Overview
The automation of industrial processes is a well-established practice, drawing from multiple engineering and technical disciplines, but process safety and cybersecurity convergence presents automation challenges. Regardless of the discipline responsible for automation, the skills and competencies required continue to evolve and change in the face of these changing technology, circumstances and requirements.
The Automation Federation has contributed to a related competency model. This model recognizes that, in addition to the core automation skills, automation professionals also need to be versed in related disciplines such as process safety and cybersecurity. There is a growing realization that processes that have not been made secure from a cybersecurity perspective may also be potentially unsafe. This provides much of the imperative for improvements in industrial cybersecurity.
Clearly, close collaboration between these disciplines is needed. Effective models for achieving this collaboration are still evolving, making it critical to share experiences across disciplines and industrial sectors through case studies.
The Practice of Automation
The Merriam-Webster dictionary defines automation as "automatically controlled operation of an apparatus, process, or system by mechanical or electronic devices that take the place of human labor." While this explains the basic concept, a full understanding is only possible within a specific context. This context is expressed in terms of the scope of application and the specific objectives to be achieved.
The automation of industrial processes has been a well-established area of expertise for many years. This expertise is available from any of several engineering and technical disciplines, depending on the situation. Process industries may draw this expertise from chemical or industrial engineering disciplines, while other industries may call on electrical or mechanical engineers. Instrumentation and electrical technicians are typically responsible for configuring and supporting automation systems. Assigning specific responsibilities to different disciplines is appropriate, since the specific objectives of automation may vary by industry.
Regardless of these objectives or the discipline responsible for automation, common skills and competencies are required. Although these may evolve and change in the face of changing technology, circumstances, and requirements, it is possible to describe them within a competency model. The Automation Federation has worked with industry experts and representatives from the US Department of Labor to develop a model that describes the skills and competencies needed from several specific occupations in the automation field.
Recognizing that maintaining automation systems security is part of the responsibilities of the automation professional this model includes elements related to industrial cybersecurity.
Objectives and Impacts
In simple terms, the objective of automation is to apply science and technology to improve the performance of a wide range of processes and equipment, in terms of safety, reliability, security, and profitability. These objectives are often the basis of business process design, business process automation, and business process re-engineering efforts. Although these may be the primary objectives, a common side effect is that changes are required to roles, processes, and jobs associated with operations.
The irony is that those who practice automation are also having their roles and responsibilities changed by changes in technology and the expectations of various stakeholders. As automation systems and technology have evolved and new requirements identified, those working in this area have had to adopt to and adapt new technology, methods, practices, and responsibilities. This is particularly true for automation engineers, technicians and related roles.
It has been understood for some time that industrial processes must be automated in a manner that protects the safety of these systems and the people who operate them. Traditionally, the focus has been on understanding the physical limits of the process and the probability of failure that can result in unsafe conditions. This is changing.
Changing Needs and Expectations
The increased use of commercial-off-the-shelf information technology has significantly impacted the role of the automation engineers, technicians, and other automation professionals. Experience and skill in the use of an increasing array of technologies has become a common expectation. This trend is likely to continue as automation solutions become more sophisticated and integrated with business processes.
Improving safety levels is a common objective for automation-related projects and activities. Process safety has been an expertise area in its own right for some time and safety and automation professionals routinely work closely to ensure performance in this area.
More recently, increased attention to the security of industrial systems is driving changes in this area, including the skills and competencies required for effective industrial automation. There is a growing realization that processes that have not been made secure from a cybersecurity perspective may also be potentially unsafe. This provides much of the imperative for improvements in industrial cybersecurity.
Similar to the situation with process safety, the security response begins with a thorough analysis of risk. Security-related risks are different in that they may be the result of threats arising from deliberate actions of determined adversaries that have identified vulnerabilities in software or hardware. It’s difficult or often impossible to predict the presence or occurrence of such threats, so automation engineers must focus on identifying vulnerabilities and develop a detailed understanding of potential consequences, which in most cases, are similar or identical to those of failures in process safety.
However, understanding the full extent of these threats and vulnerabilities may require knowledge and experience that is not prevalent in the automation related professions. As has been the case with process safety or the transition from proprietary to commercial control systems, the increased need for security has driven automation professionals to become familiar with new subjects, ranging from network design and communications configuration to the use of specialized security technologies.
It is unclear how much of this expertise is necessary for the automation professional. Time and resources are limited, and effort spent learning and applying these skills detracts from that required to develop and apply control strategies. It is unreasonable to expect automation professionals to become experts in the design, operation and support of complex IT systems, networks, and security management systems.
How to Respond to Process Safety and Cybersecurity Convergence ?
Many questions should be addressed when considering how to respond to the current and changing situation. These include:
- Are the safety and security of industrial processes being addressed using a common or shared risk management methodology? If not, should they be?
- Who is ultimately accountable for the performance of automation systems with respect to safety and security?
- Are all responsibilities associated with meeting these challenges understood and clearly assigned?
- Do automation professionals have the awareness, experience, and knowledge necessary to consider the security and safety aspects in automation system design?
- Should IT experts contribute to future HAZOPs so the impact and magnitude of cybersecurity threats can be understood as additional hazardous events that will need protective measures instituted?
- What level of expertise is required in these areas in each individual facility?
- To what degree can specialized expertise be centralized or shared across multiple facilities?
- Should users change their current deployments and add IT staff to their process automation organizations?
These represent only a sample of the questions that can arise in this context. Arriving at the best answers for a specific environment will likely require collaboration between multiple stakeholders.
While it is certainly possible for automation professionals to develop the expertise required to fully address cybersecurity and its implications for industrial automation and safety, this may not be the best approach. Cybersecurity is a highly specialized subject that requires skills and expertise in areas such as network design, intrusion detection, and digital forensics.
As has been the case for process safety and complex multivariable control, it may be preferable to develop collaborative relationships with those with the more specialized expertise required. There are several possible models for such collaboration and, at this time, it is unclear that any single model is best for all situations.
Assessing potential approaches and their suitability for a given situation begins with having each described in the form of case studies that include specific use case analysis, and work flow diagramming. Once these descriptions have been captured they can be shared through industry, sector, or supplier-centered organizations such as standards committees or user groups. This allows participants to get a much better appreciation of what options are possible and make intelligent decisions for their respective situations.
ARC and the Automation Federation will be examining these and related questions in several Monday workshops at the ARC Industry Forum in Orlando, Feb. 8-11, 2016. Attendees with an interest in this area are encouraged to participate and offer their insights.
Recommendations
ARC recommends the following actions for owner-operators and other technology users:
- Define the specific needs and responsibilities for ensuring the safety and security of industrial control systems and assign these to clearly defined roles.
- Learn more about the automation and cybersecurity competency models and consider how they may be applied to your situation.
- Share your experience with potential models and approaches with others through case studies.
- Attend the 2016 ARC Industry Forum to learn more about changes that are impacting the automation professional.
If you would like to buy this report or obtain information about how to become a client, please Contact Us
Keywords: Competency, Models, Cybersecurity, Process Safety, System Integrity, ARC Advisory Group.