Jump to content

Control system security

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Cusimanoja (talk | contribs) at 22:14, 14 October 2010 (Created page with '== Definition == Control System Security is defined as the prevention of intentional or unintentional interference with the proper operation of industrial automatio...'). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.
(diff) ← Previous revision | Latest revision (diff) | Newer revision → (diff)

Definition

Control System Security is defined as the prevention of intentional or unintentional interference with the proper operation of industrial automation and control systems through the use of computers, networks, operating systems, applications and other programmable configurable components of the system. It is known by several other names such as SCADA Security, PCN Security, Industrial Automation and Control System Security, Control System Cyber Security, Industrial Network Security and Electronic Security for Industrial Automation and Control Systems.

Control system security is very important because industrial automation and control systems automatically operate the services that we consider essential for our way of life – electricity, petroleum production, water, transportation, manufacturing and communications. Recent events such as the discovery of the Stuxnet virus have demonstrated the vulnerability of these systems to cyber incidents. The US and other governments have passed Cyber-security regulations requiring enhanced cyber security protection for control systems operating critical infrastructure.

Risks

Insecurity of industrial automation and control systems can lead the following risks:

  • Safety
  • Environmental impact
  • Lost Production
  • Equipment Damage
  • Information Theft
  • Company Image

Vulnerability of Control Systems

Industrial automation and control systems have become far more vulnerable to security incidents due to the following trends that have occurred over the last 10 to 15 years.

  • Heavy use of Commercial Off-the Shelf Technology (COTS) and protocols. Integration of technology such as MS Windows, SQL, and Ethernet means that process control systems are now vulnerable to the same viruses, worms and trojans that affect IT systems Increased Connectivity
  • Enterprise integration (using plant, corporate and even public networks) means that process control systems (legacy) are now being subjected to stresses they were not designed for
  • Demand for Remote Access - 24/7 access for engineering, operations or technical support means more insecure or rogue connections to control system
  • Public Information - Manuals on how to use control system are publicly available to would be attackers as well as to legitimate users

Government Efforts

Control System Security Standards

ISA99

ISA99 is the Industrial Automation and Control System Security Committee of the Instrumentation, Systems, and Automation Society (ISA). The committee is developing a multi-part control system standard and has released several standards and technical reports.