0% found this document useful (0 votes)
21 views17 pages

NCA OT Cybersecurity Controls Overview

The report outlines Trend Micro's compliance with the National Cybersecurity Authority's Operational Technology Cybersecurity Controls (OTCC-1:2022) to enhance cybersecurity for critical infrastructure in Saudi Arabia. It details the guidelines and controls set by the NCA and how Trend Micro's solutions align with these requirements to protect operational technology from cyber threats. The document emphasizes the importance of asset management, system protection, network security, and mobile device security in maintaining a secure OT environment.

Uploaded by

Ayman Edrees
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views17 pages

NCA OT Cybersecurity Controls Overview

The report outlines Trend Micro's compliance with the National Cybersecurity Authority's Operational Technology Cybersecurity Controls (OTCC-1:2022) to enhance cybersecurity for critical infrastructure in Saudi Arabia. It details the guidelines and controls set by the NCA and how Trend Micro's solutions align with these requirements to protect operational technology from cyber threats. The document emphasizes the importance of asset management, system protection, network security, and mobile device security in maintaining a secure OT environment.

Uploaded by

Ayman Edrees
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

General Report

Compliance Report
Trend Micro Solution Mapping Guide to the KSA NCA
Operational Technology Cybersecurity Controls (OTCC-1:2022)

February, 2023
Trend Micro
Contents

01 Executive Summary ..................................................... 03

02 Introduction ..................................................................... 04

03 NCA’s OTCC Key


Guidelines and Controls ............................................ 05

04 Trend Micro Technology


Coverage Summary ..................................................... 16

05 Deployment Scenarios ................................................ 16

06 Conclusion ......................................................................... 17
Executive Summary
With over 30 years of experience, Trend Micro is a global leader in providing security software that
protects organization from the threats can affect their exchanging digital information. Trend Micro
solutions help prevent unauthorized access to the Internet, protect mobile devices, endpoints,
gateways, servers and IOT. With its innovative technology, Trend Micro can help organizations to
protect their end users and their sensitive data from the threats that can affect their digital lives. These
solutions can be deployed and managed with ease, and they can help protect their manufacturer’s,
healthcare, Oil&Gas and organization from targeted attacks.

The solutions offered by Trend Micro are designed to meet various goals, such as increasing the return
on investment, providing a secure and easy-to-manage infrastructure, and improving the security
management of an organization. These offerings are not limited to the features of the products alone,
but also include other features such as support and reporting.

Trend Micro can help organizations


reduce their security overhead and
improve their management. It can also
help them resolve their most challenging
security issues faster by delivering
real-time protection for both the network
& endpoints. These solutions are
designed to integrate with the various
assets that are commonly used in OT
infrastructure, such as the multiple
layers of OT security & management.

Page 3 of 17 Compliance Report


Introduction
Operational Technology (OT) is critical piece of infrastructure that is essential to maintain continuous
operations in any large organization. These systems require regular maintenance and periodic updates
to their hardware, software, and other underlying components to ensure that they continue running
smoothly and are protected from potential security vulnerabilities. Given the highly sensitive nature of
the data these systems contain and the significant risks they pose to organizations if their security is
compromised, it is critical to take the proper steps to properly secure OT infrastructure.

Firstly, one of the most important steps that an organization can take to ensure that OT infrastructure
is properly secured is to gain visibility and control over the systems and devices that they use to access
them (such as laptops, mobile devices, machines, and workstations).

Secondly, when organization can identify any potential vulnerabilities in the system that could be
exploited by hackers or criminals in order to gain access to sensitive information and compromise the
security of the system. Once these vulnerabilities are identified, they can be shield through the
implementation of any necessary patches or other remediation measures. This is helps to detect any
previously known or unknown vulnerabilities that could expose the organization to additional risk in the
future.

Thirdly, in addition to performing regular security checkup, organizations should also implement
policies and best practices that are designed to reduce the risk of unauthorized access to their systems.
The key policies and procedures should be implemented in order to ensure that systems are adequately
protected on an ongoing basis. Policies should include guidelines for the use of systems such as
encryption to prevent unauthorized access to sensitive data and ensure compliance with industry best
practices.

Finally, The National Cybersecurity Authority “NCA” has developed the Operational Technology
Cybersecurity Controls (OTCC – 1: 2022) to set proper guidelines and controls to audit procedures can
help organizations ensure that their OT infrastructure is properly secured.

Page 4 of 17 Compliance Report


NCA’s OTCC Key Guidelines
and Controls
The National Cybersecurity Authority “NCA” has developed the Operational Technology Cybersecurity
Controls (OTCC – 1: 2022) to set the minimum cybersecurity requirements based on best practices and
standards to minimize the cybersecurity risks to the OT/ICS environments in order to increase the
protection of critical infrastructures that operates or depends on these systems with accordance to
international best practices.

The following points highlight the alignment between NCA’s OTCC key guidelines & controls, and Trend
Micro’s respective solutions:

Cybersecurity Defense
2-1 Asset Management Trend Micro Product Coverage

Objective: To ensure that the organization


has an accurate & detailed inventory of
OT/ICS assets in order to support the
organization’s cybersecurity and operational
requirements to maintain the production
uptime, safe operations, confidentiality,
integrity, and availability of OT/ICS assets.

2-1-1 2-1-1-2 Automated solution to collect asset inventory TXOne OT Defense Console - ODC gives
information must be utilized. clear visibility of all installed ICS assets in
the OT environment and how they’re
connected, as well as giving users vision
of the shadow OT environment.

TXOne Portable Security - Collects a


detailed snapshot of asset data including
computer information, Windows Update
status, and application lists.

TXOne EdgeFire - Operate with a high


level of asset visibility using passive asset
identification and IT/OT traffic
communication within OT networks

TXOne StellarOne - ICS application


inventory informed by OT vendors

Page 5 of 17 Compliance Report


Cybersecurity Defense
2-3 System and Processing Facilities Protection Trend Micro Product Coverage
Objective: To ensure the protection of
OT/ICS systems and processing facilities
(including workstations, servers, and Safety
Instrumented Systems “SIS”) against
cyber risks.

2-3-1 2-3-1-1 Advanced, up-to-date protection TXOne StellarOne - Industrial-Grade


mechanisms and techniques must be Next-Generation Antivirus for OT
utilized and securely managed to block and - application lock down to prevent
protect from malware, Advanced Persistent unauthorized operations and executions
Threats (APT), malicious files, and activities.
TXOne EdgeIPS Pro - support Antivirus
scan on-the-fly over network

2-3-1-6 Application whitelisting techniques or TXOne StellarOne - prevent


other similar techniques must be deployed unauthorized execution if application is
to limit the applications that are allowed to not in the approved list to limit the
run in OT/ICS environment. applications that are allowed to run in
OT/ICS environment

2-3-1-7 OT/ICS assets must be managed through TXOne EdgeIPS - support OT-aware
dedicated, segmented and hardened segmentation, to enforce only allow EWS
Engineering Workstation (EWS) and and HMI to access OT/ICS assets
information system
Human-Machine Interface (HMI) for
management purposes & maintenance.

2-3-1-8 External storage media is scanned and TXOne StellarOne - Industrial-Grade


analyzed against malware and APT. The Next-Generation Antivirus for OT
scan must be executed in an isolated and TXOne StellarOne & TMPS3 - support
secure environment. network drive and removable media
malware scan. Customer can map NAS
folder to a designated inspection host
and deploy EdgeIPS to build up a SECURE
ZONE for this purpose.

2-3-1-9 Usage of external storage media in the TXOne StellarOne - Industrial-Grade


production environment must be restricted Next-Generation Antivirus for OT provides
unless secure mechanisms for data transfer USB device trust listing
are developed and properly implemented.
TXOne Portable Security 3 Pro - provide
a secure store to carry sensitive data. And
leverage StellarProtect to limit specify
USB can used for data carry.

Page 6 of 17 Compliance Report


Cybersecurity Defense
TXOne EdgeIPS - support enforce
that only allow specify source, secure
protocol to access NAS or other
network remote media.

2-3-1 2-3-1-10 Systems’ logs and critical files must be TXOne StellarOne - write protection
protected from unauthorized access, helps secure the critical data or
tampering, illegitimate modification configuration or files from unthorization
and/or deletion. overwritten.

2-3-1-11 Unauthorized applications, scripts, TXOne StellarOne - prevent


tasks, and changes must be unauthorized execution if application is
detected and analyzed. not in the approved list.
- can help administrators review recorded
scripts execution to build up approved
operations
- prevent fileless attack and script type
attack

2-3-1-12 New communications sessions and TXOne StellarOne - Operations Behavior


commands execution must be Anomaly Detection
detected and analyzed.

2-3-1-13 Direct communications between the TXOne EdgeFire - Industrial Next


OT/ICS environment and external hosts Generation Firewall for OT
must be detected and analyzed. Segment networks and isolate
connectivity both to and between
facilities as well as production zones.

2-4 Networks Security Management Trend Micro Product Coverage


Objective: To ensure the protection of the
organization’s OT/ICS networks from cyber
risks.

In addition to subcontrols in ECC control 2-5-3


(Below controls), cybersecurity requirements for
network security management in OT/ICS
environment must cover, at a minimum, the
2-4-1 main control in OTCC:

ECC Management and restrictions on network TXOne EdgeIPS and EdgeFire -


2-5-3-5 services, protocols and ports. Industrial Next Generation Firewall for
OT Segment networks & isolate
connectivity both to and between
facilities as well as production zones.

Page 7 of 17 Compliance Report


Cybersecurity Defense
(IT environment) Trend Micro Network
ECC Intrusion Prevention Systems (IPS).
Security blocks network exploits & detect
2-5-3-6 potential breaches
•TippingPoint IPS

(OT environment) TXOne EdgeIPS and


EdgeIPS Pro - Protect vulnerable
unpatched devices & legacy systems.

ECC Secure management and protection of Trend Micro Breach Detection System
2-5-3-6 Internet browsing channel against Advanced identifies suspicious activities that may
Persistent Threats (APT), which normally lead to data loss risk:
utilize zero-day viruses and malware. •Deep Discovery Inspector
•Deep Discovery Analyzer
•Deep Discovery Director & Network
Analytics

2-4-1-1 OT/ICS environment must be TXOne EdgeIPS / EdgeFire -


segmented logically or physically from Industrial Next Generation Firewall & IPS
other environments or networks. for OT Segment networks and isolate
connectivity both to and between
facilities as well as production zones.

2-4-1-2 Different zones within the OT/ICS TXOne EdgeIPS / EdgeFire - Industrial
environment must be segmented logically Next Generation Firewall for OT Segment
or physically in accordance with the zone’s networks and isolate connectivity both to
ap- propriate level that isolates data flows and between facilities as well as
and directs traffic to "Choke Points”. production zones.

2-4-1-3 Safety Instrumented Systems (SIS) must TXOne EdgeIPS / EdgeFire - Industrial
be segmented logically or physically from Next Generation Firewall for OT Segment
other OT/ICS networks. networks and isolate connectivity both to
and between facilities as well as
production zones.

2-4-1-5 Wireless technologies must be TXOne EdgeIPS / EdgeFire - Industrial


segmented logically or physically Next Generation Firewall for OT Segment
from other OT/ICS networks. networks and isolate connectivity both to
and between facilities as well as
production zones.

2-4-1-6 Network communications, services, and TXOne EdgeIPS / EdgeFire - Industrial


connection points between different Next Generation Firewall for OT Segment
zones must be limited to the minimum to networks and isolate connectivity both to
meet operational, maintenance, and and between facilities as well as
safety requirements. production zones.

Page 8 of 17 Compliance Report


Cybersecurity Defense
2-4-1-8 Only authorized business-critical services TXOne EdgeIPS / EdgeFire - Industrial
are accessible from the internal OT/ICS Next Generation Firewall for OT EdgeFire
networks, and accessibility to services with supports OT protocols including Modbus,
known vulnerabilities must be limited to the Ethernet/IP, CIP, and more, allowing OT
greatest extent possible. and IT security system administrators to
collaborate. This allows for seamless
connection to existing network
architecture.

TXOne EdgeIPS / EdgeFire - provides


advanced protection against unknown
threats with its up-to-date threat
information. With the help of the Zero Day
Initiative (ZDI) vulnerability reward
program, EdgeFire offers your systems
exclusive protection from undisclosed and
zero- day threat

2-4-1-9 Direct communications between corporate TXOne EdgeIPS / EdgeFire - Industrial


zone and OT/ ICS zones must be prevented, Next Generation Firewall for OT Segment
and direct all the required connections networks and isolate connectivity both to
through dedicated, secured, and hardened and between facilities as well as
jump host/solution in the DMZ zone. production zones.

2-4-1-10 Remote access point in the DMZ zone must TXOne EdgeIPS / EdgeFire - Industrial
not be connected to the OT/ICS networks Next Generation Firewall for OT Segment
unless needed, while ensuring that the networks and isolate connectivity both to
session is multi-factor authenticated, and between facilities as well as
recorded, and established for a defined production zones.
period of time only.

2-4-1-12 Dedicated gateways must be used to TXOne EdgeFire - Industrial Next


segment OT/ICS networks from Generation Firewall Flexible Segmentation
corporate zone. and Isolation, EdgeFire is the ideal solution
for segmenting a network into easily
managed security zones.

2-4-1-14 Strict limitation on enabling/usage TXOne EdgeIPS / EdgeFire - Industrial


of industrial protocols and ports to Next Generation Firewall for OT The
the minimum to meet operational, EdgeFire’s core technology, TXOne
maintenance, and safety One-Pass DPI for Industry (TXODITM),
requirements. gives you the ability to create and edit
Allowlists, allowing for interoperability
between key nodes and deep analysis of
L3-L7 network traffic.

Page 9 of 17 Compliance Report


Cybersecurity Defense
2-5 Mobile Devices Security Trend Micro Product Coverage

Objective: To ensure the protection of


mobile devices (including laptops, handheld
configuration devices, network test devices,
etc.) from cyber risks & to ensure the secure
handling of sensitive data and the
organization’s information.

2-5-1 In addition to subcontrols in ECC control Trend Micro Mobile Security


2-6-3, cybersecurity requirements for Trend Micro Mobile Security is a 4 in 1
mobile device security in OT/ICS solution that gives you full visibility and
environment must cover control of mobile devices, apps, and data
through a single built in console. It strikes
the right balance between user
productivity and IT risks.
As a 4 in 1 solution, Mobile Security
includes:
•Mobile Device Management (MDM)
•Mobile Application Management
•Mobile Application Reputation Services
•Device Antivirus (Android)

ECC The cybersecurity requirements for mobile Phish Insight


2-6-3 devices security and BYOD must include at enhances information security awareness
least the for your organization by empowering
following: people to recognize and protect
2-6-3-1 Separation and encryption of themselves against the latest threats.
organization’s data and information stored
on mobile devices and BYODs.
2-6-3-2 Controlled and restricted use based
on job requirements.
2-6-3-3 Secure wiping of organization’s data
and information stored on mobile devices
and BYOD in cases of device loss, theft or
after termination/separation from the
organization.
2-6-3-4 Security awareness for mobile
devices users.

Page 10 of 17 Compliance Report


Cybersecurity Defense
2-5-1 2-5-1-4 Centralized management of mobile devices Trend Micro Mobile Security
must be deployed. Trend Micro Mobile Security is a 4 in 1
solution that gives you full visibility and
control of mobile devices, apps, and
data through a single built-in console. It
strikes the right balance between user
productivity and IT risks.

2-6 Data and Information Protection Trend Micro Product Coverage

Objective: To ensure the confidentiality,


integrity, and availability of organization’s
data and information as per organizational
policies and procedures, and related laws
and regulations.

2-6-1 2-6-1-4 Transfer or usage of OT systems’ data in Trend Micro Portable Security 3 Pro
any environment other than production - Provides Secure Transporter
environment must be limited, except after Equipped with an AES-256 hardware
applying strict controls for protecting that encryption engine, the secure storage
data. allows ICS owners and operators to carry
sensitive data in air-gapped environments
while ensuring the business’ operational
integrity. Files are scanned as they are
transferred into secure storage and only
clean files can be stored.

Page 11 of 17 Compliance Report


Cybersecurity Defense
2-9 Vulnerabilities Management Trend Micro Product Coverage

Objective: To ensure timely detection &


effective remediation of technical
vulnerabilities to prevent or minimize the
probability of exploiting these
vulnerabilities to launch cy- ber-attacks
against the organization.

In addition to subcontrols in the ECC Trend Micro Deep Security


control 2-10-3, cybersecurity requirements secures servers & applications across the
for vulnerability management in OT/ICS data center. It Provides: Vulnerability
must cover, at a minimum, the 2-9-1 main scanning and Discovery
control in OTCC: Vulnerability Shielding (Virtual Patching)

ECC Periodic vulnerabilities assessments.


2-10
-3-1

ECC Vulnerabilities classification based


2-10 on criticality level.
-3-2

ECC Vulnerabilities remediation based on


2-10 classification & associated risk levels
-3-3

ECC Subscription with authorized and trusted


2-10 cybersecurity resources for up-to-date
-3-2 information and notifications on technical
vulnerabilities.

2-9-1 2-9-1-2 With reference to the ECC subcontrol TXOne EdgeIPS\EdgeIPS Pro -
2-10-3-3, remediation of newly discovered Protect vulnerable unpatched devices
critical vulnerabilities presenting significant and legacy systems.
risks to the OT/ICS environment must be
performed in a timely manner. TXOne EdgeFire - Through virtual
patching your network has a powerful,
up- to-date first line of defense against
known threats. Users have superior
control of the patching process, which
creates a pre-emptive defense during
incidents, and provides additional
protection for legacy systems.

Page 12 of 17 Compliance Report


Cybersecurity Defense
With the help of the Zero Day Initiative
(ZDI) vulnerability reward program,
TXOne EdgeFire\EdgeIPS\EdgeIPS Pro
offers your systems exclusive protection
from undisclosed and zero- day threats.

2-11 Cybersecurity Event Logs and Monitoring Trend Micro Product Coverage
Management

Objective: To ensure timely collection,


analysis, and monitoring of cybersecurity
events for early detection of potential
cyber-attacks in order to prevent or
minimize the negative im- pacts on the
organization’s operations.

2-11-1 2-11-1-7 Malicious events must be detected TXOne OT Defense Console - ODC logs
and analyzed. activity at each EdgeIPS, EdgeIPS Pro and
EdgeFire nodes, including cybersecurity,
policy enforcement, protocol filtering,
system logs, audits, and asset detection.
The dashboard of OT Defense Console
gives you a comprehensive, consolidated
overview. This is organized into alerts,
assets, and incident events, allowing you
to directly monitor the security of your
enterprise’s industrial control system.

TXOne StellarOne - logs all incidents


events generated from agents.

TXOne Management Program - log all


incidents events which generated from
Trend Micro Portable 3 and Trend Micro
Portable 3 Pro.

2-11-1-10 All access control points between the TXOne EdgeIPS / EdgeFire - Operate
network security boundaries and external with a high level of asset visibility using
connections must be monitored. passive asset identification and IT/OT
traffic communication within OT
networks.

Page 13 of 17 Compliance Report


Cybersecurity Defense
2-12 Cybersecurity Incident and Threat Trend Micro Product Coverage
Management

Objective: To ensure timely identification,


detection, effective management, and
handling of cy- bersecurity incidents and
threats to prevent or minimize negative
impacts on organi- zation’s OT/ICS
operation.

2-11-1 2-11-1-7 In addition to subcontrols in the ECC Control Trend Micro Incident Response (IR)
2-13-3, cybersecurity require- ments for Service
cybersecurity incident and threat Trend Micro Service One - Trend
management in OT/ICS must include, at a Micro Incident Response services
minimum, the following: 2-12-1-1 OT/ICS involves IR experts with experience in
cybersecurity incident response plans must responding to breaches carried out by
be integrated and aligned with organizational advanced threat actors
plans and its proce- dures such as IT incident - The experts combined with Trend Micro
response plans, crisis man- agement, and threat intelligence (SPN) powered by
Business Continuity Plan (BCP). Endpoint and Network Detection and
Response technologies helps you to
identify & mitigate your ongoing or past
breaches or intrusions
- IR Experts who can handle most
complex attack situations
- Identify & contain breaches within the
shortest possible time
- Services & Assistance to prevent repeat
incidents while you recover - Local
presence around the globe

ECC
2-13 Cybersecurity incidents classification.
-3-2

ECC
2-13- Cybersecurity incidents reporting to NCA.
3-3

ECC Sharing incidents notifications, threat


2-13- intelligence, breach indicators and reports
3-4 with NCA.

ECC Collecting and handling threat


2-13- intelligence feeds.
3-5
Formal incident response and root cause
2-12-1 2-12-1-2 analysis for any detected cybersecurity
incidents must be conducted

Page 14 of 17 Compliance Report


Cybersecurity Defense
2-12-1 2-12-1-5 OT/ICS including Safety Instrumented
Systems (SIS) recovery procedures must
be included in the incident response,
system recovery plans, & business
continuity plans.

2-12-1-8 Threat Intelligence information must be


used to identify Tactics, Techniques, and
Procedures (TTPs) of activity groups
targeting OT/ICS systems.

Page 15 of 17 Compliance Report


Trend Micro Technology
Coverage Summary:
Below are the Technologies summary from Trend Micro mentioned above in the compliance matrix that
can be provided to customer to raise the compliance measurement against the OTCC controls.

• TXOne StellarOne • Trend Micro Deep Security


• TXOne OT Defense Console • Trend Micro Service One
• TXOne EdgeIPS • Trend Micro Mobile Security
• TXOne EdgeIPS Pro • Trend Micro Deep Discovery Inspector
• TXOne EdgeIPS Pro 216 • Trend Micro Deep Discovery Analyzer
• TXOne EdgeFire • Trend Micro Deep Discovery Director & Network Analytics
• TXOne Portable Security 3 • Trend Micro Phish Insight
• TXOne Portable Security 3 Pro

Deployment Scenarios

Capability of Offering Total Solution from IT to OT, The Real Convergence of IT/OT

Page 16 of 17 Compliance Report


Conclusion
Trend Micro’s solutions can assist Organizations with the NCA Controls (OTCC – 1: 2022) which support the
organization, healthcare, Oil&Gas and manufacturer to implement best practices to improve and enhance
their OT cybersecurity. NCA Controls (OTCC – 1: 2022) are focusing on OT infrastructure in the following
topics for Cybersecurity Defense main domain:

Asset Management $

System and Processing


Facilities Protection

Networks Security
Management

Mobile Devices Security

Data and Information


Protection

Cryptography

Vulnerabilities Management

Cybersecurity Event Logs and


Monitoring Management

Cybersecurity Incident and


Threat Management

Trend Micro aim to help making the world save for exchanging digital information, through our core
principles of customer value, innovation, trustworthiness, & collaboration. To promote resiliency, Trend Micro
support to providing organizations with the necessary tools and resources to manage their cybersecurity
risks. Through this approach, they can see the risks in a strategic & holistic manner. As a business enabler, we
help companies respond to these threats by providing them with the necessary tools & resources.

©2023 by Trend Micro Incorporated. All rights reserved. Trend Micro, and the Trend Micro t-ball logo, OfficeScan and Trend Micro Control Manager are trademarks or registered trademarks of Trend Micro Incorporated. All other company and/or
product names may be trademarks or registered trademarks of their owners. Information contained in this document is subject to change without notice. [REP01_General_Report_Template_A4_221206US]

For details about what personal information we collect and why, please see our Privacy Notice on our website at: [Link]/privacy

Page 17 of 17 Compliance Report

You might also like