United States
Change Country Homepage
  • Canada
  • Japan
  • Mexico
  • Netherlands
  • South Africa
  • United Kingdom
  • Member Login
  • |
  • Safety Automation Element List
  • |
  • Contact
  • |
  • COMPANY
    • About Us
    • Locations
    • Key Consultants
    • Clients
    • Career Opportunities
  • SERVICES
    • Certification
    • End User
    • OEM
    • Security
    • Alarm Management
  • SOFTWARE
    • exSILentia
    • PHAx
    • SILAlarm
    • SILStat
    • SERHViewer
    • Software Support
    • All Software
  • TRAINING
    • Course Dates
    • Online Training
    • On-Site Training
    • Virtual Classroom
  • WEBINARS
    • About
    • Scheduled Webinars
    • Recordings
    • Webinar Wednesdays
  • BOOKS
    • Alarm Management for Process Control
    • Certified Functional Safety Expert / Professional (CFSE / CFSP) Study Guide
    • Control Systems Safety Evaluation and Reliability, 3rd Edition
    • Electrical & Mechanical Component Reliability Handbook, 3rd Edition
    • Final Elements and the IEC 61508 and IEC 61511 Functional Safety Standards
    • Functional Safety - An IEC 61508 SIL 3 Compliant Development Process, 2nd Edition
    • Practical SIL Target Selection - Risk Analysis per the IEC 61511 Safety Lifecycle
    • Safety Book Package
    • Safety Equipment Reliability Handbook - 3rd Edition
    • Safety Instrumented Systems Verification - Practical Probabilistic Calculations
  • RESOURCES
    • Safety Automation Element List
    • Features
    • Brochures / Flyers
    • White Papers
  • WEB STORE
  • BLOG

Blog - exida explains

exida : Blog : A False Sense of Security
jcusimano's photo
John Cusimano, CFSE
Director of Security Services

A False Sense of Security

Thursday, June 21, 2012

Viewed 1465 times

Control System Security • (0) Comments • Permalink

About 5 years ago I was sitting around a big table in a conference room at a major LNG terminal.  Outside the window I could see a big city harbor filled with boats, bridges, sky scrapers and approximately 5 million people.  I could also see two huge LNG storage tanks that, I was told, had the hazard potential to form a vapor cloud that could cover the harbor and, under the right conditions, could burn and explode. 

I was brought to the facility by a control system integrator who had been working onsite and had concerns about the cyber security of the control and safety systems and the potential risk that it represented.  They wanted me to discuss options to evaluate and improve the security of the system.  As soon as I was introduced, the plant manager banged his fist on the table and said, “This facility is secure!  We have a firewall and nothing can get through it.”  Then he turned to the IT guy and said, “Isn’t that right, Paul1?” Paul fidgeted a bit in his chair and said, “Well, uh, yes, we do have a firewall between the corporate network and the process control network.”

image

Of course, Paul knew full well that his firewall, just like the firewall between the passenger cabin and the engine compartment in your car, has lots of openings to allow necessary services to pass through.  However, it was clear that the plant manager viewed the firewall as an impenetrable barricade - something analogous to the Berlin wall.  I’m sure he was thinking, “After the price I paid for that firewall, the last thing I need is some hot shot control system security expert coming in here to tell me I need to spend more money to secure my plant from some invisible threat.”  It was hard to blame him for feeling that way. 

Fortunately, we went on to have a good discussion about defense-in-depth and how firewalls, while providing a great first line of defense, are not impenetrable.  Not only can viruses and unauthorized persons slip through open ports there are also plenty of ways for malicious code or malicious people to circumvent them entirely. 

5 years later I am still visiting plants and reviewing control system network diagrams and the only layer of defense is the single firewall between the corporate LAN and the big, flat control system network. 

We’ve been talking about defense-in-depth for so long that it is almost cliché.  But, the principle of protecting critical assets with multiple layers of defense makes sense, not just in cyber security.  It starts with assessing the cyber risk to the entire control system, looking at every potential access point (e.g. firewalls, switch ports, USB ports, CD ROM drives, wireless communications, etc.) and asking, “What are the threats, what are my vulnerabilities, how much risk does that represent and, if it’s more than I can accept, how can I mitigate it”.  In a nutshell, this is the security risk assessment process that exida helped that LNG facility work through and many others like it since then. 

1Paul was not the actual name of the IT guy

Tagged as: john cusimano, cyber security, control system integrator,

(0) Comments

    You Must Be Logged In To Comment

    Become a Registered Member

Blog RSS Feed

  • Click to Subscribe

Categories

  • Alarm Management (8)
  • Control System Security (10)
  • Failure Data (15)
  • Functional Safety Certification (37)
  • General (6)
  • Layer of Protection Analysis (LOPA) (2)
  • News (1)
  • Proof Testing (1)
  • Risk Communication (7)
  • Safety Instrumented System (1)
  • Software (9)

Most recent entries

  • How do You Compare?Added 4 hours ago
  • The exida SchemeAdded 6 days ago
  • Root Cause AnalysisAdded 14 May 2013
  • Certificate Forgery!Added 09 May 2013
  • Which Edition of IEC 61508 is Relevant to Me?Added 07 May 2013
  • Setting the PaceAdded 02 May 2013
  • How Do You Certify to IEC 61508?Added 30 April 2013
  • Practice Makes Perfect…AlmostAdded 25 April 2013
  • PHA: A must or a MUST?Added 24 April 2013
  • Setting up for FAILUREAdded 18 April 2013
  • The Human Element of Functional Safety (The Challenge)Added 10 April 2013
  • A 100% Pass Rate!Added 03 April 2013
  • Changing the PVST Interval. Hey, my Architectural Constraints changed!Added 21 March 2013
  • Changing the PVST Interval. Hey, my failure rates changed!Added 20 March 2013
  • That is impossible! It has never happened before…Added 13 March 2013

Contact exida

Germany +49-89-49000547
USA +1-215-453-1720
South Africa +27 31 2671564
United Kingdom +44 (0) 2476 214 794
Canada +1-403-475-1943
Mexico +52-55-1-5-18-05-73
Asia +65 6222-5160

Stay Informed

  • Get Updates Via Facebook
  • Follow us on Twitter
  • Youtube Channel
  • RSS Feed of exida News

Resources

Safety Automation Element List
Blog
Features
White Papers
Company Brochures
Web Seminars

Newsletter

Receive our FREE Newsletter that goes out to over 5,000 industry professionals every month

Copyright 2000 - 2013 . exida.com LLC | Site Map