In Depth
SCADA System Security: Out of Control
Industrial control systems such as SCADA systems sit squarely at the intersection of the digital and physical worlds. They're vulnerable, they're unpatchable, and they're connected to the Internet.
By Todd Datz
Pollet points out another issue; vendors sometimes approve patches for only certain versions of software. He gives the example of a company that upgraded its operating system. "If I say my system isn't functioning, [control system vendors] ask what patch you're running. I say I'm running a patch for Windows 2003 Server. They say I can't give you any support [because that's not the OS our software works with]. They say scale back to the original OS. Companies can void a warranty by upgrading," says Pollet.The Fix Is in
There are some examples of new efforts by vendors. Areva, a control system vendor, recently announced a new partnership with Symantec to strengthen the security of its products. Last year, software company Verano announced Industrial Defender, a product suite aiming to protect control systems from cyberattacks.
Meanwhile, the companies that use control systems aren't completely reduced to waiting for vendors to get their acts together. Pollet says better information security on the corporate network can greatly reduce the risks posed to control systems; he mentions better router configuration, antivirus software, intrusion detection systems and more diligent patching. Torres adds the nontechnology parts of the security equation: better configuration management, better documentation of network architectures, better patch management and better contingency planning. Above all, Torres thinks the cultural gap between the IT and control side needs to be bridged.
Various private industry and government groups are taking steps to make critical infrastructure companies more aware of the flaws in their control systems. The National Institute of Standards and Technology and the National Security Agency established the Process Controls Security Requirements Forum (members include reps from the electric, water, chemical and oil industries, as well as government labs and control system vendors) to develop security specs for control systems. NERC and the oil pipeline industry are working on the creation of permanent standards. Other government agencies and major critical infrastructure industries have established working groups to address the issue. Notably, last December, the Department of Homeland Security created a new Control Systems Section inside the Protective Security Division of the Information Analysis and Infrastructure Protection Directorate.
scada system
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



