Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 6 of 37

Principle 3: Identify and categorise assets to support informed risk-based decisions

Your organisation should understand the role of each of the components within your OT system. This is critical to enable you to create appropriate and proportionate security controls within your environment. 

Tip: While this guidance focuses on the broader process required to define your system architecture, there is additional international guidance on delivering an asset discovery programme which can be referred to including:

For each asset you should be able to define three factors; criticality, exposure and availability.

Criticality

Criticality describes how important the functioning of the asset is to the wider OT system, in terms of its impact on:

  • Business Would a failure cause the process to stop or result in a lower yield ?
  • Safety Would a failure cause harm or damage to people, equipment, and/or the environment ?
  • Security Would a failure result in the system being exposed to an unacceptable level of risk ? 

To gain a complete understanding of an asset's criticality, it should be examined in the context of the wider system. This will require combining the criticality of the asset with information about your wider system connectivity. 

Exposure

Exposure refers to the discoverability and accessibility of networked devices within an organisation, which could make them vulnerable to potential threats. This should account for what defence in depth controls might add to its security. Exposure should consider several factors including:

  • the time of exposure (for example is it accessible 24/7 or only accessible when required?)
  • the type of connectivity being used (for example direct connections to the public internet are inherently more exposed than private fibre links)
  • communications flow (for example does the system accept inbound connections?) 
  • proximity to external networks such as the internet or remote access points
  • physical accessibility (are there opportunities for unauthorised physical interaction, such as plugging in devices or physical presence near the system) 

Availability

Availability refers to the timely, reliable access to data and information services for authorised users. OT availability should include what business or operational functions would be lost in the event of that single asset being unavailable. 

Where systems are highly critical, they are likely to be deployed for high-availability with redundancy built in and automated failover systems. This wider system availability may lower the availability requirements of some individual assets, making them easier to update and maintain. 

Information to record on availability could include but is not limited to:

  • timescales for known downtime, such as repeat scheduled maintenance windows
  • high-availability deployments, including its architecture and the identification of the paired high-availability device or service and/or automated failover systems 
  • ability for the system asset to support rolling deployments, where updates can be provisioned with zero downtime

Tip: Vendors should provide categorisations of their updates so users can understand how the update will impact the asset's functionality. This should also include clear guidance on how quickly the update should be applied, in line with NCSCs Vulnerability management guidance best practice timelines.

Key categorisations may include ‘update’ (where a bug or unintended behaviour is being removed), ‘security’ (where a vulnerability is being remediated) or ‘feature updates’ (where new functionality is being added). The vendor should also highlight if the vulnerability is being actively exploited, and ensure it is added to the CISA Known Exploited Vulnerability List.

For ‘security’ updates, vendors should publish a security advisory that is automatically retrievable according to the Common Security Advisory Framework (CSAF) and includes links to one or more complete and accurate CVE records. The NCSCs Vulnerability management guidance should be referred to for further advice.

Criticality, exposure and availability factors should be recorded as part of the definitive record to enable your organisation to take effective risk based decisions when considering new or revised security controls. For example, consider three common assets in an OT environment: a safety controller, a firewall and a regional supervisory control and data acquisition (SCADA) platform.

  1. The safety controller is crucial for system safety, so it is typically designed to have minimal network connectivity with other assets. It also needs to be highly-available to ensure the process is protected during operations. 
  2. In contrast, a firewall for external connectivity is located at the edge of the network and provides important functions like secure remote access. While this is useful, it is less critical to day-to-day operations; however, it is also more exposed to potential threats. Where this external data flow is essential to the process, this will likely be deployed as a high-availability pair. 
  3. A regional SCADA platform deployed on a virtualisation platform needs connectivity to all your OT systems and is likely critical to the business. It is also likely more exposed to external services than most of your OT assets, potentially exporting data to business systems. Where this is critical, it is also likely to be deployed as a high-availability pair. 

When looking at updating in this scenario, you might choose to prioritise updates or maintenance of the firewall due to its exposure to threats, despite the fact it is less critical to the OT system. The fact that it is in a high-availability pair may allow you to update one asset at a time to prevent any impacts on operations. For similar reasons you may be able to routinely maintain your SCADA platform where you can fail over to the warm standby system during the maintenance process. 

Your organisation should use a comprehensive risk management framework to inform these decisions, such as the NCSC's risk management framework (which aligns with international standards such as ISO 27001 and includes vital techniques such as threat modelling and attack trees ). Note that IEC 62443-3-2 provides some additional advice specific to industrial automation and control systems.  

Summary

You should have each asset systematically assessed and categorised by its criticality (business, safety, security), exposure within the OT system architecture and any availability constraints. The documented factors, recorded in a definitive record should be used to support risk-based decision-making. Enabling informed decisions regarding security controls, maintenance and updating.

Published

Reviewed

Version

1.0