Cyber security standard aims at critical infrastructure in process industries

The International Instrument Users Association (WIB) releases comprehensive cyber security standard to protect critical industrial computer systems from cyber attack.

11/16/2010


The International Instrument Users Association (WIB), an international organization that represents global manufacturers in the industrial automation industry, announced the second version of the Process Control Domain Security Requirements For Vendors document – the first international standard that outlines a set of specific requirements focusing on cyber security best practices for suppliers of industrial automation and control systems.

“We are pleased to announce today the second version of our cyber security standard,” said Alex van Delft, competence manager for process control at DSM and chairman of the WIB. “This is an important step in the ongoing process to improve the reliability of our critical manufacturing and production systems, and provides end-users the ability to communicate their expectations about the security of process automation, control, and safety systems.”

With industrial networks being increasingly connected to the hostile IT world, and the frequency and sophistication of malware growing exponentially, industrial stakeholders must act today to protect their critical systems. Whether it is a targeted attack like Stuxnet, or an accidental disruption, a single cyber incident can cost millions of dollars in lost revenue, jeopardize employee and public safety, and potentially disrupt national critical infrastructure.

“Our increasingly connected production systems are facing a growing threat on a daily basis and we must do all we can to ensure a safe and secure operational environment,” said Peter Kwaspen, strategy and development manager, EMEA control and automation systems at Shell Projects & Technology. “This document provides the common language we need to communicate our expectations around security to our suppliers and the framework to work together to help improve the overall security posture for our critical systems.”

Led by major companies such as Shell, BP, Saudi Aramco, Dow, DuPont, Laborelec, Wintershall, and dozens of other end-users, as well as leading vendors such as Invensys, Sensus, and multiple government agencies, the group spent two years developing the requirements and piloting a certification program to ensure a functional, scalable, and ultimately valuable result.

“The security requirements outlined in the document went through a year of comments and revisions from over 50 global stakeholders and were subjected to a thorough pilot certification program over the last eight months,” said Jos Menting, cyber security advisor GDF Suez Group. “We’ve now come to a truly functional cyber security standard based on the needs of end-users and it is now up to us, the end-users, to take advantage of this effort and insist that our vendors are certified.”

Members of the WIB Plant Security Working Group have already started implementing the requirements into their procurement processes and others around the world are heeding the call. “Shell has mandated conformance to the WIB standard for all vendors supplying systems to be deployed in Shell’s process control environment starting January 1, 2011,” said Ted Angevaare, PACO EMEA control and automation systems team leader. “These requirements will become a standard part of the procurement language saving us a significant amount of time and effort.”

Leading suppliers of industrial process control and automation systems are also starting the process of integrating the requirements into their organizations. “Adopting the WIB’s security requirements ensures that Invensys has a set of measurable practices in place that enforce a safer and more secure critical infrastructure. Not only do the requirements provide current-state measures, they allow us to continue to improve and adapt to the ever-changing security landscape,” said Ernie Rakaczky, program manager for control systems cyber security at Invensys Operations Management. “From our perspective, this program is a major shift, not only focusing on tactics, but one that puts into place strategic elements that address operational change.”

Cyber security at all stages of the industrial product lifecycle

The WIB standard is designed to fit the needs of end-users – the system owner/operators – and reflects the unique requirements for industries like oil and gas, electric power, smart grid, transportation, pharmaceutical, and chemical. The goal is to address cyber security best practices and allocate responsibility at various stages of the industrial system lifecycle: Organizational practices, product development, testing, commissioning, maintenance, and support.

“Security is not a one-time application, but rather a process in which every stakeholder must contribute in order to achieve any significant improvement in operational reliability,” said Auke Huistra, project manager at National Infrastructure against Cyber Crime (NICC). “The WIB requirements are designed with this principle at its core and we are encouraging critical infrastructure stakeholders in The Netherlands to integrate the requirements into their cyber security plans.”

The requirements were also constructed to address a broad range of cyber security topics relevant to industrial stakeholders; from high-level requirements for vendor’s internal security policies, procedures, and governance, to specific requirements concerning access, authentication, data protection, default password protection, and patch management. When a vendor’s solution complies with this set of requirements, the solution is considered by the WIB to be Process Control Domain Security Compatible.

The requirements are further broken down into 3 levels designed to reflect various starting points of global suppliers and provide a scalable framework to plan improvements over time. In the program, there are Gold, Silver and Bronze levels, each consisting of a set requirements designed to verify that applicable policies and practices are in place, enabled and practiced by the vendor.

Successful global cooperation

From the beginning, industry leaders recognized that given the global nature of industrial cyber security, any effort to standardize cyber security best practices would require stakeholder cooperation from different industry sectors and in different regions of the world. The WIB association was the ideal conduit to guide creation of the standard given its independent nature and membership composition. Moreover, the initiative needed to reflect and incorporate the important cyber security activities happening internationally. Many government agencies, industry working groups, and standards bodies were consulted to ensure harmony. For example, major industry standards efforts such as ISA SP99, NIST 800-53, NISTIR 7628, and various international government regulations such as NERC/CIP were reviewed and incorporated where appropriate or expanded to ensure testability. The WIB executive committee has started the process of introducing the WIB PCD requirements into the CEN/CENELEC and IEC international standards framework.

Download a copy of the standard.

www.wib.nl

www.wib.nl/download.html

www.isssource.com/wib

Edited by Peter Welander, pwelander@cfemedia.com

Visit the Control Engineering Plant Safety & Security Channel.



The Top Plant program honors outstanding manufacturing facilities in North America. View the 2015 Top Plant.
The Product of the Year program recognizes products newly released in the manufacturing industries.
Each year, a panel of Control Engineering and Plant Engineering editors and industry expert judges select the System Integrator of the Year Award winners in three categories.
Doubling down on digital manufacturing; Data driving predictive maintenance; Electric motors and generators; Rewarding operational improvement
2017 Lubrication Guide; Software tools; Microgrids and energy strategies; Use robots effectively
Prescriptive maintenance; Hannover Messe 2017 recap; Reduce welding errors
The cloud, mobility, and remote operations; SCADA and contextual mobility; Custom UPS empowering a secure pipeline
Infrastructure for natural gas expansion; Artificial lift methods; Disruptive technology and fugitive gas emissions
Mobility as the means to offshore innovation; Preventing another Deepwater Horizon; ROVs as subsea robots; SCADA and the radio spectrum
Research team developing Tesla coil designs; Implementing wireless process sensing
Commissioning electrical systems; Designing emergency and standby generator systems; Paralleling switchgear generator systems
Natural gas engines; New applications for fuel cells; Large engines become more efficient; Extending boiler life

Annual Salary Survey

Before the calendar turned, 2016 already had the makings of a pivotal year for manufacturing, and for the world.

There were the big events for the year, including the United States as Partner Country at Hannover Messe in April and the 2016 International Manufacturing Technology Show in Chicago in September. There's also the matter of the U.S. presidential elections in November, which promise to shape policy in manufacturing for years to come.

But the year started with global economic turmoil, as a slowdown in Chinese manufacturing triggered a worldwide stock hiccup that sent values plummeting. The continued plunge in world oil prices has resulted in a slowdown in exploration and, by extension, the manufacture of exploration equipment.

Read more: 2015 Salary Survey

Maintenance and reliability tips and best practices from the maintenance and reliability coaches at Allied Reliability Group.
The One Voice for Manufacturing blog reports on federal public policy issues impacting the manufacturing sector. One Voice is a joint effort by the National Tooling and Machining...
The Society for Maintenance and Reliability Professionals an organization devoted...
Join this ongoing discussion of machine guarding topics, including solutions assessments, regulatory compliance, gap analysis...
IMS Research, recently acquired by IHS Inc., is a leading independent supplier of market research and consultancy to the global electronics industry.
Maintenance is not optional in manufacturing. It’s a profit center, driving productivity and uptime while reducing overall repair costs.
The Lachance on CMMS blog is about current maintenance topics. Blogger Paul Lachance is president and chief technology officer for Smartware Group.
The maintenance journey has been a long, slow trek for most manufacturers and has gone from preventive maintenance to predictive maintenance.
Featured articles highlight technologies that enable the Industrial Internet of Things, IIoT-related products and strategies to get data more easily to the user.
This digital report will explore several aspects of how IIoT will transform manufacturing in the coming years.
Maintenance Manager; California Oils Corp.
Associate, Electrical Engineering; Wood Harbinger
Control Systems Engineer; Robert Bosch Corp.
This course focuses on climate analysis, appropriateness of cooling system selection, and combining cooling systems.
This course will help identify and reveal electrical hazards and identify the solutions to implementing and maintaining a safe work environment.
This course explains how maintaining power and communication systems through emergency power-generation systems is critical.
click me