The objective of an Industrial Control System security program is to define the desired security stance of the industrial network (the IDMZ and lower levels), identify current deviation, and strategize improvement activities. The resulting program will be comprised of a repetitive set of activities geared towards establishing, improving, and maintaining a healthy ICS security posture.
The following figure shows a summary of the resulting ICS security program. It follows the aforementioned NIST standards and builds upon the CPwE security framework, as discussed in an earlier chapter. The summary figure helps to illustrate the activities that went into designing the program, which we will look at in more detail in the next sections.
The following activities were performed during the development process of the ICS security program:
- Define ICS-specific policies
- Define and inventory the ICS assets
- Perform an initial risk assessment on discovered ICS assets...