0% found this document useful (0 votes)
14 views7 pages

ICS Governance and Security Compliance

The document discusses the governance, risk management, and compliance (GRC) in Industrial Control Systems (ICS), emphasizing the alignment of security strategies with business objectives and regulatory requirements. It outlines the importance of standards and policies in enhancing safety and performance, particularly in the energy sector, and details configuration management practices to control modifications in ICS environments. Additionally, it highlights the challenges faced in maintaining physical and logical security, including the need for disaster recovery plans and careful management of updates.

Uploaded by

Waqar Roy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views7 pages

ICS Governance and Security Compliance

The document discusses the governance, risk management, and compliance (GRC) in Industrial Control Systems (ICS), emphasizing the alignment of security strategies with business objectives and regulatory requirements. It outlines the importance of standards and policies in enhancing safety and performance, particularly in the energy sector, and details configuration management practices to control modifications in ICS environments. Additionally, it highlights the challenges faced in maintaining physical and logical security, including the need for disaster recovery plans and careful management of updates.

Uploaded by

Waqar Roy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

ICS Operational Environment​​ ​ ​ ​ ​ By Raed Ahsan

Section 1: Governance, Risk, and


Compliance:
What is Governance in ICS?

A)​ The process of establishing and maintaining a framework and supporting management
structure…to provide assurance that information security strategies are aligned with and
support business objectives, are consistent with applicable laws and regulations,… and
provide assignment of responsibility, all in an effort to manage risk - NIST-SP-800-100


Image credit to Infosec for providing components of governance.

For accomplishing governance in ICS, there are a few components that the implementor or the
person/team responsible for GRC needs to follow and consider.

The Governance of ICS is similar to the governance of IT: Both need to be aligned with the
business goals before the final implementation.

The only difference is that ICS governance does not force cybersecurity unless it is mandated
by the government regulations

1
ICS Operational Environment​​ ​ ​ ​ ​ By Raed Ahsan

Risk Management in ICS.

Risk management in ICS ensures that an organization has security assets and resources
aligned to address any risk that could adversely impact the organizational activities and also
supporting business goals.

The primary concerns to be addressed in risk management within an ICS environment:


●​ Human Safety
●​ Regulatory Compliance
●​ Environmental Safety
●​ Loss of equipment
●​ Loss of intellectual property
●​ Loss or damage to products

Any security measure that impairs safety is unacceptable.

Compliance in ICS:

Compliance in ICS security focuses on ensuring that organizational activities are performed in
accordance with the laws and regulations that pertain to those ICS environments.

ICS security compliance depends on the business sectors in which the industry operates.

2
ICS Operational Environment​​ ​ ​ ​ ​ By Raed Ahsan

Feel free to research each of the organizations and how they align with ICS for your better
understanding, as there can be much information that gets interconnected with each other.

Section 2: ICS Policies and Standards:


International Society of Automation (ISA) definition of standard:

“A set of characteristics or quantities that describes features of a product, process, service,


interface, or material.”

Benefits of Standards:
●​ Increases safety
●​ Improves performance
●​ Saves time and money
●​ Enables interchangeability
●​ Reduces downtime

3
ICS Operational Environment​​ ​ ​ ​ ​ By Raed Ahsan

Specific to the energy sector, the mandated governance for ICS can be found in NERC CIP:

It provides 11 security standards for the bulk electric system.

Policies are standards in action.

Across all different industries, some of the widely used policies:


●​ Physical Security
●​ Incident Response
●​ Business Continuity

4
ICS Operational Environment​​ ​ ​ ​ ​ By Raed Ahsan

●​ Configuration Management

Physical security is the first line of defense against unauthorized access.

Section 3: Configuration Management:


It involves policies and procedures written to control modifications to hardware, firmware,
software, and documents. It enables organizations to prevent improper modifications of any of
the components being used in the ICS environment.

ICS-specific management and guidance can be found in NIST-SP-800-82. The security


controls for security management can be found in NIST-SP-800-53. It provides all the
details for maintaining, monitoring, and documenting configuration management
controls and changes.

Testing any valuation of restricted access settings should be performed before setting the
maximum allowed restriction setting to ensure it doesn’t impede the ICS security controls
requirements.
(Most controls are written for a traditional ICS environment because most HMIs, PLCs, and data
historians run on traditional or legacy systems of Windows or Linux.)

There must be an intact change management plan to ensure any changes to the security
controls in the ICS environment are correctly done, and are in compliance with the security
requirements mentioned in the documentations.

5
ICS Operational Environment​​ ​ ​ ​ ​ By Raed Ahsan

These are the four phases of ICS Security Configuration Management.


There must be a component inventory in the ICS environment to clear document the asset,
the owner, details, version, location, and protocol being used with that component.

Section 4: Physical and Logical


Challenges:

​ ​ ​ ​ ​ Credit: infosec ICS/OT

Production speed, efficiency, and quality can be overwhelming when being pressured by the
management.

6
ICS Operational Environment​​ ​ ​ ​ ​ By Raed Ahsan

Vendors can also upgrade, close down, or move themselves to another location, with newer
domains being focused. So, relying on just a single one can be really tough to handle in the
future if any of the cases mentioned above happen.
Disaster Recovery of network devices like switches and routers is easy, as they can be
replaced with new ones. But, in the case of PLCs, RTUs, HMIs, and other devices that play a
vital role in the processing and operation of the ICS, it can be difficult to recover them. A good
practice is to have a spare of each device to reduce downtime of the operation.
Updates are really tough in ICS, but if it’s really crucial, then they must be thoroughly tested and
revised before the final implementation.

Common questions

Powered by AI

Governance strategies in ICS are aligned with business objectives by establishing and maintaining a framework that supports business strategies, ensuring compliance with applicable laws and regulations, and assigning responsibilities appropriately. Unlike IT governance, ICS governance does not inherently mandate cybersecurity unless required by governmental regulations, thus differentiating it from IT governance .

Compliance in ICS varies across different business sectors because each sector is subject to specific laws and regulations that dictate compliance requirements. It is important because it ensures that organizational activities are conducted legally and ethically, reducing risks of legal penalties and enhancing safety and security .

Standards in ICS provide several benefits including increased safety, improved performance, time and money savings, interchangeability, and reduced downtime. The International Society of Automation (ISA) is noted for defining these standards as a set of characteristics or quantities that describe features of various elements .

Configuration management is crucial in ICS environments to control modifications to hardware, firmware, software, and documents, thereby preventing improper changes that could affect system integrity. NIST-SP-800-82 and NIST-SP-800-53 are recommended guides that provide detailed instructions for maintaining and documenting configuration management controls and changes .

In the energy sector, NERC CIP influences ICS governance by providing 11 mandatory security standards that ensure the security and reliability of the bulk electric system .

Physical security serves as the first line of defense against unauthorized access in ICS environments. It forms a critical component of security policies, ensuring that physical access to sensitive ICS components and data is controlled and monitored to prevent breaches .

Risks associated with relying on a single vendor for ICS components include the potential for vendors to upgrade, close down, or relocate, which could disrupt operations. To mitigate these risks, it is suggested to not solely depend on one vendor and to maintain a spare inventory of critical devices to ensure continuous operation without significant downtime .

To effectively manage physical and logical challenges in ICS, it is crucial to maintain production speed, efficiency, and quality under pressure from management. Ensuring availability of spare devices to reduce downtime and thoroughly testing updates before implementation are recommended measures to manage these challenges .

Having a component inventory in ICS configuration management is significant because it provides a clear documentation of every component, including the asset details, owner, version, location, and protocol. This enables efficient monitoring, management, and compliance with security measures, enhancing overall system security and operational efficiency .

The primary concerns addressed in risk management for an ICS environment include ensuring human safety, maintaining regulatory compliance, safeguarding environmental safety, and preventing the loss or damage to equipment, intellectual property, and products .

You might also like