ICS,OT and IT Notes Flashcards
Purdue Model Levels
4/5 - Enterprise, 3.5 - ICS DMZ, 3 - SCADA Operations, 2 - Control System area (HMI), 1- Controllers, PLCs, RTU, 0 - Physical Processes, Sensors, Switches, Relays, Pumps , Valves.
PLC (Programmable Logic Computer)
Connects the physical hardware to the real world, and runs logic code to read state or change the state of the engineering process.
Data Historian
contains data on the industrial control system environment (Changes and trends over time). Targeted for exfiltration of sensitive info.
Engineering Workstation
EW has access to software to program and change PLCs and other field devices. targeted to get access to the code for PLCs and change the processes.
HMI (Human Machine Interface)
Visual interface between the physical process and the operators.
IT Email System (Not ICS)
used to pivot towards data historian. Typically shares a trust relationship with data historians.
What are the 5 Critical ICS Assets
PLC, Data Historian, Engineering Workstation, HMI, and IT Email System
How to defend critical assets
Network Segmentation, Network Monitoring (IDS), Engineering Tasks (Check logic and RUN mode for field devices)
Network Security Monitoring Devices
Switches & Firewalls
PLC Protection
Put devices in “RUN” mode to prevent remote access changes. Check the hash of the project files for critical PLCs. Change Management at the PLC level.
Data Historian Protection
Any data coming into data historian monitoring, exfiltration from data historian monitoring, Separate AD and domain environment from IT AD, & no trust relationships
Engineering Workstation Protection
Network monitoring, Data exfiltration (USB removable media), and network-specific commands from the device (Ports and remote access ports).
HMI Protection
Monitor network-specific traffic from HMI, Changes to the HMI, application logs, or alarm logs, Jump box in DMZ
IT Email System Protection
Sandboxing for URL, Attachments, etc. IT Security and awareness of ICS, IT security provides data to ICS security.
Asset Inventory