Industrial machines will increasingly become connected to systems and people not only within the plant, but across the enterprise and beyond. Monitoring and applying analytics and software to real-time data at the edge can enable new business models and yield dramatic improvements in asset uptime and operating performance.
However, in order to realize these benefits, it is vitally important to ensure secure connectivity between industrial machines, devices, systems and people. Getting it right depends on proper up-front design and implementation of the network infrastructure. It also requires a comprehensive view towards addressing security for internal and external threats, across both the enterprise (IT) and operating (OT) environments. It's also important to form multiple layers of defense, and to establish security processes and policies that identify and contain evolving threats in industrial automation and control systems.
One good approach to this is offered by Rockwell Automation and Cisco, who recently announced new additions to their
Converged Plantwide Ethernet (CPwE) architectures that address constantly changing security practices driven by IT/OT convergence in industrial markets. Each new guide is accompanied by a white paper summarizing the key design principles:
The
Industrial Demilitarized Zone Design and Implementation Guide and white paper provide guidance to users on securely sharing data from the plant floor through the enterprise.
The
Identity Services Design and Implementation Guide and white paper introduce an approach to security policy enforcement that tightly controls access by anyone inside the plant, whether they are trying to connect via wired or wireless access.
I'd be curious to learn whether you think this approach is enough to start on the IIoT Journey, and if not, what's missing. Let me know by comment or email.