ICS Basic Training Module 1
Intro to Industrial Control Systems
ICS Basic Training – Learning Goals
Baseline shared vocabulary for Common ICS vulnerabilities and
IT and OT to work together strategies to mitigate them
Application of lessons learned Preparation for foundational ICS
through real-world case studies certifications like GICSP, CSSA
ICS Basic Training - Audience
• IT Personnel • OT Personnel
• Network admins • System integrators
• Security researchers • Engineers
• Security analysts • Technicians
• Managers
ICS Basic Training - Author
• David Formby
• PhD Electrical and Computer Engineering,
Georgia Institute of Technology
• 10+ ICS-CERT vulnerabilities
• 12+ publications on ICS security
• Presented at RSA, Black Hat, S4, ICSC…
• Co-Founder and CEO/CTO Fortiphyd Logic
Overview
• About this course
• What is an industrial control system?
• Common ICS security misconceptions
• Roles and Responsibilities
What is a Control System?
• System to control some physical
process, using
• Sensors – sense the state
• Actuators – act on the state
• Controller – uses actuators to
move sensed state to desired state
• Everyday examples
• Home thermostat and furnace
• Cruise control
What is an Industrial Control System?
• Control system for industrial
processes using
• Sensors
• Controller
• Actuators
• Human machine interface (HMI),
usually
• Remote Diagnostics, usually
• Operational Technology (OT)
• As opposed to information
technology
What is an Industrial Control System?
• HMI
• Operators can view process data
and modify set points (targets)
• Manipulated Variable
• Physical characteristic that is
directly modified by actuator
• Controlled Variable
• Physical characteristic that the
controller is attempting to control
Common Misconceptions – Air Gap Security
• “Our control system isn’t
connected to the Internet so we
don’t have to worry about
security”
• Email alerts, remote diagnostics,
contractors
• Stuxnet jumped a strict air gap to
destroy 1000 centrifuges
• For how long in the age of
Industrial IoT and data analytics?
Common Misconceptions – Security Through
Obscurity
• “Our control system only uses
closed proprietary protocols and
software, so hackers don’t know
how to attack them”
• Hackers research these for fun on
the weekends
• Legacy proprietary software
sometimes cannot be upgraded or
fixed
• Browse ICS-CERT advisories for
your vendors
Common Misconceptions – Just use standard
IT security
• “The ICS personnel just need to
follow all the same security
practices IT does”
• Network scans can crash legacy
devices
• Automatic updates break critical
functionality
• Mistakes -> power outages, death
• IT security products usually don’t
understand ICS protocols, physics
Whose Job Is it Anyway?
• IT and OT often clash over ICS security
• OT
• “The control system is ours. We have a hard
enough time keeping it running without IT
coming in and messing with stuff they don’t
understand”
• IT
• “Cyber security is our responsibility. The ICS
network is vulnerable and only we know how
to secure it.”
• BOTH have responsibility
OT/ICS Roles and Responsibilities
• Control engineer
• Design, implementation, and operation
• Consider cybersecurity throughout design and operation
• Process engineer
• Safety and efficiency of process
• Include security in calculations for safety
• Operator
• Watch HMIs and maintain operations
• Practice cyber hygiene, be aware of suspicious activity
IT Roles and Responsibilities
• Security researcher
• Finds new vulnerabilities and works with industry to fix them
• Security analyst
• Analyze, integrate, and test security solutions
• Security architect
• High level planning to make sure network is secure
• System/network administrator
• Maintain (install, configure, update) systems on the network
• Implement and monitor security and backup policies
Organization Roles and Responsibilities
• Owner/Operator
• Owns facility or operates it for another
• Implement cyber security policies
• System integrator
• Designs and builds complex control systems
• Often responsible for training and migration
• Build security into networks and software
• Vendors
• Creates software and hardware for ICS
• Design with security, fix vulnerabilities
• Government
• Ensure safety of public by enforcing
regulations and creating standards
• Can be owner/operator
Organization Examples
• Vendor • Government
• Rockwell Automation • NIST
• Siemens • CISA
• Schneider Electric
• Honeywell
• Owner/operator • System Integrators
• Saudi Aramco • Leidos
• Chevron • Wunderlich-Malec
• BP • Barry-Wehmiller
Overview
• ICS
• Control industrial process with sensors,
actuators, HMI, diagnostics
• Security misconceptions
• Air gap ≠ secure
• Obscure/proprietary ≠ secure
• IT security tools/practices cannot be
directly applied
• Roles and Responsibilities
• Both IT and OT responsible for security
References
• [Link]
• NIST, “NIST Guide to Industrial Control System (ICS) Security”
• NIST, “National Initiative for Cybersecurity Education (NICE)
Cybersecurity Workforce Framework”