Archives
PCSF Historical Archives
PCSF Groups(All documents are in PDF format.) Antivirus Software on Control Systems Interest GroupThis group will focus on increasing communication between antivirus vendors, control vendors, and end-users, with the aim of increasing the benefits and reducing the risk of deploying host based antivirus on control systems.
Chair: David Teumin Business Case Development Interest GroupThe protection of control systems from cyber security threats requires resources and personnel to plan, develop and implement needed security measures. This group will focus on developing the business rationale for justifying that investment. Chair: Ernest Rakaczky Control System Technical Security Metrics Interest GroupThis group will focus on advancing the state of the art and the state of the practice in security metrics for control systems. With limited success, the research community has spent a significant amount of time and effort trying to measure system and component security. A good understanding of security measurement and effective ways for determining mitigations would be useful to everyone. Generally, industry has responded to demands for improvement in software security by increasing their efforts in creating 'more secure' products and services. But how can it be determined that the work toward security has been effective in making any system or component more secure? Can it be determined if this effort is paying off? Can the results be quantified? Are updated systems more secure than earlier versions? Approaches and techniques for answering these, and similar, questions were addressed by this interest group.
Chair: Miles McQueen Control Systems Research Interest GroupThis group is concerned with both basic and applied research in security methodologies and technologies related to control systems, including Supervisory, Control, and Data Acquisition (SCADA) systems and Critical Infrastructures. We span the full spectrum of security, including reliability, safety, dependability, and trustworthiness. As control systems are increasingly networked to other systems, their role in such network-centric systems or (system of systems) is critical. The increase in the number, sophistication, and speed of computer network attacks is an indication of the importance of the Process Control Systems Forum in general and in this Interest Group in particular. Thus, new approaches to vulnerability assessments, real-time monitoring, survivability and denial, and consequence management are sought. Further, the relatively new field of information forensics, or "inforensics", of control systems is another area of interest. Lastly, the complexity of critical infrastructures yields inter-dependencies between component systems. Improved modeling and assessment of these inter-dependencies might yield new approaches to the prevention of cascading failures.
Chair: Dr. Ann Miller Education and Training Interest GroupThis group will gather, develop, and publicize education & training materials and curricula related to control systems security. Chair: Brian LopezProduct:
Lemnos Interoperable Security Project Interest GroupThe goal of the interest group is to promote interoperable vendor security solutions for control system communications over IP. It is part of the industry outreach effort of the Lemnos Interoperable Security Project, which is sponsored by the US Department of Energy's National SCADA Test Bed. Chair: David Teurmin Responsible Vulnerability Disclosure Interest GroupAlthough only a small number of SCADA and Control Systems product vulnerabilities have been publically disclosed, this is likely to change as these applications are connected with more accessible networks and come under increased scrutiny from security researchers. Control systems vendors, asset owners, and government-sponsored vulnerability coordination centers all have an interest in ensuring that vulnerabilities are properly and efficiently handled, regardless of how they are discovered or who discovers them.
Chair: Zach Tudor IAM (Identity and Access Management) SCADA Interest GroupNERC CIP regulations indirectly call for identity and access management from identity roles, privileges, logical and physical access rights and termination processes. Deployment of CIP requires involvement of departments who own the identities. This will include HR, Purchasing, Finance and other departments whom SCADA asset owners might not be thinking about when they consider CIP. Further, as organizations begin to become CIP complaint they will, like with Sarbannes Oxley, have trouble maintaining their processes. This will lead to developing attestation processes such that a manager can ascertain on a monthly or quarterly basis what access rights their workers require and automating portions of the process to reduce cost and administrative overhead. Our group will address the underlying technical architecture required to accomplish this securely as well as educate asset owners about the identity business processes required. Security is a process and not a technological solution. Chair: Guy HuntingtonGoals:
Control System Security Event Monitoring Working GroupDetecting attacks on control systems is critical because many of the applications and protocols have inherent vulnerabilities. Security Event Management (SEM) products and Managed Security Services collect and correlate data from traditional IT sources. The working group will look to leverage the existing solutions and find ways to augment these solutions with control system detection sources and correlation intelligence. Good practices, information sharing, product and service solutions, and case studies will help asset owners detect cyber attacks on the critical infrastructure. Chair: Dale PetersonCharter: The purpose of the Control Systems Security Event Monitoring Working Group is to serve as a clearinghouse of information and tools to detect attacks on control systems. The Working Group will (1) collect control system attacks statistics to quantify and qualify the threat (2) correlate control system detection events with IT detection events (3) normalize control system detection events from different vendors and (4) create and maintain a list of control system detection products and services SCADA Cyber Self-Assessment Working Group (SCySAg)The driver behind this Working Group and this effort is the fact that existing self assessment methodologies aimed at traditional IT environments do not adequately meet the needs of the SCADA environment. The SCADA community is interested in creating and owning the part of this process that is unique to their environment. In recognition of this fact, SCADA specific elements have been added within broader self-assessment methods, and efforts for development of SCADA-specific tools are starting to emerge in the community (Example: SCADA security elements in the "NRECA IT Recovery Plan for Electric Cooperatives" https://crn.cooperative.com/Resources/SoftwareDownloads/ITRecoveryPlanning.htm). This group intends to serve as both an information resource to encourage and serve such efforts and a vehicle via which their results can reach the SCADA community.
Chair: Brian Isle Technical Approach: The team will first identify in-progress initiatives and available tools and methodologies for SCADA cyber self-assessment. The output of this activity serves two purposes: to provide resource information for SCADA operators wishing to embark on a self assessment program; to allow the working group to identify gaps in available requirements information in order to effectively focus its requirements work.
If gaps in self assessment requirements are identified, the team will work to fill these gaps and publish and publicize its results. This work will be phased by addressing identified gaps incrementally. This overall plan keeps the team motivated by structuring smaller focused deliverables. Identification and formation of effective relationships with the target audience for the group's work are part of this effort. The following key elements characterize the proposed approach to developing the SCADA self-assessment requirements
Standards Awareness Working Group (Congress of Chairs)This Working Group will provide a venue for the chairs of standards groups to coordinate the work of their groups, thus avoiding duplication of efforts, eliminating inconsistent standards, and assuring development of all required standards. In addition to standards chairs, full membership in the group is open to the person with primary responsibility to develop recommended practices in an industry, as well as to people who regularly attend standards meetings of groups not represented on the Standards Awareness Working Group. Adjunct membership is open to people who wish to improve their awareness of activities and work-in-progress in all working groups participating in the Standards Awareness WG. Funding agencies wishing to assess the status of the standards activities throughout the world are encouraged to join as adjunct members. Chair: Dr. William RushAdmins: Dennis Holstein Charter: The purpose of this working group is to raise the awareness of work in progress on process control security standards and related projects. Through information sharing the goal is to improve the quality of all such standards. This group will achieve these aims by providing a single forum at which Chairs of standards groups can assemble to review their goals, progress, and results. Full voting membership in the group is open only to chairs of standard groups, or similar organizations, (or their designated representatives), and with approval of the Chairman of the Congress of Chairs, to people who bring intimate knowledge of other groups not represented by their chairs. Products: |
