Attachment_14_--_San_Diego_Upgrade_Strategy_DRAFT.docx
DOCX document 1 MB Posted
- Attached to
- Operation & Maintenance for SBIWTP Federal contract opportunity
- Solicitation number
- IBM15R0001
About this file
ATTACHMENT 14
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Control Assessment and Recommendation
IBWC San Diego SCADA Upgrade Strategy and Information System Security Plan
DRAFT
December 30, 2014 Attachment 14
TABLE OF CONTENTS
| 1.0 Executive Summary | 1 |
| 2.0 INTRODUCTION | 1 |
| 3.0 ROLES AND RESPONSIBILITIES | 2 |
| 4.0 SECURITY PROGRAM | 3 |
| 5.0 UPGRADE RECOMMENDATIONS | 3 |
| The sections below are the upgrade recommendations based on the Security Assessment Report (SAR) provided in December 2013. | 3 |
| 5.1 Security Policy | 3 |
| 5.2 Configuration Management | 3 |
| 5.3 Active Directory | 4 |
| 5.4 Asset Management | 4 |
| 5.5 SCADA System Architecture | 4 |
| 5.5.1 PLCs | 5 |
| 5.6 Current Configuration | 9 |
| 5.7 Anti-Virus | 12 |
| 5.8 Contingencies – Disaster Recovery & Redundancy | 12 |
| 5.8.1 Recovery | 12 |
| 5.8.2 Redundancy | 12 |
| 5.9 Vulnerability Management | 13 |
| 5.10 Current Risks | 13 |
| 6.0 Upgrade Plans | 14 |
| 6.1 Control Equipment and Firmware Updates | 14 |
| 6.2 SCADA Software and Equipment Updates | 16 |
| 6.2.1 Servers | 16 |
| 6.2.2 Clients | 17 |
| 7. Network Upgrade | 18 |
| 8. Physical and Environmental Security | 19 |
| 9. Communications and Operations Management | 19 |
| 10. 24/7 Continuous Monitoring | 20 |
| 11. Access Control | 20 |
| 11. Information Systems Acquisition, Development and Maintenance | 21 |
| 12. Information Security Incident Management | 21 |
| 13. Contingency Planning and Business Continuity Management | 22 |
| 14. Compliance | 23 |
| 15. Risk Management | 23 |
| 16. Awareness and Training | 25 |
| Human Resources Security | 25 |
LIST OF FIGURES
| Figure 5-2 Ethernet connection to PLC5 | 6 |
| Figure 5-3: Current PLC Configuration | 8 |
| Figure 5-4: Current Configuration | 11 |
LIST OF TABLES
| Table 5- 1: Ethernet Connections to DR+ Modules | 5 |
| Table 5- 2: MicroLogix PLCs | 6 |
| Table 5- 3: ControlLogix PLCs and EBNet Modules | 7 |
| Table 5- 4: Flex I/O Drops | 8 |
| Table 5- 5: Current Connected Equipment | 9 |
i
1.0 Executive Summary
Presidential Policy Directive 21 (PPD-21) was released on February 12, 2014. It established a federal policy addressing resilience in the critical infrastructure. The policy spans public and private information system owners and operators and mandates the strengthening of the critical infrastructure (including Federal facilities).
A Security Test and Evaluation (ST&E) was performed on the South Bay International Water Treatment Plant (SBIWTP) Supervisory Control and Data Acquisition (SCADA) System during December 2013. This test included an audit of policies, procedures, and facilities, as well as non-intrusive cyber security tests. The test identified deficiencies related to the SBIWTP SCADA system. Several security weaknesses were identified including the following:
· Minimal support to the Windows operating system.
· Legacy SCADA software
· Shared workstation and SCADA component user accounts
· Limited backup procedures
· Poor disaster recovery planning The weaknesses identified during the ST&E process must be corrected or mitigated to ensure that effective security services are maintained for the SBIWTP SCADA environment.
A Risk Assessment of SBIWTP was also performed during December 2013. This assessment identified several risks that are categorized into three (3) different impact levels (Low, Medium, and High). They were also separated into three (3) different Control categories (Management, Operational, and Technical). The most significant risk for each control is shown below:
· Management - the lack of vulnerability scanning or remediation;
· Operational – contingency planning and a lack of system backup and recovery procedure
· Technical – lack of Identification and Authentication procedures.
A SCADA Security Design Report has been created for SBIWTP and is provided below. The report is based upon best practices that are currently being adopted throughout the industry, and it follows guidance promulgated by the National Institute of Standards and Technology (NIST). This report discusses a top-down approach for implementing and managing a security program for the SCADA system of SBIWTP.
2.0 INTRODUCTION
Today's federal environment is changing rapidly and it is becoming increasingly technical. Consequently, new laws that govern information security require federal agencies to adopt a minimum set of security controls to protect their information systems. Federal Information Processing Standard (FIPS) 200, Minimum Security Requirements for Federal Information and Information Systems, specifies the minimum security requirements to be addressed for federal information systems. These requirements span seventeen (17) security areas.
The SBIWTP SCADA security program will follow guidance given in NIST SP 800-82 Guide to Industrial Control Systems (ICS) Security. This publication combines best practices from NIST SP 800-53 Recommended Security Controls for Federal Information Systems and ANSI/ISA 99: 02-01:2009 Security for Industrial Automation and Control Systems: Establishing an Industrial Automation and Control Systems Security Program. The program aims to construct reportable metrics and repeatable processes that can be used to improve the security posture of the entire organization.
3.0 ROLES AND RESPONSIBILITIES
Information System Security Manager The ISSM is responsible for information security for all USIBWC systems. ISSM responsibilities include:
A. reducing risk exposure, B. Ensuring the agency’s activities do not introduce unnecessary risk to the enterprise.
C. Ensuring compliance with all applicable security policies, standards, , state/federal regulations, and security initiatives
| Information System Security Officer | The ISSO is the incident response point of contact for communicating with State Incident Response Team and coordinating agency actions that respond to an information security incident. |
| SCADA Systems Analyst | The SSA responsibilities include Onsite: |
A. Maintenance of SCADA system documentation B. Incident Response and configuration management of SCADA system componets.
C. Vulnerability and patch management testing and implementation D. SCADA system disaster recovery and training E. Backup Procedures F. Software and Hardware Inventory G. Authorization and Authentication H. SCADA Physical Security Administrators/Operators Are responsible for complying with all applicable provisions of policies, procedures and practices.
4.0 SECURITY PROGRAM
The objective of the SBIWTP SCADA security program is to demonstrate due diligence by creating reportable metrics and repeatable processes that address security vulnerabilities and mitigate their associated risks to the environment. Governance and compliance are the driving components for the long-term strategy of the security program. Proper compliance requires support executive management.. The security program will be developed within the paradigm of addressing SBIWTP’s business needs As the security program matures over time, the goal will be to underline the importance of the following:
1. Developing security policies to address information security requirements.
2. Implementing reasonable security controls to manage SBIWTP security risks which feed into the overall business risks.
3. Ensuring all users are aware of their responsibility to protect organizational assets.
4. Monitoring and reviewing the performance and effectiveness of and the security program
5. Continual improvement based on changes to the organizational risk posture.
5.0 UPGRADE RECOMMENDATIONS
The sections below are the upgrade recommendations based on the Security Assessment Report (SAR) provided in December 2013.
5.1 Security Policy
Policies and procedures should be developed for SBIWTP. The objective of information security policy is to provide minimum requirements for information security that align with the SBIWTP business needs. These policies must also address all applicable laws and regulations that oversee the SBIWTP. Information security policies will be approved by executive management personnel. The policies will then be published and distributed to all employees and relevant stakeholders..
Information security policies will be reviewed over assigned intervals and they will be revisited to incorporate significant changes to the SBIWTP SCADA environment. These reviews will evaluate a policy’s adequacy; they will be updated when necessary. Each policy will have an appropriate owner who will assume the responsibility of the development, review, and evaluation of the policy.
5.2 Configuration Management
A baseline configuration should be developed to include the United States Government and Configuration Baseline (USGCB) for windows devices. Further, SBIWTP should test, validate, and document changes to the SCADA system in a staging environment before deploying the changes to production. Once a configuration change request is approved, a workflow entry is placed in a queue for review. Before approval, the, SBIWTP should perform a security impact analysis to verify that all controls are functioning properly.
5.3 Active Directory
Active Directory should be deployed to control access privileges to specific assets, Users should be given functions commensurate with his or her assigned job functions.
5.4 Asset Management
The objective of asset management is to monitor all assets throughout their lifecycles within SBIWTP. All assets will be identified. Further, asset owners will be assigned appropriately who will assume the responsibility of accounting for them. Asset ownership will be aligned with information system ownership. Asset owners will be responsible for developing and distributing Acceptable Use Policies (AUP)s to the asset users..
5.5 SCADA System Architecture
The SCADA system is directly connected to Programmable Logic Controllers (PLC). The SCADA system provides a graphical representation of the system’s status, and provides operational parameters to SBIWTP industrial control equipment.
The current SCADA system is comprised of Rockwell Automation FactoryTalk View SE version 5.10. It is deployed in a redundant configuration on two (2) physical servers and 14 “fat” clients. There are three (3) sets of the SCADA server configurations. The SCADA servers run the Microsoft Windows 2003 R2 operating system. The clients run the Microsoft Windows XP operating system. The current version of the FactoryTalk View SE is not supported on operating systems newer than Microsoft Server 2003 R2 or Windows XP. There is an Active Directory Server connected to this system running on a standalone server. Its operating system is Microsoft Server 2008 R2. The FactoryTalk View SE utilizes Active Directory for user authentication.
An upgrade of the system platform and the operating system is strongly recommended because Microsoft has ended support for these operating systems. There are too many risks to keep these legacy systems in production.
The SCADA system uses Moxa Ethernet switches to connect all of the Ethernet devices. The network is deployed in a star configuration utilizing both copper and fiber wires. The switches are currently not monitored to display status information on the SCADA system.
Figure 5-1 shows the general configuration of the current SCADA system.
Figure 5-1 SCADA System Configuration
5.5.1 PLCs
The PLCs are directly connected to the SCADA computers. The PLC controls all of the system functions including turning pumps on and off, and opening and closing valves. There is currently a mix of Rockwell Automation PLC’s deployed throughout the system.
5.5.1.1 PLC5
There are several Rockwell Automation 1771-L40B (PLC5) PLC’s deployed in a “Hot-Backup” configuration. All of these PLCs utilize Data Highway + (DH+) for communication to other PLCs. There is no direct connection to the Ethernet network. Consequently, these PLCs were not recorded in the risk assessment document. There are ControLogix Ethernet bridges that create the link from Ethernet to DH+. Below is the list of Ethernet bridges to DH+ modules:
Table 5- 1: Ethernet Connections to DR+ Modules
| Location |
| IP Address |
| Part Number |
| Release |
| Firmware |
| LCP-HWE |
| 192.168.2.125 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-HWE
| 1756-DHRIO |
| C |
| 4.1 |
| LCP-PSTE |
| 192.168.2.126 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-PSTE
| 1756-DHRIO |
| D |
| 6.3 |
| LCP-NaOCl |
| 192.168.2.127 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-NaOCl
| 1756-DHRIO |
| C |
| 4.1 |
| LCP-SP |
| 192.168.2.128 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-SP
| 1756-DHRIO |
| C |
| 4.1 |
| LCP-HWE |
| 192.168.2.150 |
| 1756-ENBT |
| A |
| 6.1 |
LCP-HWE
| 1756-DHRIO |
| E |
| 7.2 |
Figure 5-2 shows the typical connection from Ethernet to the PLC5.
Figure 5-1 Ethernet connection to PLC5
5.5.1.2 MicroLogix 1400
There are a total of five (5) 1766-L32AWA (MicroLogix 1400) PLC’s directly connected to the Ethernet network. Below is the list of MicroLogix PLC’s used in the system with current configuration information.
Table 5- 2: MicroLogix PLCs
| Location |
| IP Address |
| Part Number |
| Release |
| Firmware |
| Belt Press Bldg. |
| 192.168.2.135 |
| 1766-L32AWA |
| B |
| 11 |
| Belt Press Bldg. |
| 192.168.2.136 |
| 1766-L32AWA |
| B |
| 10 |
| Belt Press Bldg. |
| 192.168.2.137 |
| 1766-L32AWA |
| B |
| 11 |
| Belt Press Bldg. |
| 192.168.2.138 |
| 1766-L32AWA |
| B |
| 11 |
| LCP-ADMIN |
| 192.168.2.242 |
| 1766-L32AWA |
| B |
| 11 |
5.5.1.3 CONTROLOGIX
There are a total of three (3) ControLogix PLC’s connected to the Ethernet network via ENBT Ethernet module. Below is the list of ControLogix PLCs and ENBT modules used in the system with current configuration information.
Table 5- 3: ControlLogix PLCs and EBNet Modules
| Location |
| IP Address |
| Part Number |
| Release |
| Firmware |
| LCP-ADMIN-PCC |
| 192.168.2.222 |
| 1756-ENBT |
| A |
| 1.4 |
| LCP-ADMIN-PCC |
| 192.168.2.223 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-ADMIN-PCC
| 1756-L64 |
| B |
| 17.2 |
| LCP-BSC |
| 192.168.2.236 |
| 1756-ENBT |
| A |
| 4.8 |
LCP-BSC
| 1756-L61 |
| B |
| 17.3 |
| LCP-B1 |
| 192.168.2.237 |
| 1756-ENBT |
| A |
| 4.8 |
LCP-B1
| 1756-L61 |
| B |
| 17.3 |
| LCP-B2 |
| 192.168.2.238 |
| 1756-ENBT |
| A |
| 4.8 |
LCP-B2
| 1756-L61 |
| B |
| 17.3 |
| LCP-B3 |
| 192.168.2.239 |
| 1756-ENBT |
| A |
| 4.8 |
LCP-B3
| 1756-L61 |
| B |
| 17.3 |
| LCP-HWE |
| 192.168.2.150 |
| 1756-ENBT |
| A |
| 6.1 |
LCP-HWE
| 1756-L63 |
| B |
| 19.11 |
Figure 5-3 shows the general configuration of the PLC’s.
Figure 5-2: Current PLC Configuration Flex I/O The Rockwell Automation Flex I/O is directly connected to the Ethernet network. There are 12 racks of Flex I/O currently on the network. Below is a list of the Flex I/O drops:
Table 5- 4: Flex I/O Drops
| Location |
| IP Address |
| Part Number |
| Release |
| Firmware |
| LCP-DAF Drop 50 |
| 192.168.2.224 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-DAF Drop 51 |
| 192.168.2.225 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 20 |
| 192.168.2.226 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 21 |
| 192.168.2.227 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 22 |
| 192.168.2.228 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 23 |
| 192.168.2.229 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 24 |
| 192.168.2.230 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 30 |
| 192.168.2.231 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 31 |
| 192.168.2.232 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 32 |
| 192.168.2.233 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 33 |
| 192.168.2.234 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SSKPS Drop 40 |
| 192.168.2.235 |
| 1794-AENT |
| B |
| 4.2 |
5.6 Current Configuration
Currently the overall connection of the system is in a general star configuration. There are no zones to separate the equipment. This allows easy access to all equipment once access is gained to the Ethernet network.
Below shows all of the equipment onsite that is connected to the Ethernet:
Table 5- 5: Current Connected Equipment
| Location |
| New IP Address |
| Part Number |
| Version |
| Firmware |
| LCP-HWE |
| 192.168.2.125 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-HWE
| 1756-DHRIO |
| C |
| 4.1 |
| LCP-PSTE |
| 192.168.2.126 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-PSTE
| 1756-DHRIO |
| D |
| 6.3 |
| LCP-NaOCl |
| 192.168.2.127 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-NaOCl
| 1756-DHRIO |
| C |
| 4.1 |
| LCP-SP |
| 192.168.2.128 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-SP
| 1756-DHRIO |
| C |
| 4.1 |
| Belt Press Bldg. |
| 192.168.2.135 |
| 1766-L32AWA |
| B |
| 11 |
| Belt Press Bldg. |
| 192.168.2.136 |
| 1766-L32AWA |
| B |
| 10 |
| Belt Press Bldg. |
| 192.168.2.137 |
| 1766-L32AWA |
| B |
| 11 |
| Belt Press Bldg. |
| 192.168.2.138 |
| 1766-L32AWA |
| B |
| 11 |
| LCP-HWE |
| 192.168.2.150 |
| 1756-ENBT |
| A |
| 6.1 |
LCP-HWE
| 1756-DHRIO |
| E |
| 7.2 |
LCP-HWE
| 1756-L63 |
| B |
| 19.11 |
| LCP-Admin |
| 192.168.2.175 |
| PT-7324 |
1.3
| LCP-DAF |
| 192.168.2.176 |
| EDJ-508A |
| LCP-ASTN |
| 192.168.2.177 |
| EDJ-516A |
| LPC-SST |
| 192.168.2.178 |
| EDJ-516A |
| LCP-SSKPS1 |
| 192.168.2.179 |
| EDJ-508A |
| LCP-Admin |
| 192.168.2.180 |
| PT-7710 |
| LCP-ADMIN-PCC |
| 192.168.2.222 |
| 1756-ENBT |
| A |
| 1.4 |
| LCP-ADMIN-PCC |
| 192.168.2.223 |
| 1756-ENBT |
| A |
| 1.4 |
LCP-ADMIN-PCC
| 1756-L64 |
| B |
| 17.2 |
| LCP-DAF Drop 50 |
| 192.168.2.224 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-DAF Drop 51 |
| 192.168.2.225 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 20 |
| 192.168.2.226 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 21 |
| 192.168.2.227 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 22 |
| 192.168.2.228 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 23 |
| 192.168.2.229 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-ASTN Drop 24 |
| 192.168.2.230 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 30 |
| 192.168.2.231 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 31 |
| 192.168.2.232 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 32 |
| 192.168.2.233 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SST1 Drop 33 |
| 192.168.2.234 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-SSKPS Drop 40 |
| 192.168.2.235 |
| 1794-AENT |
| B |
| 4.2 |
| LCP-BSC |
| 192.168.2.236 |
| 1756-ENBT |
| A |
| 4.8 |
LCP-BSC
| 1756-L61 |
| B |
| 17.3 |
| LCP-B1 |
| 192.168.2.237 |
| 1756-ENBT |
| A |
| 4.8 |
| LCP-B2 |
| 192.168.2.238 |
| 1756-ENBT |
| A |
| 4.8 |
| LCP-B3 |
| 192.168.2.239 |
| 1756-ENBT |
| A |
| 4.8 |
LCP-B3
| 1756-L61 |
| B |
| 17.3 |
| LCP-B4 |
| 192.168.2.240 |
| 1756-ENBT |
| A |
| 4.8 |
| LCP-ADMIN |
| 192.168.2.242 |
| 1766-L32AWA |
| B |
| 11 |
Figure 5-4 shows the general configuration of the system. Please note that not all devices/PLC’s are shown.
Figure 5-3: Current Configuration
5.7 Anti-Virus
The HMI computers run Norton Antivirus (AV). However, the AV definitions are seven years out of date. No program or policy exists for AV updates. We observed that antivirus scans were running, or the AV dashboard was overlaid on top of process graphics, on some HMIs during the course of the work day.
No SCADA test station is available for validating software or AV updates, so the system is vulnerable to updates which are untested and which could compromise the availability of the system.
A workshop should be held with NIWTP and IBWC IMD to define the configuration, tuning, and updating of antivirus software on the SCADA top-end. Personnel should be assigned roles in the maintenance of the AV system and the auditing of AV logs and reports.
5.8 Contingencies – Disaster Recovery & Redundancy
The top-end SCADA system, by definition, is a supervisory system overlaid on an ICS. Since the ICS operates on embedded controllers independent of the SCADA system, the ICS is capable of running itself during a SCADA failure. The ICS has locally configured control set points, alarm and shut down limits which should be operable regardless of the SCADA system status.
There is no disaster recovery capability. Both SCADA servers are located in the same building. The operations team would like for the SCADA system to have a secondary presence in the Administration building.
Each existing SCADA server is paired with a standalone uninterruptible power supply (UPS). The batteries in these UPS units typically last three to five years. Since the installed models are no longer produced, and due to their age, they are considered end-of-life.
5.8.1 Recovery
If a SCADA server fails or causes its application to be inoperable, then the system should have a method of efficiently using a recent disc image to rebuild that server’s configuration as soon as a reliable server can be installed. This type of disc image restoration should allow for a manual recovery to full HMI application operability typically within one day.
Key operating set points, if not stored in PLC hardware, should be configured as retentive in the HMI application so that they are still set correctly after restarting the application (or rebuilding it off a recent backup).
5.8.2 Redundancy
The top-end SCADA system should be composed of two or more HMI application servers. The Control Building application server (primary) should be used for all HMI configuration as well as runtime functionality. Additional HMI application servers, such as the one in the Admin Building (secondary), should synchronize their configuration
5.9 Vulnerability Management
The main objective of vulnerability management is to detect and remediate vulnerabilities in a timely fashion. A vulnerability management process should be part of IBWC’s effort to control information security risks. This process will allow an organization to obtain a continuous overview of vulnerabilities in their IT environment and the risks associated with them. Only by identifying and mitigating vulnerabilities in the IT environment can an organization prevent attackers from penetrating their networks and stealing information.
A vulnerability management lifecycle consists of five phases:
· Preparation
· Define scope
· Inform asset owners and IT
· Plan the scans
· Vulnerability scan
· Start vulnerability scan
· Monitor stability & performance of systems under scan
· Communicate issues
· Receive scans results
· Define remediating actions
· Analyze Vulnerabilities and associated risk
· Provide input and recommendations for risk remediation
· Waiver Process (for risk acceptance)
· Implement remediating actions
· Implement Corrective Actions
· Feedback on implementation of corrective actions
· Discuss alternatives
· Rescan
· Perform Rescan
· Analyze Results
· Feedback on rescan results The organization should perform ongoing vulnerability scans of the SCADA environment to identify big security gaps during the periods between scheduled scans. In contrast a continuous vulnerability management requires at least a monthly scan of the entire environment which reduces the risks that IBWC faces.
5.10 Current Risks
The current risk with the given configuration is the lack of zones in the network. If any device on the network becomes compromised, the whole system is exposed. Almost all of the controls equipment is not at the latest firmware revisions. These risks will be addressed in the upgrade plan.
6.0 Upgrade Plans
This section describes the upgrade plans to the SCADA system.
6.1 Control Equipment and Firmware Updates
Rockwell Automation provides firmware updates via the internet. The control equipment should be maintained/updated at least once per year. This will assist in keeping the latest patches in the equipment and consistent operation if all of the hardware is at the same level of firmware. The following is the list of available updates for the various control equipment:
Table 6- 1: Available Updates For Control Equipment
| Location |
| IP Address |
| Part Number |
| Version |
| Installed Firmware |
| Firmware Available |
| LCP-HWE |
| 192.168.2.125 |
| 1756-ENBT |
| A |
| 1.4 |
| 6.6 |
LCP-HWE
| 1756-DHRIO |
| C |
| 4.1 |
| 5.4 |
| LCP-PSTE |
| 192.168.2.126 |
| 1756-ENBT |
| A |
| 1.4 |
| 6.6 |
LCP-PSTE
| 1756-DHRIO |
| D |
| 6.3 |
| 6.3 |
| LCP-NaOCl |
| 192.168.2.127 |
| 1756-ENBT |
| A |
| 1.4 |
| 6.6 |
LCP-NaOCl
| 1756-DHRIO |
| C |
| 4.1 |
| 5.4 |
| LCP-SP |
| 192.168.2.128 |
| 1756-ENBT |
| A |
| 1.4 |
| 6.6 |
LCP-SP
| 1756-DHRIO |
| C |
| 4.1 |
| 5.4 |
| Belt Press Bldg. |
| 192.168.2.135 |
| 1766-L32AWA |
| B |
| 11 |
| 15.001 |
| Belt Press Bldg. |
| 192.168.2.136 |
| 1766-L32AWA |
| B |
| 10 |
| 15.001 |
| Belt Press Bldg. |
| 192.168.2.137 |
| 1766-L32AWA |
| B |
| 11 |
| 15.001 |
| Belt Press Bldg. |
| 192.168.2.138 |
| 1766-L32AWA |
| B |
| 11 |
| 15.001 |
| LCP-HWE |
| 192.168.2.150 |
| 1756-ENBT |
| A |
| 6.1 |
| 6.6 |
LCP-HWE
| 1756-DHRIO |
| E |
| 7.2 |
| 7.3 |
LCP-HWE
| 1756-L63 |
| B |
| 19.11 |
| 20.13 |
| LCP-Admin |
| 192.168.2.175 |
| PT-7324 |
1.3
| LCP-DAF |
| 192.168.2.176 |
| EDJ-508A |
| LCP-ASTN |
| 192.168.2.177 |
| EDJ-516A |
| LPC-SST |
| 192.168.2.178 |
| EDJ-516A |
| LCP-SSKPS1 |
| 192.168.2.179 |
| EDJ-508A |
| LCP-Admin |
| 192.168.2.180 |
| PT-7710 |
| LCP-ADMIN-PCC |
| 192.168.2.222 |
| 1756-ENBT |
| A |
| 1.4 |
| 6.6 |
| LCP-ADMIN-PCC |
| 192.168.2.223 |
| 1756-ENBT |
| A |
| 1.4 |
| 6.6 |
LCP-ADMIN-PCC
| 1756-L64 |
| B |
| 17.2 |
| 20.13 |
| LCP-DAF Drop 50 |
| 192.168.2.224 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-DAF Drop 51 |
| 192.168.2.225 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-ASTN Drop 20 |
| 192.168.2.226 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-ASTN Drop 21 |
| 192.168.2.227 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-ASTN Drop 22 |
| 192.168.2.228 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-ASTN Drop 23 |
| 192.168.2.229 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-ASTN Drop 24 |
| 192.168.2.230 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-SST1 Drop 30 |
| 192.168.2.231 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-SST1 Drop 31 |
| 192.168.2.232 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-SST1 Drop 32 |
| 192.168.2.233 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-SST1 Drop 33 |
| 192.168.2.234 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-SSKPS Drop 40 |
| 192.168.2.235 |
| 1794-AENT |
| B |
| 4.2 |
| 4.3 |
| LCP-BSC |
| 192.168.2.236 |
| 1756-ENBT |
| A |
| 4.8 |
| 6.6 |
LCP-BSC
| 1756-L61 |
| B |
| 17.3 |
| 20.13 |
| LCP-B1 |
| 192.168.2.237 |
| 1756-ENBT |
| A |
| 4.8 |
| 6.6 |
| LCP-B2 |
| 192.168.2.238 |
| 1756-ENBT |
| A |
| 4.8 |
| 6.6 |
| LCP-B3 |
| 192.168.2.239 |
| 1756-ENBT |
| A |
| 4.8 |
| 6.6 |
LCP-B3
| 1756-L61 |
| B |
| 17.3 |
| 20.13 |
| LCP-B4 |
| 192.168.2.240 |
| 1756-ENBT |
| A |
| 4.8 |
| 6.6 |
| LCP-ADMIN |
| 192.168.2.242 |
| 1766-L32AWA |
| B |
| 11 |
| 15.001 |
Before starting any firmware updates, the current program should be uploaded directly from the PLC to ensure that all programs are current and up to date. The firmware updates will require the system to either be stopped or put in to a manual operational mode. The firmware files are available via Rockwell Automation Web site:
http://www.rockwellautomation.com/rockwellautomation/support/firmware/overview.page?
The firmware should be updated using the Rockwell Automation Control Flash Program.
6.2 SCADA Software and Equipment Updates
The SCADA software FactoryTalk View SE should be upgraded from version 5.10 to the most current which is 8.0 as of the publish date of this document.
6.2.1 Servers
Two (2) New servers should be purchase to modernize the operation and provide redundancy. New servers should be setup with the following configuration:
· Server
· Hardware
· Quantity 1 – 12 Core CPU with Hyper Threading
· 64 Gb RAM
· Quantity 8 – 1 TB Hard Drive
· Quantity 4 RAID-1 VDisks
· Quantity 8 Network Interface Connections (NIC)
· Software
· VMWare vSphere Enterprise Edition
· Microsoft Server 2012 R2 Standard Edition
· Quantity of 5 Virtual Machines
· Microsoft Server 2012 R2 Remote Desktop Server
· Quantity of 15 Licenses
· Virtual Machines
· VM1
· 4 Cores
· 8 Gb RAM
· VDisk 1
· 3 NIC’s
· Windows Server 2012 R2
· FactoryTalk View SE Server
· VM2
· 4 Cores
· 8 Gb RAM
· VDisk 2
· 1 NIC
· Windows Server 2012 R2
· FactoryTalk Historian
· VM3
· 4 Cores
· 16 Gb RAM
· VDisk 3
· 1 NIC
· Windows Server 2012 R2
· Remote Desktop Server
· FactoryTalk View SE Client
· VM4
· 4 Cores
· 4 Gb RAM
· VDisk 4
· 1 NIC
· Windows Server 2012 R2
· FactoryTalk Directory Server
· Server 2- Same specification as the above. This server will provided failover and testing capabilities to the organization. The key VM on this host will be active Directory, back up engine, and monitoring software
· VM1
· 4 Cores
· 4 Gb RAM
· VDisk 4
· 1 NIC
· Windows Server 2012 R2
· Windows Active Director Services Figure 6-1 shows configuration of Servers.
Figure 6-1: Server Configuration
6.2.2 Clients
The current clients run Windows XP and should be upgraded to Windows 8.1, but with the new configuration the computers could be converted to thin clients and connect to the Remote Desktop Server to display the SCADA screens. If the clients were converted to thin clients the updates would only need to be managed on the server.
7. Network Upgrade
The network should be re-configured into separate zones. This would help in containing threats and issues into manageable zones. Figure 7-1 shows the modification of the Ethernet connectivity such that the system is broken up in zones.
Figure7-1: Zone Configuration The Moxa switches located in Levels 0-3 will be replaced by Rockwell Automation Stratix switches. This will allow the ControLogix controller to actively monitor the status of the switches. This information will then be sent to the SCADA system for viewing and alarming. This will allow automatic notification of issues with the network switches. There should be an Industrial Protocol Firewall installed directly to each PLC Ethernet connection. This will allow for better monitoring and defense against various threats.
8. Physical and Environmental Security
The physical environment should be upgraded to defend against unauthorized physical access, damage, theft, compromise, and interference to the SBIWTP SCADA processing facilities. SBIWTP should ensure that every employee and authorized user is assigned a Common Access Card (CAC) that must be presented to the proximity card reader in order to gain access to the facility. Human Resources should require each employee to sign a card access form prior to receiving the CAC; Human Resources should retain a copy of the signed form in the employee’s personnel files. All levels of access should be reviewed upon internal transfers and employment termination.
When a CAC is not available, all personnel must have their identity validated using a government ID. A temporary visitor badge would then be issued, It must be displayed at all times while in the facility. The visitor name badge must be turned-in to the security desk before leaving.
For physical and environmental security the SBIWTP must also ensure the following:
1. Access control should be governed via the CAC system; that only gives access to only authorized individuals.
2. Cable cabinets should be maintained in an orderly manner to permit proper airflow. Further, equipment temperatures should be maintained at acceptable levels to prevent hot spots.
3. Network cables should be secured in locked network rooms.
4. Power and Ethernet cables should be run through the floor in metal cube post conduits.
5. IBWC supplies its server room with an uninterruptible power supply (UPS). The UPS should provide approximately 20-30 minutes of battery life, t to facilitate an orderly shutdown..
6. The IBWC fire suppression and detection systems should be inspected frequently. The fire detection devices for within the data center should activate automatically to notify officials and emergency responders of a fire.
7. The temperature and humidity levels within the data center should be based on best practices and industry standards. It should monitor its temperature and humidity levels in real-time (24x7 basis) via a third party vendor at an off-site location.
9. Communications and Operations Management
Procedures will be established that define responsibilities for the communication and operation of all information processing facilities.. Segregation of duties will be implemented to reduce the risk of negligent or deliberate information system misuse. Precautions will be used to prevent and detect malicious code and unauthorized mobile code. Information system media will be controlled and physically protected to prevent unauthorized disclosure, modification, removal, or destruction of information assets. Procedures will be established for handling and storing information.
Information systems will be monitored and information security events will be recorded. SBIWTP will employ monitoring techniques to comply with applicable statewide policies related to acceptable use.
10. 24/7 Continuous Monitoring The organization should deploy a Continuous monitoring solution to enables the organization to see a continuous stream of near real-time snapshots of the state of risk to their security, data, SCADA devices, PLCs, the network, end points and devices and applications. Assessing security controls as well as ongoing monitoring of security controls.
The continuous monitoring should be implemented through a combination of services and SIEM for log and event collection and correlation to help organizations separate real events from nonimpact events, as well as locate and contain events.
11. Access Control
Access to information systems, processing facilities, will be controlled on the basis of business and security requirements. Formal procedures will be developed and implemented to control access rights to, information systems, and services to prevent unauthorized access.
In order to ensure that account management is properly implemented, SBIWTP should review system accounts in accordance with defined policy.
Within the Active Directory, it is highly recommended to configure the GPO settings to lock an account after an organization-defined period of inactivity. An access control schema should be established to clearly define user access roles. Account management auditing also strongly recommended to monitor user activity in the SCADA system.
Separation of duties should be implemented in order to provide a clear delineation of system access roles and responsibilities within the SBIWTP SCADA system. It is recommended that a role-based access control matrix is developed to display how access control is managed for the system.
Access control lists (ACLs), should be deployed within all firewalls. They should be routinely printed for review in accordance with SBIWTP policy
It is highly recommended that the Active Directory GPO setting for the SBIWTP SCADA system enforces a limit of three (3) consecutive invalid logon attempts by an individual user. Upon reaching the limit, the account should be locked for 15 minutes..
It is recommended to implement a login warning banner for the SBIWTP SCADA system in order to legally protect SBIWTP from unlawful intrusion into its network. Prior notice of real-time monitoring of the system environment and the explanation of criminal prosecution are means of legal protection in the event that the system is breached.
It is highly recommended that the Active Directory GPO setting for the SBIWTP SCADA system prevents further access to the SBIWTP SCADA system by initiating a session lock after thirty minutes of inactivity. The session lock should be maintained until authentication is reestablished.
It is imperative that the SBIWTP implement a mechanism that requires user ID and password combination in order to access any information system. If there is personably identifiable information (PII) in the system, the access control must be implemented as soon as possible.
It is recommended that the SBIWTP implements and enforces a remote access The SBIWTP must ensure that the remote access is controlled through a VPN via a secure shell (SSH) and Secure Hypertext Transfer Protocol (HTTP) for the SBIWTP SCADA system. The current Cisco VPN router requests a username and password to access the network, but a formal policy must be finalized and approved by management, Auditing of the VPN connection must be established to monitor all of the access control points. A remote access management console can assist in reviewing client activity and user interface for the SBIWTP SCADA system.
It is recommended that SBIWTP implements and enforces a wireless access policy that permits and restricts wireless access to the network.
It is recommended that SBIWTP implements and enforces a mobile device policy that permits and restricts mobile device access to the network.
11. Information Systems Acquisition, Development and Maintenance
Policies and procedures will be employed to ensure the secure maintenance of information systems. Encryption will be used to protect sensitive information at rest and during transmission.. Access to system files and program source code will be restricted. Further, IT support activities will be conducted in a secure manner.
12. Information Security Incident Management
Information security incidents will be managed securely allowing timely corrective action to be taken. Formal incident reporting and escalation procedures will be established and communicated to all users. An incident management procedure will be developed to support incidents throughout the incident response lifecycle.
SBIWTP should consider employing an automated incident response tool to assist with monitoring security incidents. The tool should automatically notify the appropriate officials of any deficiencies or vulnerabilities associated with reported security incidents.
Incident response exercises and tests should be conducted annually to help ensure that the incident response capability is adequate.. Any lessons learned should be documented and reviewed annually by the ISSO and senior management. Any adjustments to the incident response procedures should be incorporated into annual reviews and updates.
SBIWTP should employ an incident coordinator to offers advise and assist the users of the SCADA system with handling and reporting security incidents.
13. Contingency Planning and Business Continuity Management
The objective of business continuity management is to recover from interruptions of critical business processes and the effects of major failures of information systems. A business continuity management plan and a contingency plan will be established to minimize the impact on SBIWTP and recover from the loss of information assets. The plan will use a combination of preventive and recovery controls. A managed process will be developed and maintained for business continuity throughout the agency that addresses the information security requirements..
. The plans should be reviewed annually at a minimum. The plan reviews should focus on the following elements:
· Operational requirements
· Security requirements
· Technical procedures
· Hardware, software, and other equipment (types, specifications, and amount)
· Names and contact information of team members
· Names and contact information of vendors, including alternate and off-site vendor points-of-contact
· Alternate and offsite facility requirements
· Vital records (electronic and hardcopy)
The organization should establish restoration priorities based on identified recovery objectives and metrics. These will be defined in in a business impact analysis. The recovery priorities allow SBIWTP to maintain essential business functions during an information system disruption, compromise, or failure.
The contingency plan should include a testing element to ensure that all employees within SBIWTP are trained for their roles and responsibilities. The following areas should be addressed in contingency testing:
· System recovery on an alternate platform from backup media
· Coordination among recovery teams
· Internal and external connectivity
· System performance using alternate equipment
· Restoration to normal operations
· Notification procedures
It is recommended that all SBIWTP employees are trained with respect to their specific contingency roles and responsibilities. Training Should be conducted annually. A New hire who will have contingency plan responsibilities should receive training within two weeks of his or her start date. Recovery personnel should be trained on the following elements:
· Purpose of the plan
· Cross-team coordination and communication
· Reporting procedures
· Security requirements
· Team-specific processes (Notification, Activation, Recovery, and Reconstitution Phases)
· Individual responsibilities (Notification, Activation, Recovery, and Reconstitution Phases)
The contingency test plan should include a schedule detailing the timeframes for each test and its test participants. The test plan should also define a clear scope, scenario, and logistics. SBIWTP should ensure that an exercise never disrupts normal operations. Test results and lessons learned are documented and reviewed by test participants and other personnel as appropriate. Information collected during the test and post-test should be incorporated into future iterations of the contingency plan. Testing should be performed, on an annual basis.
IBWC should research the possibility of obtaining a third party vendor to provide the services of secured offsite storage and recovery..
IBWC should research the possibility of obtaining a third party vendor to for alternate telecommunications services. Service and disaster recovery contracts should provide information on network interconnectivity between the primary and alternate sites. Other mitigation service options that can detect denial of service and network traffic anomalies should also be considered.
It is highly recommended that IBWC creates both an automated and manual backup procedures in the event of a disaster or a disruption. Tape information should always be encrypted. IBWC should also implement effective procedures to perform full data backups on a regular basis. A copy of the daily backups should be securely transported on a daily basis and stored off site in an environmentally controlled storage facility which resides outside the immediate regional area.
SBIWTP should perform disaster recovery plan testing to identify gaps and omissions. System recovery on an alternate platform from backup media should also be performed during testing to ensure reliability and integrity of information.
SBIWTP should identify the circumstances that can inhibit a recovery and reconstitution to a known state during disaster recovery and contingency plan testing.
14. Compliance
The design, operation, use, and management of information and information assets are subject to regulatory security requirements. Compliance with legal requirements is necessary to avoid conflicts with any law. Legal requirements include, but are not limited to: state statute, statewide and agency policy, regulations, contractual agreements, intellectual property rights, copyrights, and protection and privacy of personal information.
15. Risk Management
Risk Management involves a process of identifying risk, assessing risk, and taking steps to reduce risk to an acceptable level. Risk management is critical for the SBIWTP to maintain a secure environment. Risk assessments will identify, quantify, and prioritize risks against agency criteria for risk acceptance and objectives. The results will determine the appropriate actions and priorities for managing risks and for implementing the appropriate security controls.
Risk management will include the following steps as part of a risk assessment:
1. Identify the risks
a. Identify agency assets and the associated information systems.
b. Identify threats to organizational assets
c. Identify the vulnerabilities
d. Identify sources that may compromise confidentiality, integrity and availability of the assets.
2. Analyze and evaluate the risks
a. Assess the impact on the agency
b. Assess the likelihood of risks compromise the system.
c. Assign a level to the risks
d. Determine whether the risks are acceptable
3. Identify and evaluate options for the mitigation of risk
a. Apply appropriate controls
b. Accept the risks
c. Avoid the risks
d. Transfer the risks t Select appropriate security controls to mitigate the risks.
16. Awareness and Training
A security awareness and training program should be implemented to train all employees on their roles and responsibilities when using SBIWTP information systems..
IBWC should ensure that its security awareness training provides clear direction to all employees and contractors regarding the safety and security of their user credentials. The awareness training should explain best practices to secure user IDs and describes all password regulation requirements.
In addition, a Rules of Behavior document should provide clear descriptions of appropriate behavior and expectations. Employees and contractors should be required to read and acknowledge the Rules of Behavior annually. Security awareness training should be provided to all employees and contractors annually.
All users who would have access to the SBIWTP SCADA system should receive security awareness training prior to gaining access. I Information system security training should be incorporated into its orientation processes. All users should complete annual security awareness refresher training. Records of annual security refresher training should be maintained by Human Resources.
IBWC should provide role based security-related training before authorizing access to its systems.
Human Resources Security
All employees, volunteers, contractors, and third party users of SBIWTP information assets are responsible for understanding their responsibilities and all associated AUPs. . All candidates for employment, volunteer work, contractors, and third party users will be adequately screened, Prior to being hired
All employees, volunteers, contractors and third party users will receive security awareness training. They will also receive regular updates on policies and procedures as appropriate to their job functions.
Procedures will be implemented to ensure an employee’s, volunteers, contractors or third parties separating from SBIWTP will return of all equipment. The separated employee’s access rights should also be promptly removed.
| IBWC San Diego SCADA Upgrade Strategy – Confidential – AITHERAS, LLC | 68 |
| Security Control | |
| Control Name | |
| Control Text | |
| Recommendation |
Management Controls
Certification, Accreditation, and Security Assessments
| CA-01 |
| Certification, Accreditation, and Security Assessment Policies and Procedures |
| The organization develops, disseminates, and periodically reviews/updates formal, documented, security assessment and certification and accreditation policies that address purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the security assessment and certification and accreditation policies and associated assessment, certification, and accreditation controls. |
| It is highly recommended that IBWC document and implement an overarching security program that develops, disseminates, and periodically reviews and updates: a formal, documented, security authorization policy that addresses purpose, scope, roles, responsibilities, and compliance; and formal, documented procedures to facilitate the implementation of the security authorization policy and its associated controls. |
| CA-02 |
| Security Assessments |
| The organization conducts an assessment of the security controls in the information system [Assignment: organization-defined frequency, at least annually] to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. |
| IBWC should conduct a security assessment on the SBIWTP SCADA System on an annual basis or whenever a significant change occurs within its environment. As with most government entities, the organization should move towards an ongoing security authorization focus as mandated by NIST SP 800-53, Rev. 4 and should infuse the effort within its current continuous monitoring practices. |
| CA-03 |
| Information System Connections |
| The organization authorizes all connections from the information system to other information systems outside of the accreditation boundary and monitors/controls the system interconnections on an ongoing basis. Appropriate organizational officials approve information system interconnection agreements. |
| If the SBIWTP SCADA System has interconnections with other systems internal and external to IBWC, then the interconnection agreements and/or memorandums of agreement should be documented and signed by all parties where information is being transmitted, processed, or stored. |
Typically, the signed agreements with external systems will ensure that the external information system connections are authorized, monitored, and controlled. These documents set out the terms of the interconnection, agree to defined configurations, and establish dates as to when the connections and the security safeguards shall remain in place.
| CA-03(5) |
| System |
Interconnections Restrictions on External System Connections
| The organization employs deny-all, allow by exception policy for allowing external connections to connect to the information systems. |
| If the SBIWTP SCADA System has interconnections with other systems internal and external to IBWC, then the interconnection agreements and/or memorandums of agreement should be documented and signed by all parties where information is being transmitted, processed, or stored. |
Typically, the signed agreements with external systems will ensure that the external information system connections are authorized, monitored, and controlled. These documents set out the terms of the interconnection, agree to defined configurations, and establish dates as to when the connections and the security safeguards shall remain in place.
| CA-05 |
| Plan of Action and Milestones |
| The organization develops a plan of action and |
milestones for the System to document the organization’s planned remedial actions to correct weaknesses or deficiencies noted during the assessment of the security controls and to reduce or eliminate known vulnerabilities in the system and updates existing PoAM’s monthly based on the findings from security controls assessments, vulnerability assessments, security impact analyses and continuous monitoring activities.
It is strongly recommended that IBWC create a standard operating procedure document for plans of action and milestones in order to fully define the corrective action plan and measurable milestones that require remedial actions for all systems and applications within the organization -- including the SBIWTP SCADA System.
| CA-07 |
| Continuous Monitoring |
| The organization develops a continuous |
monitoring strategy and implements a continuous monitoring program that includes i) Establishment of system components to be monitored ii) Establishment of frequency of such monitoring iii) Ongoing security control assessments in accordance with the CM strategy, iv) Ongoing security status monitoring or organization-defined metrics in accordance with the CM strategy v) Response action to address results of the analysis and vi) Reporting the security status of organization and the information system to CIO monthly.
Oversight and monitoring of the security controls for the SBIWTP SCADA System should be conducted on an ongoing basis, and the ISSO should inform the Authorizing Official on an annual basis or whenever changes that may impact its security posture occur.
IBWC should ensure that alterations and deficiencies in the operation of its security controls are tracked by procuring a tool to document, analyze, and report configuration changes or evolving threats to its network.
| CA-07(1) |
| Continuous |
Monitoring Independent Assessment The organization employs third party assessors or assessment teams to monitor the security controls in the information system on an ongoing basis.
It is recommended that IBWC seek out a third-party assessment team to perform its ATO security control testing and management in order to avoid conflict of interest in properly reporting the security posture for the SBIWTP SCADA System.
| CA-08 |
| Penetration |
Testing The organization conducts penetration testing every three (3) years on the information System by a third party or independent penetration agent to perform penetration testing on the information system or system components.
It is recommended that IBWC procure a third-party vendor to perform an external penetration test on the SBIWTP SCADA system in order to properly test that the control mechanisms currently in place are effective in thwarting outside attacks from hackers and intruders into the system environment.
| CA-09 |
| Internal System |
Connections The organization Authorizes internal connections for a class of components with common characteristics and or configurations for example, VPN connections or mobile devices.
If the SBIWTP SCADA System has interconnections with other systems internal to IBWC, then the interconnection agreements and/or memorandums of agreement should be documented and signed by all parties where information is being transmitted, processed, or stored.
Planning
| PL-01 |
| Security Planning Policy and Procedures |
| The organization develops, disseminates, and periodically reviews/updates: (i) a formal, documented, security planning policy that addresses purpose, scope, roles, responsibilities, and compliance; and (ii) formal, documented procedures to facilitate the implementation of the security planning policy and associated security planning controls. |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .