ThomasNet Home   |   Promote Your Business
Home  |   My ThomasNet News®  |   Industry Market Trends  |   Submit Release  |   Advertise  |   About Us May 25, 2012  

NIST publishes Guide to Industrial Control Systems Security.

Print | 
Email |  Comment   Share  
June 23, 2011 - NIST has issued final version of its Guide to Industrial Control Systems Security, which is intended to help pipeline operators, power producers, manufacturers, air traffic control centers, and other managers of critical infrastructure to secure their systems while addressing performance, reliability, and safety requirements. Publication provides specific guidance on how to reduce vulnerability of this infrastructure to malicious attacks, equipment failures, and other threats.

Final Version of Industrial Control Systems Security Guide Published


National Institute of Standards & Technology
100 Bureau Dr., Stop 1070
Gaithersburg, MD, 20899-1070
USA



Press release date: June 21, 2011

The National Institute of Standards and Technology (NIST) has issued the final version of its Guide to Industrial Control Systems (ICS) Security (SP 800-82),* intended to help pipeline operators, power producers, manufacturers, air traffic control centers and other managers of critical infrastructures to secure their systems while addressing their unique performance, reliability, and safety requirements.

Pipelines and power transmission systems are key components of the nation's vast critical infrastructure. NIST's new Guide to Industrial Control Systems Security provides specific guidance on how to reduce the vulnerability of this infrastructure to malicious attacks, equipment failures, and other threats to the operation and reliable performance of underpinning control systems.

Copyright: Shutterstock/LiteChoices

Finalized after three rounds of public review and comment, the guide is directed specifically to federally owned or operated industrial control systems (ICS), including those run by private contractors on behalf of the federal government. Examples include the mail handling operations, air traffic control towers, and some electricity generation and transmission facilities and weather observation systems. However, the guide's potential audience is far larger and more diverse than the federal government, since about 90 percent of the nation's critical infrastructure is privately owned.

The guide responds to responsibilities assigned to NIST under the Federal Information Security Management Act (FISMA). The law directs NIST to develop information security standards and guidelines for non-national security federal information systems. While these FISMA-related specifications are not mandatory for the private sector or state and local governments, many businesses and other organizations have adopted the NIST-developed standards and guidelines. Drafts of the new document have been downloaded more than 1,000,000 times, and the guide already is referenced in industry-specific security publications.

Industrial control systems include supervisory control and data acquisition (SCADA) systems, distributed control systems and programmable logic controllers. The scope of facilities and equipment encompassed by these technologies range from broadly dispersed operations, such as natural gas pipelines and water distribution systems, down to individual machines and processes.

Most industrial control systems began as proprietary, stand-alone systems that were separated from the rest of the world and isolated from most external threats. Today, widely available software applications, Internet-enabled devices and other nonproprietary IT offerings have been integrated into most such systems. This connectivity has delivered many benefits, but it also has increased the vulnerability of these systems to malicious attacks, equipment failures and other threats.

As a rule, these systems must operate continuously and reliably, often around the clock. Unlike information technology (IT) systems, which process, store, and transmit digital data, industrial control systems typically monitor the system environment and control physical objects and devices, such as pipeline valves. Disruptions or failures can result in death or injury, property damage, and loss of critical services.

Due to these unique performance, reliability and safety requirements, securing industrial control systems often requires adaptations and extensions to the NIST-developed security standards and guidelines for IT systems only. The new guide describes these adaptations and extensions, provides an overview of various systems and their organizational layouts, describes typical threats and vulnerabilities, and recommends appropriate countermeasures.

"Securing an industrial control system requires a proactive, collaborative effort that engages cyber security experts, control engineers and operators and other experts and experienced workers," says NIST mechanical engineer and lead author Keith Stouffer. "It also requires factoring in-and addressing-new risks introduced by the evolving 'smart' electric power grid."

Stouffer recommends using the new guide along with Guidelines for Smart Grid Cyber Security (NISTIR 7628), which NIST issued last September, to tackle security issues arising from the convergence of the electric power Smart Grid and ICS.

The free 155-page guide can be downloaded from the NIST Computer Security Resource Center at: http://csrc.nist.gov/index.html.

*K. Stouffer, J. Falco and K. Scarfone, Guide to Industrial Control Systems (ICS) Security (SP 800-82). June 2011.

Media Contact: Mark Bello, mark.bello@nist.gov, 301-975-3776
Print | 
Email |  Comment   Share  
Contacts: View detailed contact information.


 

Post a comment about this story

Name:
E-mail:
(your e-mail address will not be posted)
Comment title:
Comment:
To submit comment, enter the security code shown below and press 'Post Comment'.
 



 See related product stories
More .....
Don’t hunt for stories like this.
Let Services
Product News Come to You!
Get a Free Subscription
to Product News Alerts.
Start Your Free
Subscription to
Industry Market Trends.
 See more product news in:
Services
 More New Product News from this company:
NIST-Sponsored Report addresses greenhouse gas measurement.
Disaster/Failure Study Data will be available via NIST website.
NIST Physicist receives 2011 William F. Meggers Award.
More ....
 Other News from this company:
Experts to Discuss Botnet Challenges, Steps for Prevention at May 30 Workshop
Locascio, Cavanagh Assume New NIST Leadership Roles
AIA National Convention Programs Highlight Building Science
Cloud Computing Forum & Workshop V Meets June 5-7 at the Department of Commerce
Next Generation Rail Forums Head to Kansas City and Orlando
More ....
 Tools for you
Watch Company 
View Company Profile
Company web site
More news from this company
E-Mail Story
Save Story
Search for suppliers of
Trade Associations


Home  |  My ThomasNet News®  |  Industry Market Trends  |  Submit Release  |  Advertise  |  Contact News  |  About Us
Brought to you by Thomasnet.com        Browse ThomasNet Directory

Copyright © 2012 Thomas Publishing Company
Terms of Use - Privacy Policy



Error close

Please enter a valid email address