Why Do Effective Cybersecurity Programs Need Independent Certification?

Author photo: Eric Cosman
By Eric Cosman

Overview

As described in a previous Insight, end users face significant challenges in ensuring the security of their industrial automation systems. The complexity of the subject can impede many organizations to a significant degree. It is unrealistic to expect plant effective cybersecurity programsoperations staff to be experts in cybersecurity. While they are likely to be familiar with the need for risk assessment and the possible consequences, cybersecurity threats and vulnerabilities evolve rapidly and are often not well understood without help from experts in the field. Identifying, assessing, and selecting specific products and technologies to address them may also require specialized expertise and relevant experience. Industry standards and practices define what is required for effective cybersecurity programs. But these are often very detailed and written in arcane language. Other sources of guidance, such as those available from NIST, may or may not be relevant for the specific domain or industry in question.

End users require a straightforward way to assess people, processes and technology to determine and verify conformance to the requirements provided by the standards.  And they should be able to do so without having to read and absorb what can be thousands of pages of detailed requirements.

Independent certification could meet this need, making it an essential element of the cybersecurity response.

Evolving Standards and Practices

Over the past several years there have been significant advancements in defining specific security-related expectations and requirements.  Many come in the form of standards and practices, both at the sector and broad industry levels.  The ISO 27001 standard for IT cybersecurity, NIST special publications (SP800-53 and SP800-82), NERC CIP, and the ISA-62443 and IEC 62443 standards are well-known examples that contain useful and relevant information.

effective cybersecurity programsThe combination of standards such as ISO 27001 and the 62443 series can provide an excellent reference in the design of an industrial automation system’s cybersecurity program. More recently, the NIST Framework and associated guidance documents provide a structure and context for such a program. Additional guidance is also available within several critical infrastructure sectors.

To be most useful, these standards must address the people, process and technology components of cybersecurity, while being suitable for application to situations ranging from complex integrated systems to specific devices.

However, the amount of available information can present a major challenge to those trying to secure their systems. There are many sources to choose from, each with a specific audience and intended application. End users and even suppliers often find it difficult to determine which standards and practices to use as the basis for their respective responses. This can be a particular challenge when designing systems for a broad set of industries or sectors.

For example, while general-purpose security standards and practices contain information that may be valuable in securing industrial automation systems, they are not sufficient, since they do not explicitly address the unique needs in this area. Some of the content of sector-specific standards may not be appropriate or widely accepted in other sectors.

Those who have to decide which standards and practices to apply must have some level of familiarity with the intent, content, strengths, and weaknesses of the various alternatives in order to make suitable recommendations and selections.

Supplier Response

To a large degree, a supplier’s success in the marketplace is influenced by how they respond to standards and accepted practices. To support their development or marketing efforts they may assign resources to monitor, assess, or contribute to various standards to be able to make more informed decisions. With many suppliers involved in standards development, it is less likely that the results will favor one particular approach or technology.

Once they have identified the most relevant standards for the target market, most suppliers address the requirements by improving the security-related capabilities of their products and solutions. Just promoting these products can often represent an implicit endorsement of the standards to which they comply.

Challenges for End Users

The situation end users face is not as clear. For the most part, complying with or promoting standards does not translate into any competitive advantage. As a result, they seldom have the necessary resources available to help develop and apply standards, yet have to make important decisions as part of the specification and procurement process. Even if they can identify the specific standards and guidance that are most applicable to their situation, they still face the fact that such information is typically quite detailed and complex, and may not be suitable for casual use.

Since the final accountability and responsibility for security typically falls upon end users, it is essential that they have an objective set effective cybersecurity programsof criteria for evaluating possible alternatives. External experts are commonly engaged to help develop these criteria based on an interpretation of requirements. In such situations, the quality of the interpretation may vary widely based on the knowledge and experience of the expert. It is particularly important to solicit advice from someone who is very familiar with the needs of the industry or sector in question.

Since they are likely not subject matter experts themselves, end users benefit from having a straightforward way to assess the quality not just the technology, but also the people and processes that will comprise their cybersecurity programs.

In the case of processes, it is essential to select experts who have been proven effective in similar situations. While standards will typically define what processes may be required in terms of desired outcomes and dependencies, they seldom prescribe the details of the processes themselves.

Ultimately, people apply technology and processes. It is very important to be able to evaluate the knowledge, skills, and experience of those people to be able to select those most likely to succeed. Referrals, recommendations, and reputation are important in making such decisions, but these may apply more to a company than to a specific individual.

Tools Available

Certification programs address at least part of this need. Several are now available or emerging that can help end users assess and vet all three elements of the cybersecurity response.

Technology and product certification specifications are available for confirming that devices and solutions meet specific security related requirements. Examples include the Achilles platform from Wurldtech and the ISASecure specifications from the ISA Security Compliance Institute (ISCI). TÜV SÜD also has the ability to test and verify the security functions implemented in a process control system and check the conformity of development and integration processes.

effective cybersecurity programsEnd users who are considering whether to state conformance to one or more of these certifications as part of the evaluation and procurement process should take some time to become familiar with the program coverage, as well as the basis for its requirements.

Although these and similar tools provide a level of assurance with respect to the capability of specific products, this only confirms that the products are suitable for use in a secured automation system. It is important to take a broader perspective that includes all of the elements of a cybersecurity program.

The IEC System of Conformity Assessment Schemes for Electrotechnical Equipment and Components (IECEE) also has a task force that is examining how to assess conformity to the 62443 standards. Since the standards address people, process, and technology; each element will be addressed.

With respect to the people element, several organizations issue certificates or certifications that confirm that those who have taken their training have demonstrated a specific level of knowledge of the subject matter.  ISA has developed a knowledge-based certificate recognition program designed to increase awareness of the ISA-62443 standards. Although this is not a full certification program, the individual certificates are awarded to those who successfully complete a designated training program and pass a multiple-choice exam.

The Certified Information Systems Security Professional (CISSP) certification is a commonly used credential for demonstrating technical and managerial competence; skills; experience; and credibility to design, engineer, implement, and manage an information security program to protect organizations from growing sophisticated attacks. However, it is seldom sufficient for industrial security applications.

The Global Industrial Cyber Security Professional (GICSP) certification assesses a base level of knowledge and understanding of professionals who engineer or support control systems and share responsibility for the security of these environments.

Various service provider companies also provide training for those working in industrial control systems security.

Choose Carefully

Certifications and certificates can be of great value in addressing the inherent complexity of industrial cybersecurity. However, even when using such tools there will be challenges. As with product selection, there are many options to choose from and the end user must take the time to understand the scope and limitations of each before citing them in requests for bid or procurements specifications. It is simply not sufficient to state the requirement for a specific certification without conducting this analysis.

If possible, it is also wise to benchmark with other end users or peer companies with similar needs. This is often possible through involvement with trade associations such as the American Chemistry Council (ACC), the American Fuel & Petrochemical Manufacturers (AFPM). Those looking for information should ask peers what certificates or certifications they value or require as part of their programs. In some cases, trusted suppliers can also be used a source for this type of information.

Conclusions

Independent certification of products, technology and expertise can provide a useful tool for end users when developing their industrial cybersecurity programs, but only if they take the time and care required to understand the scope and limitations of the options available to them.

Recommendations

Based on ARC research and analysis, we recommend the following actions for owner-operators and other technology users:

  • Research available offerings – Spend some time looking into certification programs to determine those that are most applicable to your needs and specific situation. This includes gaining an understanding of the objectives of specific programs and their targeted markets.
  • Support certifications of choice – When the choices are made, help others in their selection by endorsing particular programs or contributing feedback that would be useful in making improvements.
  • Understand possible limitations – While general-purpose cybersecurity certifications such as CISSP may be useful, they may not be sufficient to address the specific needs of industrial cybersecurity.
  • State requirements of suppliers – When stating requirements to suppliers, consider using certifications as a component, provided that you understand the content and limitation of any such programs.

 

If you would like to buy this report or obtain information on how to be-come a client, please contact us

Keywords: Standards, Certification, Certificates, Cybersecurity, Industrial Automation Systems, ARC Advisory Group.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients