ICS-SCADA Security

  1. Contrasting Information Technology and Operational Technology Security
    1. Fundamental Security Priorities
      1. Information Technology Security Focus
        1. Data Confidentiality Protection
          1. Information Integrity Assurance
            1. System Availability Requirements
              1. Compliance and Regulatory Adherence
              2. Operational Technology Security Focus
                1. Personnel and Equipment Safety
                  1. Continuous System Availability
                    1. Process Integrity Maintenance
                      1. Operational Reliability
                        1. Environmental Protection
                      2. System Characteristics and Constraints
                        1. Equipment Lifecycle Management
                          1. Extended Operational Lifespans
                            1. Legacy System Integration Challenges
                              1. End-of-Life Support Issues
                              2. Maintenance and Update Challenges
                                1. Production Downtime Constraints
                                  1. Vendor Support Limitations
                                    1. Change Management Complexity
                                      1. Testing and Validation Requirements
                                      2. Real-Time Operating Requirements
                                        1. Deterministic Response Timing
                                          1. Specialized Hardware Dependencies
                                            1. Performance Optimization Needs
                                            2. Physical World Impact Considerations
                                              1. Safety Risk Assessment
                                                1. Environmental Consequence Management
                                                  1. Economic Impact Evaluation
                                                    1. Regulatory Compliance Requirements
                                                    2. Operating Environment Factors
                                                      1. Harsh Industrial Conditions
                                                        1. Temperature and Humidity Extremes
                                                          1. Electromagnetic Interference
                                                            1. Vibration and Shock Resistance
                                                          2. Purdue Enterprise Reference Architecture
                                                            1. Architecture Model Overview
                                                              1. Level 0 Physical Process Layer
                                                                1. Sensors and Measurement Devices
                                                                  1. Actuators and Control Elements
                                                                    1. Physical Process Equipment
                                                                    2. Level 1 Basic Control Layer
                                                                      1. Programmable Logic Controllers
                                                                        1. Local Control Devices
                                                                          1. Safety Instrumented Systems
                                                                          2. Level 2 Area Supervisory Control
                                                                            1. Human Machine Interfaces
                                                                              1. Area Supervisory Controllers
                                                                                1. Local Data Historians
                                                                                2. Level 3 Site Operations Management
                                                                                  1. Manufacturing Execution Systems
                                                                                    1. Plant Data Historians
                                                                                      1. Operations Management Applications
                                                                                      2. Level 3.5 Industrial Demilitarized Zone
                                                                                        1. Network Segmentation Implementation
                                                                                          1. Security Gateway Deployment
                                                                                            1. Data Exchange Control
                                                                                            2. Level 4 Business Planning and Logistics
                                                                                              1. Enterprise Resource Planning Systems
                                                                                                1. Supply Chain Management
                                                                                                  1. Business Intelligence Applications
                                                                                                  2. Level 5 Enterprise Network Integration
                                                                                                    1. Corporate Information Technology Systems
                                                                                                      1. Cloud Service Connectivity
                                                                                                        1. External Business Partner Integration