Overview
Much has been written on the current imbalance between supply and demand for skilled and experienced industrial cybersecurity expertise. While many related reports often focus on general-purpose IT cybersecurity, the situation is even more acute for industrial cybersecurity. Proficiency in that field requires more than expertise in IT security and network design. It also requires detailed knowledge and experience with various aspects of process design and control strategy development.
Public and private sector initiatives to better understand the specific needs and make plans for expanding the available pool of cybersecurity expertise have produced competency models and similar tools, leading to more detailed curricula and certification programs. Although these tools are necessary, skills development cannot be achieved through education alone. Practical experience is required, particularly in industrial cybersecurity, where the most effective response requires a thorough understanding of potential consequences for the physical equipment and processes.
We Live in a Risky World
Several widely reported attacks were either directed at, or had indirect impact on industrial automation systems. Direct attacks have ranged from the Stuxnet attack of several years ago to more recent attacks on steel mills and other facilities.
Directed attacks are not the only threat. Most industrial systems use common, commercial-off-the-shelf (COTS) computers, networks, and software. This puts them at risk for collateral damage from malicious software designed to exploit known or recently discovered vulnerabilities in a wide variety of COTS technology.
The number of vulnerabilities identified continues to increase as more researchers focus on industrial control systems and applications. According to SCADAhacker, “Data obtained from the former Open-Source Vulnerability Database shows that through the end of 2014, more than 85% of all ICS vulnerabilities have been disclosed since 2011…”
The increased number of vulnerabilities has in turn led to an increased number of disclosures of ICS-related security incidents.
Perhaps the most important component of risk is potential consequence, which can only be fully understood with knowledge and experience in the specific area or domain in question. Just examining and assessing the computer and network elements of the automation system is not sufficient to understand these consequences. It is also essential to have a detailed understanding of the process and equipment under control. Process engineers use hazard identification methods to study consequences such as physical damage, release of hazardous material, or other business or safety risks to be able to avoid or mitigate these when designing the process.
How Asset Owners Are Responding
Asset owners are responding to changing risk in a variety of ways. These range from evaluating new tools and solutions to developing sophisticated cybersecurity management processes. Typically, the imperative originates in governance and management functions and is then channeled through the IT security function. However, the response must take the form of a comprehensive program that involves IT, OT, and other stakeholders. Regardless of the specifics, it is generally accepted that these programs can only be successful over the long term if they address each of the three essential elements of people, process, and technology. The people and process elements are commonly combined in proposed organizational changes.
Technology
Technology is often the first element addressed. There is typically a desire to achieve quick results by applying new products and solutions, but no amount of technology will fully address the problem. On the contrary, complex or incompatible products and technology can actually complicate the problem.
People and Processes
Addressing the process element almost always involves a critical review of the organizations responsible for managing cybersecurity and how they work together. Those responsible for IT infrastructure security often challenge engineering and operations to demonstrate that their systems have been adequately protected. This can exacerbate the friction that may already exist between the IT and operations functions in a company, often due to a lack of understanding of their respective drivers and constraints. Much more must be done to identify common concerns, imperatives, and objectives, which are essential prerequisites for effective partnerships.
People and Expertise Are Key
The development of appropriate skills and experience is a key element in addressing this challenge. These skills must reflect the content of available standards and practices that have been developed for both general information cybersecurity and industrial cybersecurity.
There have been many discussions and debates about the best approach for achieving such expertise. Is it more effective for security experts to develop knowledge of and appreciation for the nature of the manufacturing operations environment, or should operations engineers strive to develop expertise in security? While an argument could be made for either approach, the unfortunate truth is that neither is guaranteed to work in all situations.
Success in an ICS cybersecurity role is determined less by previous background than by the individual acknowledging the gaps in their skills and experience, and being willing to learn. There are several examples of recognized experts who have come from both the IT and OT worlds.
Understanding the Process Under Control
To fully understand and appreciate what is required to secure an industrial control system and associated networks, it is first necessary to understand the physical process and system under control, as well as the logic developed to automate it.
The process and equipment may be described in documents with names like “process description” or “process overview.” Although these may take the form of narrative descriptions, it is more common for them to include some combination of diagrams and tables giving design conditions. The logic used to control the equipment may be available in a variety of forms, ranging from narrative documents to logic diagrams or even computer source code. Such documents may have names such as “control system design” or “automation strategy.” The information in these documents helps in the design of more resilient networks and segmentation of the controllers. It also defines what normal network traffic should look like.
Even with access to such documents it may not be possible to fully understand the physical process without assistance from a production or control engineer or operations staff responsible for its operation. It is quite common – especially with older facilities – for the above documents to be out of date, or simply not available.
Although gaining the necessary understanding of the production processes may take considerable time and effort, it is critical for developing an effective cybersecurity response.
Available Tools
While defining and developing roles with the necessary expertise can be challenging, some helpful tools are available.
Competency Models
A competency model describes the knowledge, skills, and abilities a person needs to perform well in a particular occupation. The US National Institute of Standards and Technology (NIST) provides a general framework that can be used to develop competency models for use in specific areas.
The Automation Federation worked with industry experts and representatives from the US Department of Labor to develop a competency model for automation that serves as a pathway for building the next generation of automation and engineering professionals. The content of the model is based on a variety of sources, including the Guide to the Automation Body of Knowledge from ISA, licensing requirements for professional engineers, and various professional certificates.
While the automation competency model contains some elements that pertain to this subject, there is also a separate competency model devoted entirely to cybersecurity. The Automation Federation has also contributed enhancements to this model to help differentiate between the needs for operations and business systems.
Unfortunately, competency models are insufficient in themselves to completely define the roles and expertise required.
NIST NICE Framework
Since the practice of industrial cybersecurity crosses the disciplines of security, engineering, and operations, it is necessary to define a common set of concepts and terminology that bridges these disciplines.
The National Initiative for Cybersecurity Education (NICE) at NIST has produced a Framework that serves as a reference resource for describing and sharing information about cybersecurity work and the knowledge, skills, and abilities needed to complete tasks that can strengthen an organization’s cybersecurity posture.
This framework provides a taxonomy and common lexicon that addresses all cybersecurity work and workers, irrespective of where or for whom the work is performed. The intent of the framework is to allow employers to use focused, consistent language in professional development programs when using industry certifications and academic credential and selecting relevant training opportunities for their workforce.
Much of its content is in the form of a series of appendices that describe the following elements:
- categories of common cybersecurity functions
- specialty areas of cybersecurity work
- roles, comprised of specific knowledge, skills, and abilities required to perform tasks in a work role
- knowledge, skills, and abilities required to perform tasks, generally demonstrated through relevant experience or performance-based education and training
- tasks or specific work activities that could be assigned to a professional working in one of the work roles.
Certifications
Having defined the competencies and responsibilities required to address industrial cybersecurity, organizations need an effective way to assess the level of achievement of individuals. This is commonly addressed using exams and associated certifications. Industrial cybersecurity certifications are available from several sources and typically complement those used for information security.
Certifications do not obviate the need for individual interviews and skills assessment, but they do provide a valuable starting point and establish a common baseline.
Conclusions
Success in industrial cybersecurity requires a combination of aptitude, skills, and experience in both information security and industrial applications. Asset owners and others who seek to develop or acquire this expertise should employ available tools in the context of a comprehensive cybersecurity program that describes the organizational models and roles required to meet well-defined requirements.
Recommendations
Based on ARC research and analysis, we recommend the following actions for asset owners and others wishing to develop industrial cybersecurity expertise:
- Establish the "Shared Vision" – Take the time to clearly describe the characteristics of a future state that can be turned into goals that are shared across organizations.
- Risk Assessment – Understand the nature of the physical process, associated equipment and the supporting network. Perform a risk assessment to define, identify, and classify the security vulnerabilities in your industrial control system.
- People and Processes before Organization – In planning for the cybersecurity response, common practice is to focus on organizational details. A better approach is to identify the processes and procedures required, and the skills necessary to execute them. These skills are then described in the form of roles.
- RACI Analysis – Conduct a detailed analysis of the specific roles and individuals that must be responsible, accountable, consulted or informed (RACI) with respect to the various tasks required.
- Role and Skill Definition – Consider the use of formal competency models as tools in the development of careers in automation and cybersecurity.
- Share Case Studies – If you have examples of successful responses to the challenges in obtaining or developing the necessary expertise, consider sharing them in the form of case studies. The ARC Industry Forum provides an excellent opportunity for industry participants to both present and learn from these.
If you would like to buy this report or obtain information about how to become a client, please Contact Us
Keywords: Cybersecurity, Process Knowledge, Process Safety, Control Strategy, ARC Advisory Group.