Securing Remote Access to SCADA During the Pandemic Era
DOI:
https://doi.org/10.15680/IJCTECE.2022.0502006Keywords:
SCADA, industrial control systems, remote access, Zero Trust, pandemic, OT security, critical infrastructure.Abstract
When COVID-19 arrived in the early part of 2020, it made clear for many operators that their old assumptions about engineers, vendor technicians and systems integrators accessing Supervisory Control and Data Acquisition systems had to go. Field offices shut down. Visits to site were cancelled. Downtime maintenance grew short because of a reduced workforce available on-site. Still, the gas pipes kept moving product, the lights were not shut off and the local water company was treating the supply to homes throughout its region. This document takes a look at the consequences of that transition for security and how the industry architects responded in patterns. It is informed by incidents occurring between 2020 and the spring of 2022 and references the advice put forth by the National Institute of Standards and Technology, CISA and the International Electrotechnical Commission during that timeframe. I suggest a phased approach to remote access: creating a specific Industrial Demilitarized Zone, requiring engineers or vendor technicians to "jump" to specific protected computers or systems hosted in that DMZ, multifactor authentication, systems for managing privileged accounts and the application of Zero Trust policies. My main idea is for the readers - operators of critical infrastructure - to have working patterns for making remote connections safer without interrupting the rate at which the facilities operate
References
[1] U.S. Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation, “DarkSide Ransomware: Best Practices for Preventing Business Disruption from Ransomware Attacks,” Joint Advisory AA21-131A, May 2021.
[2] T. J. Williams, “The Purdue Enterprise Reference Architecture,” Computers in Industry, vol. 24, no. 2–3, pp. 141–158, 1994.
[3] K. Stouffer, V. Pillitteri, S. Lightman, M. Abrams, and A. Hahn, “Guide to Industrial Control Systems (ICS) Security,” NIST Special Publication 800-82 Revision 2, May 2015.
[4] International Electrotechnical Commission, “IEC 62443: Security for Industrial Automation and Control Systems,” multi-part series, 2013–2020.
[5] Dragos, Inc., “Year in Review 2021: ICS/OT Cybersecurity,” February 2022.
[6] IBM Security and Ponemon Institute, “Cost of a Data Breach Report 2021,” July 2021.
[7] Verizon, “2021 Data Breach Investigations Report,” May 2021.
[8] Joint advisory from the Federal Bureau of Investigation, the U.S. Secret Service, and the Cybersecurity and Infrastructure Security Agency, “Compromise of U.S. Water Treatment Facility,” February 2021.
[9] U.S. Department of Homeland Security, Transportation Security Administration, “Security Directive Pipeline-2021-01 and Pipeline-2021-02,” May–July 2021.
[10] U.S. Federal Bureau of Investigation, public statement on the JBS USA cyber incident, June 2021.
[11] U.S. Cybersecurity and Infrastructure Security Agency, “Apache Log4j Vulnerability Guidance,” Alert AA21-356A, December 2021.
[12] U.S. Cybersecurity and Infrastructure Security Agency, “Implementing Strong Authentication,” guidance materials, 2020–2021.
[13] J. Kindervag, “No More Chewy Centers: Introducing the Zero Trust Model of Information Security,” Forrester Research, September 2010.
[14] S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, August 2020.
[15] The White House, “Executive Order 14028: Improving the Nation’s Cybersecurity,” May 12, 2021.
[16] World Economic Forum, “The Global Risks Report 2021,” 16th Edition, January 2021.
[17] European Union Agency for Cybersecurity (ENISA), “Threat Landscape 2021,” October 2021

