Cybersecurity Challenges Extend to Level 1

Author photo: Eric Cosman
ByEric Cosman
Category:
Technology Trends

For more than a decade, experts in automation and information technology have given considerable attention and effort to ensuring the cybersecurity of industrial control systems. The result is that industry now has a wealth of information and guidance available in the form of standards, practices, and case studies. Widespread adoption and implementation remains a challenge, but there is a broad consensus on the need for improved products that are “secure by design,” as well as improved response by asset owners, using available frameworks and tools. Although we’ve seen considerable progress, many challenges remain, and new opportunities are still presenting themselves.

Cybersecrity Challenges Extend to Level I.png

 

Some of these opportunities are associated with the lower levels of the control systems infrastructure. Many of the current standards (e.g., ISA-62443, NERC CIP) have focused primarily on the applications, computers and networks at the manufacturing operations and control levels (levels 3 and 2) of the reference model, with comparatively little attention given to field devices and networks.

The forthcoming ISA-62443-4-2 standard addresses security requirements for components, but the primary focus is on the components of control systems at levels 1 and 2.

Field Devices: An Overlooked Cybersecurity Risk?

Recent posts to blogs and discussion boards have pointed out that field devices provide process information to both control and safety systems and are the basis for anomaly detection, yet have little in the way of protection from cyber-attack. Implicit trust of these devices may have been appropriate when they were based on physical principles, but most modern devices have some level of intelligence, which can be subverted or compromised. Failures or inaccurate data at this level could, in turn, compromise the integrity of the entire control system.

The ISA99 committee (responsible for the 62443 standards on ICS cybersecurity) is currently considering forming a separate work group to investigate the need for further requirements and guidance for securing field devices. This could be a complex effort, as it has implications for and dependencies on several other existing and planned standards (e.g., ISA-84, ISA-108) in the ISA portfolio. Nonetheless, the topic must be addressed.

Does the possible failure or compromise of field level devices present a significant risk for the security of industrial control systems? Is it reasonable to assume that such devices can be targets of cyber-attacks, or are they adequately protected by measures taken at the higher levels of the architecture? Given the presence of proprietary and often arcane protocols at this level, is it even possible to apply existing solutions to their protection? Are there parallels between this situation and that of the Industrial Internet of Things? After all, aren’t field devices “things?”

These and many other questions must be addressed by the ICS cybersecurity community, working closely with other disciplines such as safety engineers, process control engineers and instrument designers. Such collaboration will hopefully lead to a consensus on the nature and severity of the risks, as well as best measures to apply to mitigate them. The dialog and debate taking place in blogs and other forums must move into standards committees and similar forums to achieve this consensus, and to identify any new requirements or guidance that may be required.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients