SCADA RISK AND AUDIT METHODOLOGY PROJECT

profileDamonHermit
SEC6084ICSRiskAuditMethodologyProjectTemplate.docx

ICS RISK & AUDIT METHODOLOGY PROJECT TEMPLATE 9

ICS Risk & Audit Methodology Project Template for Water Plant

SEC6084

Your Name

INSTRUCTIONS

PLEASE REVIEW THE DOCUMENT FOR DETAILS. IT'S A SCADA INDUSTRY PROJECT SO MAKE SURE THE INDUSTRY IS RELATED TO SCADA AND IS A CRITICAL INFRASTRUCTURE INDUSTRY. MOREOVER, MAKE SURE YOU DO NOT JUST COPY PASTE FROM ANY SOURCE I WILL CHECK EACH AND EVERYTHING INDIVIDUALLY. ALL THE TABLE OF CONTENTS MENTIONED IN THE DOCUMENT SHOULD BE COVERED. ALSO, MAKE SURE YOU QUOTE AND CITE ALL THE SOURCES PROPERLY. FOLLOW APA STRICTLY. NO PLAGIARISM AT ALL. STRICT APA FORMAT AND REFERENCING. QUALITY WORK REQUIRED. IF THE WORK IS GOOD, IT'S MY WORD THAT I WILL GIVE YOU A GOOD TIP ON TOP OF THE AMOUNT BEING PAID. I WANT QUALITY WORK. IF YOU CAN'T, PLEASE DON'T WASTE YOUR TIME OR MINE. IF THE WORK IS NOT UP TO THE MARK, PLEASE DON'T EXPECT TO GET PAID.

Running Head: ICS Risk & Audit Methodology Project Template 2

Table of Contents

Description of Industry X

Industrial Control System Processes Employed X

Profile ICS Security Devices X

Create Diagrams of ICS Device Network X

Identify, Measure, and Manage Risks ……………………………………………………………X

Identify Security Controls X

Apply ICS Security Best Practices X

Identify Vulnerability Continuous Monitoring Strategy X

Reference X

Appendix X

Example: Industrial Incident or Accident ...………………………………………………...X

Example: Disaster Recovery and Incident Response…….. ……………………………...X

Example: Test Outputs X

Example: Vulnerability Scan Reports X

Example: Analysis Metrics from Tools X

Example: Presentations X

Example: Screenshots of Systems X

List of Tables and Figures

Figure 1. Example: ICS System Documentation X

Figure 2. Example: Security Solution Documentation X

Description of Industry

1. What type of industry is this?

2. What is the importance of this industry to society?

Industrial Control System Processes Employed

1. List industrial control system processes specific to industry.

2. List the control systems that control those processes and how they control those processes.

3. Create a network diagram displaying the interconnections of the industrial control system devices listed in item 3.

a. For example: Use ICS CERT CSET, Visio, Excel, Word, etc.

Profile ICS Devices

1. For each ICS device document:

a. Logical Ports

For example, 80, 443, etc.

http://www.digitalbond.com/tools/the-rack/control-system-port-list/

b. Protocols Running

For example, SMTP, SNMP, DNP3, Modbus, Fieldbus, Ethernet, etc.

c. Physical Connection Types

For example, serial, RJ45, USB, parallel, etc.

http://www.digitalbond.com/tools/the-rack/control-system-port-list/

d. Default Accounts:

Research the manufacturer’s information on the device. Look for default account information to login with.

Check “Default Password List” for an entry: http://www.defaultpassword.com/

e. Services

Research manufacturer’s information on the device and document services running.

f. Authentication

Research manufacturer’s website for the device and locate information on how the device authenticates users.

g. Use of Encryption

Research manufacturer’s website for the device and locate information about encryption. For example, does the device use encrypted connections? Is the back-end database encrypted? What type of encryption does it use? Is public/private key encryption like RSA?

h. Logging Capability

Research manufacturer’s website for the device and locate information about logging. Answer questions like is logging enabled? Are logs stored locally or remotely?

i. Other Security Documentation

Does the manufacturer have any security related documentation not provided above that would be of use?

Identify, Measure, and Manage Risks

1. Identify risks:

Risk is a function of M, AV, T, and V:

R = f (M, AV, T, V)

R – risk, M – mission importance, AV – asset values, T – threats, V – vulnerabilities

2. “What”: what is the problem/challenge in managing risks and auditing the ICS? Explain how you might measure

“Why”: why do you need and want to solve the problem?

  “How”: how do you economically solve it?

Identify Security Controls

1. Select security controls based on results from “Industrial Control System Processes Employed” and “Profile ICS Devices”:

Reference either ICS CERT CSET or NIST 800-53, Security and Privacy Controls for Federal Information Systems and Organizations,

http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf

Apply ICS Security Best Practices

1. NIST 800-82, Industrial Control System Security, http://csrc.nist.gov/publications/drafts/800-82r2/sp800_82_r2_draft.pdf

2. Identify unremediated risks and choose risk strategy: Accept risk, avoid risk, mitigate risk, share risk, transfer risk, combination.

Reference: NIST 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems, http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r1.pdf

Identify Vulnerability Continuous Monitoring Strategy

1. Examples:

a. Nessus - Bandolier modules.

b. Metasploit – ICS exploits.

c. Snort

d. Nmap – Identify ICS “friendly” scans.

2. Are these IA certified tools? How so?

a. For example:

i. NIAP: https://www.niap-ccevs.org/CCEVS_Products/pcl.cfm

ii. Common Criteria: https://www.commoncriteriaportal.org/products/

b. For example: Are these tools SCAP-compliant?

3. Create script rules for baselining each ICS system.

a. For example scripts rules should audit:

i. Installed programs.

ii. Users, groups.

iii. Shares.

iv. Services.

v. Processes.

vi. Etc.

Reference

Appendix