reduce H1-3 Moderate Unlikely Medium
P.6 - Supporting Utilities Major Likely High Reduce I1-3 Major Unlikely Medium
Page 46 of 48
UNCLASSIFIED
9.1.1 The effectiveness of a risk management approach is dependent not only on the
methodology applied to the development of risk assessment data, but also on
its continued update as influencing factors change over time.
9.1.4 The subsections to follow indicate measures that are likely to contribute to the
ongoing effectiveness of the SCADA Risk Management Framework.
9.2.1 The overall SCADA Security Risk Management Framework should be reviewed
over time to ensure that it functions effectively. Measures that can be
undertaken to assist in this activity include, but are not necessarily limited to,
the following:
Internal process reviews
External (independent) process reviews and audits
Implementation of Key Performance Indicators (KPIs) designed to monitor
SRMF processes.
Page 47 of 48
UNCLASSIFIED
9.3.1 Having measured corporate risk exposures associated with the operation of the
SCADA system(s), Section 8 of this document provides a suggested
management reporting tool.
9.4.1 As noted, both the internal and external threat environment is likely to change
over time.
9.4.2 To maintain the currency of RMF deliverable(s), a program should be put into
place to:
Trigger a refresh at defined intervals (e.g. annually).
Allow the risk environment to be re-evaluated in response to defining
changes (e.g. the introduction of new technologies or the emergence of a
significant external threat source).
Page 48 of 48









