• No results found

Cyber Security From product to system solution

N/A
N/A
Protected

Academic year: 2021

Share "Cyber Security From product to system solution"

Copied!
16
0
0

Loading.... (view fulltext now)

Full text

(1)

Cyber Security

From product to system solution

Markus Brändle, Network Management Forum Heidelberg, 8./9./10. October 2013

© ABB Network Management Forum October 14, 2013 | Slide 1

(2)

Measures taken to protect a computer or computer system (as on the Internet) against unauthorized access

or attack*

translates into

Measures taken to protect the reliability, integrity and availability of power and automation technologies against unauthorized

access or attack

Cyber Security

A definition

in the context of power and automation technology

(3)

Existing regulatory frameworks

 Energiewirtschaftsgesetz (EnWG) currently in force:

 §11 (1a): "Der Betrieb eines sicheren

Energieversor-gungsnetzes umfasst […] einen angemessenen Schutz gegen Bedrohungen für Telekommunikations- und

elektronische Datenverarbeitungssysteme[…]. Die

Regulierungsbehörde erstellt hierzu […] einen Katalog

von Sicherheitsanforderungen […]. Ein angemessener Schutz des Betriebs eines Energieversorgungsnetzes wird vermutet, wenn dieser Katalog der Sicherheits-anforderungen eingehalten und dies vom Betreiber

dokumentiert worden ist. Die Einhaltung kann von der

Regulierungsbehörde überprüft werden. […]"

 The mentioned catalogue of requirements is not

available yet!

© ABB Network Management Forum October 14, 2013 | Slide 3

(4)

Upcoming regulatory frameworks

 "Referentenentwurf": "Gesetz zur Erhöhung der Sicherheit informationstechnischer Systeme"

 Establishes German BSI as the "competent authority“.

 Requires operators of critical infrastructure to implement state-of-the-art security controls.

 Requires operators to report significant incidents to the

BSI.

 Refers to industry standards and proven-in-the-field

practices as expected state-of-the-art.

© ABB Network Management Forum October 14, 2013 | Slide 4

(5)

Cyber Security

 Cyber security has become an more important issue by

introducing Ethernet (TCP/IP) based communication

protocols to industrial automation and control systems. e.g. IEC60870-5-104, DNP 3.0 via TCP/IP or IEC61850

 Connections to and from external networks (e.g. office

intranet) to industrial automation and control systems have opened systems and can be misused for cyber attacks

 Cyber attacks on industrial automation and control systems

are real and increasing, leading to large financial losses

 Utilities need to avoid liability due to non-compliance with

regulatory directives or industry best practices

Why is Cyber Security an issue?

© ABB Group October 14, 2013 | Slide 5

(6)

The biggest challenges - organizational

© ABB Network Management Forum October 14, 2013 | Slide 6

Images: www.guardianconsultants.co.uk wegilant.com www.floris-cm.nl blogpool4tool.com

Risk Management Awareness

(7)

Disruptive Changes Sustaining Security

The biggest challenges - technical

© ABB Network Management Forum October 14, 2013 | Slide 7

Images: www.zazzle.co.nz www.zoho.com blog.monitorscout.com www.leadthefish.com nl.123rf.com www.ccure.it

Situational Awareness Installed Base

(8)

© ABB Group October 14, 2013 | Slide 8

Cyber Security

BDEW White Paper Requirements

Motivation:

 Security measures for control and

telecommunication systems

 Protect the operation of these

systems against security threats Main Requirements:

 Robustness Testing / Product &

System Hardening

 User Account Management

 User activity logging / Audit Trail

 Secure Communication

 Antivirus

 Firewall

(9)

Holistic Approach to Cyber Security

Cyber Security for the energy sector

ABB Network Manager

System status 1. Secure network architecture 2. System monitoring 3. System protection 4. Cyber Security management system 5.

© ABB Group October 14, 2013 | Slide 9

Monitor Protect

(10)

Cyber Security for the energy sector

Steps to sustainable cyber security – network architecture

© ABB Group

October 14, 2013 | Slide 10

 No direct access to secure zone

 No services (e.g. remote desktop) between insecure and secure

zone

 No direct data exchange between office and SCADA network (e.g. use of data diodes)

 Control of traffic between zones

(11)

Cyber Security for the energy sector

Steps to sustainable cyber security – system monitoring

Automated and centralized monitoring:

Host monitoring:

 Event-logs, processes, resources

 Server and workstations

Equipment monitoring:

 Ping, SNMP, Syslog

 RTUs, switches and routers

Network monitoring:

 performance incl. SCADA protocols (e.g. IEC

60870-5-104, DNP 3.0, Modbus, ICCP, …)

 Monitoring within network zones

© ABB Group

(12)

Cyber Security for the energy sector

Steps to sustainable cyber security – system protection

System protection includes:

 Access control

 Antivirus systems (in Windows environments if

possible)

 Whitelisting following need-to-know principle

 Security updates of applications, operating systems and

third party products

 Trusted shares for updates of applications

© ABB Group

(13)

Cyber Security for the energy sector

Steps to sustainable cyber security – management system

Fulfillment of policies:

 BDEW Whitepaper, DIN 27009, ISO/IEC TR 27019

 Internal policies (e.g. ISMS, integrated security management

systems)

Asset management for IP-based system components:

 Baseline of current status

 Procurement, commissioning and service

Change Management:

 Traceability of software changes (e.g. operating system, applications, and configurations)

 System restore (backup strategy)

© ABB Group

(14)

Cyber Security for the energy sector

Partnership ABB and Industrial Defender

Why Industrial Defender?

 Global leader in automation systems management for industrial control systems

Customer benefits?

 Technology alignment

 Verified solutions

 Combined Know-How

Efficient and comprehensive security solutions

Managing Diverse Requirements of Automation Systems

Environments

The convergence of:

© ABB Group

(15)

From product to system solution

Summary

Cyber security from ABB

 is embedded in substation

automation products and solutions

 is an integral part of product

development and quality assurance

 comprises the latest technology

and high competence

 enables customers to protect,

monitor and manage their systems

 safeguards systems in a

changing world

© ABB Group

(16)

© ABB Group

References

Related documents

Reviewing the clinical question, “Do anesthesia providers, implementing a temperature guideline compared to not using a temperature guideline affect the incidence of

 In case of incorrect data input, when saving the form, the user is displayed a conspicuously coloured error message at the upper part of a screen, with reference to the data

If you create the proxy using "SvcUtil.exe", system will generate the contract, service client operation and data contract in single "service.cs" file. If you want

More broadly, by suggesting and showing how the governance of a firm’s alliances affects that firm’s partner selection behavior and its innovativeness, this paper answers the recent

The FMIs supervised by the Bank sit at the heart of the UK economy and financial system in the form of, for example, the payment systems which allow goods and services to be

2.1 In consideration of you agreeing to abide by the terms of this EULA, we grant you a personal, nontransferable, non-exclusive license to use the Software, Website, and the

Thomas and Ganster (1995) studied hospital employees and found that childcare benefits were not related to work- family conflict but that flexible scheduling can increase

També en els escrits de Célestin Freinet (1896-1966) trobem elements claus del treball per projectes i de l'aprenentatge servei. Freinet defensa que els infants apre- nen perquè