Build a cyber security incident response plan

A plan lets everyone respond properly to a control system security breach, whether it's a failure of a critical cyber component or an intentional break-in.

12/01/2009


 

PODCAST

tinyurl.com/yjtwxhw

Today’s modern industrial control systems are built on open system platforms and technologies. This means that what was once proprietary and closed is now more accessible—and therefore more vulnerable to intrusion. While we frequently hear reports about cyber security breaches in financial and consumer systems, we are now just starting to hear about such incidents reported on control systems. Many of these are the result of malicious activity, and others are the result of unintended consequences that result from a change made somewhere in the system, or an inappropriate use of the system.

It is best to be prepared and have an incident response plan in place. The purpose of the plan is to better prepare your organization for responding when there is suspicion of an incident to one of your control systems. This plan will allow you to properly respond to any type of cyber security incident—whether it is a failure of a critical cyber component, malicious software executing on your system or an intentional break-in to one of your control systems.

Components of the plan

An early part of the plan will be to describe the various types of incidents that may occur on your systems. These will range from simple failures such as a hard disk or CPU failure, infection of your system with a worm or virus, unintended consequences from changes made to the system, or a deliberate attack on the system from an insider or outsider.

The plan will describe who to call when such an incident occurs. The plan will include procedures for the responders to follow to determine the type of attack and how best to respond. The plan should also include procedures that will allow the process or plant to continue to operate while personnel are responding to the cyber security incident.

The plan should include definitions for additional responses where necessary. For example, if the security incident is the result of a virus or worm being introduced into the system, include actions that can be taken to delete the virus or worm, as well as procedures for how to prevent the incident from occurring again. This will require that an investigation be performed in order to determine how the virus or worm was introduced into the system.

Define forensics

The plan should also define what forensics are to be performed if the incident is intentional, and how to maintain the chain of custody of evidence gathered as part of the investigation. There are times when outside help is needed to resolve the problem, or to report the problem properly to comply with regulations. Therefore, reporting procedures and regulations should be documented in the plan as well. In many cases, the control system vendor has expertise in this area that can be very useful in creating the plan.

There are many more aspects to putting together a cyber security incident response plan for your industrial control systems. A good approach to use in creating the plan is to work with your IT organization as well as your vendors. Both will already have plans in place, and they will be able to assist in the creation of a plan for your industrial control systems. It is critical, as well, to get management support for the creation of the plan.

Once the plan is developed, all members of the organization will need to be trained on their role with respect to the incident response plan. Some may only need to know who to call, while others will require detailed training on how to respond.

One final note: Ensure the plan works. The execution of the plan should be practiced and updated with lessons learned. With a good cyber security incident response plan in place and understood, an organization can minimize the impact of an incident on its industrial control system.




References

www.security.honeywell.com/industrial/solutions/cyber/index.html


Author Information

Kevin Staggs is an Engineering Fellow with Honeywell Process Solutions and a member of the company’s global architecture team. This article is an excerpt from a Control Engineering podcast.




No comments
The Top Plant program honors outstanding manufacturing facilities in North America. View the 2013 Top Plant.
The Product of the Year program recognizes products newly released in the manufacturing industries.
The Engineering Leaders Under 40 program identifies and gives recognition to young engineers who...
The true cost of lubrication: Three keys to consider when evaluating oils; Plant Engineering Lubrication Guide; 11 ways to protect bearing assets; Is lubrication part of your KPIs?
Contract maintenance: 5 ways to keep things humming while keeping an eye on costs; Pneumatic systems; Energy monitoring; The sixth 'S' is safety
Transport your data: Supply chain information critical to operational excellence; High-voltage faults; Portable cooling; Safety automation isn't automatic
Case Study Database

Case Study Database

Get more exposure for your case study by uploading it to the Plant Engineering case study database, where end-users can identify relevant solutions and explore what the experts are doing to effectively implement a variety of technology and productivity related projects.

These case studies provide examples of how knowledgeable solution providers have used technology, processes and people to create effective and successful implementations in real-world situations. Case studies can be completed by filling out a simple online form where you can outline the project title, abstract, and full story in 1500 words or less; upload photos, videos and a logo.

Click here to visit the Case Study Database and upload your case study.

Maintaining low data center PUE; Using eco mode in UPS systems; Commissioning electrical and power systems; Exploring dc power distribution alternatives
Synchronizing industrial Ethernet networks; Selecting protocol conversion gateways; Integrating HMIs with PLCs and PACs
Why manufacturers need to see energy in a different light: Current approaches to energy management yield quick savings, but leave plant managers searching for ways of improving on those early gains.

Annual Salary Survey

Participate in the 2013 Salary Survey

In a year when manufacturing continued to lead the economic rebound, it makes sense that plant manager bonuses rebounded. Plant Engineering’s annual Salary Survey shows both wages and bonuses rose in 2012 after a retreat the year before.

Average salary across all job titles for plant floor management rose 3.5% to $95,446, and bonus compensation jumped to $15,162, a 4.2% increase from the 2010 level and double the 2011 total, which showed a sharp drop in bonus.

2012 Salary Survey Analysis

2012 Salary Survey Results

Maintenance and reliability tips and best practices from the maintenance and reliability coaches at Allied Reliability Group.
The One Voice for Manufacturing blog reports on federal public policy issues impacting the manufacturing sector. One Voice is a joint effort by the National Tooling and Machining...
The Society for Maintenance and Reliability Professionals an organization devoted...
Join this ongoing discussion of machine guarding topics, including solutions assessments, regulatory compliance, gap analysis...
IMS Research, recently acquired by IHS Inc., is a leading independent supplier of market research and consultancy to the global electronics industry.
Maintenance is not optional in manufacturing. It’s a profit center, driving productivity and uptime while reducing overall repair costs.
The Lachance on CMMS blog is about current maintenance topics. Blogger Paul Lachance is president and chief technology officer for Smartware Group.