ASE Labs
Welcome Guest. Please register or log in now. There are 237 people online (0 Friends).
  • Home
  • Articles
  • News
  • Forum
  • Register/Login

Cyber Security Standard Published to Protect Global Critical Infrastructure

Poster: SySAdmin
Posted on November 10, 2010 at 5:07:01 AM
Cyber Security Standard Published to Protect Global Critical Infrastructure

DEN HAAG, Netherlands, November 10, 2010/PRNewswire/ --

    - The International Instrument Users Association (WIB) Releases
Comprehensive Cyber Security Standard to Protect Critical Industrial Computer
Systems from Cyber Attack

    The International Instrument Users Association (WIB), an international
organization that represents global manufacturers in the industrial
automation industry, announced the second version of the Process Control
Domain - Security Requirements For Vendors document - the first international
standard that outlines a set of specific requirements focusing on cyber
security best practices for suppliers of industrial automation and control
systems.

    "We are pleased to announce today the second version of our cyber
security standard," said Alex van Delft, Competence Manager Process Control
at DSM and Chairman of the WIB. "This is an important step in the ongoing
process to improve the reliability of our critical manufacturing and
production systems and provides end-users the ability to now communicate
their expectations about the security of process automation, control and
safety systems."

    "We Are Now Entering A Period Of Consequences"

    With industrial networks being increasingly connected to the hostile IT
world, and the frequency and sophistication of malware growing exponentially,
industrial stakeholders must act today to protect their critical systems.
Whether it is a targeted attack like Stuxnet, or an accidental disruption, a
single cyber incident can cost millions of dollars in lost revenue,
jeopardize employee and public safety and potentially disrupt national
critical infrastructure.

    "Our increasingly connected production systems are facing a growing
threat on a daily basis and we must do all we can to ensure a safe and secure
operational environment," said Peter Kwaspen, Strategy & Development Manager,
EMEA Control & Automation Systems at Shell Projects & Technology. "This
document provides the common language we need to communicate our expectations
around security to our suppliers and the framework to work together to help
improve the overall security posture for our critical systems."

    Led by major companies such as Shell, BP, Saudi Aramco, Dow, DuPont,
Laborelec, Wintershall and dozens of other end-users, as well as leading
vendors such as Invensys and Sensus and multiple government agencies, the
group spent two years developing the requirements and piloting a
certification program to ensure a functional, scalable and ultimately
valuable result.

    "The security requirements outlined in the document went through a year
of comments/revisions from over 50 global stakeholders and were subjected to
a thorough pilot certification program over the last 8 months," said Jos
Menting, cyber security advisor GDF Suez Group. "We've now come to a truly
functional cyber security standard based on the needs of end-users and it is
now up to us, the end-users, to take advantage of this effort and insist that
our vendors are certified."

    Members of the WIB Plant Security Working group have already started
implementing the requirements into their procurement processes and others
around the world are heeding the clarion call.

    "Shell has mandated conformance to the WIB standard for all vendors
supplying systems to be deployed in Shell's process control environment
starting January 01, 2011," said Ted Angevaare, PACO EMEA Control &
Automation Systems Team Leader. "These requirements will become a standard
part of the procurement language saving us a significant amount of time and
effort."

    Leading suppliers of industrial process control and automation systems
are also starting the process of integrating the requirements into their
organizations.

    "Adopting the WIB's security requirements ensures that Invensys has a set
of measurable practices in place that enforce a safer and more secure
critical infrastructure. Not only do the requirements provide current-state
measures, they allow us to continue to improve and adapt to the ever-changing
security landscape," said Ernie Rakaczky, program manager for control systems
cyber security at Invensys Operations Management. "From our perspective, this
program is a major shift, not only focusing on tactics, but one that puts
into place strategic elements that address operational change."

    Cyber Security at All Stages of The Industrial Product Lifecycle

    The WIB standard is designed to fit the needs of the end-user - the
system owner/operator - and reflects the unique requirements for industries
like oil and gas, electric power, smart grid, transportation, pharmaceutical,
and chemical. The goal is to address cyber security best practices and
allocate responsibility at the various stages of the industrial system
lifecycle: Organizational practices, product development, testing and
commissioning and maintenance and support.

    "Security is not a one-time application, but rather a process in which
every stakeholder must contribute in order to achieve any significant
improvement in operational reliability," said Auke Huistra, project manager
at National Infrastructure against Cyber Crime (NICC). "The WIB requirements
are designed with this principle at its core and we are encouraging critical
infrastructure stakeholders in The Netherlands to integrate the requirements
into their cyber security plans."

    The requirements were also constructed to address a broad range of cyber
security topics relevant to industrial stakeholders; from high-level
requirements for vendor's internal security policies, procedures, and
governance, to specific requirements concerning access/authentication, data
protection, default password protection and patch management. When a vendor's
solution complies with this set of requirements, the solution is considered
by the WIB to be Process Control Domain Security Compatible.

    The requirements are further broken down into 3 levels designed to
reflect various starting points of global suppliers and provide a scalable
framework to plan improvements over time. In the program, there are Gold,
Silver and Bronze levels, each consisting of a set requirements designed to
verify that applicable policies and practices are in place, enabled and
practiced by the vendor.

    A Successful Global Cooperation

    From the beginning, industry leaders recognized that given the global
nature of industrial cyber security, any effort to standardize cyber security
best practices required stakeholder cooperation from different industry
sectors and in different regions of the world. The WIB association was the
ideal conduit to guide the creation of the standard given its independent
nature and membership composition. Additionally, the initiative needed to
reflect and incorporate the important cyber security activities happening
internationally so many government agencies, industry working groups and
standards bodies were consulted to ensure harmony. For example, major
industry standards efforts such as ISA SP99, NIST 800-53, NISTIR 7628 and
various international government regulations such as NERC/CIP were reviewed
and incorporated where appropriate or expanded to ensure testability. The WIB
executive committee has started the process of introducing the WIB PCD
requirements into the CEN/CENELEC and IEC international standards framework.

    For more information on the WIB Process Control Domain Security
Requirements standard visit http://www.wib.nl or to download a copy, please
visit http://www.wib.nl/download.html or http://www.isssource.com/wib.

Source: International Instrument Users Association (WIB)

Michelle Palmer, +001-630-240-0705, mpalmer@mediasolvegroup.com, for WIB; or Tom Kuperij, Managing Director of WIB, +31-70-3560092
 
Print This Entry
Tags PR Press Release
Related Articles
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
Login
Welcome Guest. Please register or log in now.
Forgot your password?
Navigation
  • Home
  • Articles
  • News
  • Register/Login
  • Shopping
  • ASE Forums
  • Anime Threads
  • HardwareLogic
  • ASE Adnet
Latest News
  • Kingston HyperX Cloud 2 Pro Gaming Headset Unboxing
  • Synology DS415+ Unboxing
  • D-Link DCS-5020L Wireless IP Pan/Tilt IP Camera
  • Actiontec WiFi Powerline Network Extender Kit Unboxing
  • Durovis Dive Unboxing
  • Bass Egg Verb Unboxing
  • Welcome to the new server
  • Gmail Gets Optional Preview Pane
  • HBO Go on Consoles
  • HP Touchpad Update
Latest Articles
  • D-Link Exo AC2600 Smart Mesh Wi-Fi Router DIR-2660-US
  • HyperX Double Shot PBT Keys
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones
  • ScharkSpark Beginner Drones
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera
  • Contour Unimouse Wireless Ergonomic Mouse
  • HyperX Cloud Alpha Pro Gaming Headset
  • Linksys Wemo Smart Home Suite
  • Fully Jarvis Adjustable Standing Desk
Latest Topics
  • Hello
  • Welcome to the new server at ASE Labs
  • Evercool Royal NP-901 Notebook Cooler at ASE Labs
  • HyperX Double Shot PBT Keys at ASE Labs
  • Avantree ANC032 Wireless Active Noise Cancelling Headphones at ASE Labs
  • ScharkSpark Beginner Drones at ASE Labs
  • HyperX Alloy FPS RGB Mechanical Gaming Keyboard at ASE Labs
  • D-Link DCS-8300LH Full HD 2-Way Audio Camera at ASE Labs
  • Kingston SDX10V/128GB SDXC Memory at ASE Labs
  • What are you listening to now?
  • Antec Six Hundred v2 Gaming Case at HardwareLogic
  • Sans Digital TR5UTP 5-Bay RAID Tower at HardwareLogic
  • Crucial Ballistix Smart Tracer 6GB PC3-12800 BL3KIT25664ST1608OB at HardwareLogic
  • Cooler Master Storm Enforcer Mid-Tower Gaming Case at HardwareLogic
  • Arctic M571-L Gaming Laser Mouse at ASE Labs
  • Contour Unimouse Wireless Ergonomic Mouse at ASE Labs
Advertisement
Advertisement
Press Release
  • Huntkey Has Launched Its New Power Strips with USB Chargers on Amazon US
  • Inspur Releases TensorFlow-Supported FPGA Compute Acceleration Engine TF2
  • Hot Pepper Introduces Spicy New Smartphones in US Markets
  • Sharp Introduces New Desktop Printers For The Advanced Office
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • DJI Introduces Mavic 2 Pro And Mavic 2 Zoom: A New Era For Camera Drones
  • Fujifilm launches "instax SQUARE SQ6 Taylor Swift Edition", designed by instax global partner Taylor Swift
  • Huawei nova 3 With Best-in-class AI Capabilities Goes on Sale Today
  • Rand McNally Introduces Its Most Advanced Dashboard Camera
  • =?UTF-8?Q?My_Size_to_Showcase_Its_MySizeId=E2=84=A2_Mobil?= =?UTF-8?Q?e_Measurement_Technology_at_CurvyCon_NYC?=
Home - ASE Publishing - About Us
© 2010 Aron Schatz (ASE Publishing) [Queries: 16 (8 Cached)] [Rows: 292 Fetched: 35] [Page Generation time: 0.45028305053711]