Industrial Internet Consortium Announces First Security Claims Evaluation Testbed

Author photo: Chantal Polsonetti
ByChantal Polsonetti
Category:
Company and Product News

The Industrial Internet Consortium (IIC) announced its first security assessment-focused testbed: the Security Claims Evaluation Testbed. IIC member organizations UL, Xilinx, Aicas and PrismTech are collaborating on the project to provide an open and easily configurable cybersecurity platform for evaluation of endpoint, gateway, and other networked components' security capabilities. Data sources can include industrial, automotive, medical and other related endpoints requested for secure operation analysis.

IIC members will be able to connect their equipment to the testbed to evaluate the security of their devices within two different scenarios: individually on a device level, or with a system of other endpoints, gateways, etc. The options include exploration of methodology and collection of evidence to demonstrate the system operational security processes supporting the key characteristics of the system relative to evaluation of the participant's claims. Additionally, the testbed enables the evaluation of those critical areas of an architecture pattern that need to be secured as outlined in the Industrial Internet Reference Architecture Technical Report.

The IIC contends that understanding the security of devices very early in product development can minimize delays for product launch. The testbed aims to enable manufacturers to improve the security posture of their products and verify alignment to the upcoming IIC Security Framework Technical Report prior to product launch to help accelerate time to market.

The testbed will be rolled out in three stages, with the first being initial deployment in a lab environment and the second in a micro-factory environment. The third phase will be determined by the growth of the testbed. The security testbed's phased release approach provides an opportunity to evaluate security vulnerabilities at a device as well as system level prior to large-scale deployment across many key applications driving the Industrial Internet of Things (IIoT) / Industry 4.0.

The testbed will leverage several technologies from non-IIC constituents, including: secure intelligent gateway and networking IPs providing endpoint to the cloud communication from SoC-e (System-on-Chip engineering S.L.), overall testbed monitoring with real-time analytics from Juxt.io, endpoint monitoring from PFP Cybersecurity, and programmable SOC Platforms and IP from iVeia.

To learn more about this testbed, visit www.iiconsortium.org/security-claims .

Keywords: Cybersecurity, Operational Security Processes, Security Of Devices, Industrial Internet of Things (IIoT), Industry 4.0, ARC Advisory Group.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients