IT Security and the Plant Floor
A few months ago, while attending a conference on “Cybersecurity for Process Control,” we heard a question from a very smart network engineer at Cisco that got us thinking. He asked: “Why not just apply the already developed practices and technologies from information technology security to plant floor security— isn’t that good enough to solve the problem?” A week later, an IT security specialist said: “None of this would be a problem if those plant floor people just used proper security policies. What’s wrong with them?” Both of these questions are valid. In the dozens of industrial cybersecurity incidents we’ve investigated over the past five years, had the facility followed good IT security practices in network design, password handling, and access controls, virtually none of the problems would have occurred. So why don’t we just deploy the standard IT practices for our process control systems and stop making such a big deal of plant floor security? Are process engineers so stupid, lazy, or stubborn that they won’t just do what IT says? Process engineers are certainly not stupid, lazy, or stubborn (OK, there are a few exceptions). Certainly some don’t deploy the proper IT security measures because they don’t understand them, but most hesitate because they sense that somehow many IT practices don’t mix well with the plant floor environment. And they’re correct, for four very good reasons. |
|
Read more...
|
|
ANSI/ISA-99 security standards and the Tofino Industrial Security Solution
May 2009 (presentation)
ANSI/ISA-99 standards Security for Industrial Automation and Control Systems are summarized, particularly the concepts of Zones and Conduits. In addition, Tofino is shown as a solution for achieving the standards.....
|
|
Read more...
|
|
Cyber security for pipeline control systems
February 2009 (article)
Eric Byres, CTO of Byres Security Inc., has
published an article about cyber security and pipeline control systems
in Pipeline and Gas Journal.....
ARTICLE EXTRACT:
CYBER SECURITY AND THE PIPELINE CONTROL SYSTEM
|
|
Read more...
|
|
|
October 2008 (video)
In this video Eric Byres, CTO of Byres Security, describes how the Tofino™ Industrial Security Solution protects critical infrastructure from threats that penetrate or bypass IT firewalls..... |
|
Read more...
|
|
|
February 12, 2008 (article)
The days of teenage hobbyist hackers who break into systems just to prove they can do it is over. Today hacking is big business by criminal organizations.....
|
|
Read more...
|
|
|
|
<< Start < Prev 1 2 Next > End >>
|
| Results 1 - 9 of 10 |