Skip to main content
Guidance

Operational Technology

Making sense of cyber security in OT environments.

Pages

Page 7 of 37

Principle 4: Identify and document connectivity within your OT system

Most modern OT systems no longer operate in air-gapped environments by default. Instead, they require external connectivity to support business functions, streamline maintenance activities, and enable enhanced security controls. It’s the connectivity and interactions between assets within a system that allow it to work to perform the intended function. Understanding how these assets work together within the wider system is essential for building effective and proportionate security controls.

When designing connectivity, reducing your organisation's vulnerability to potential attacks is paramount. For instance, the use of wireless communication technologies can elevate risks, as threat actors may not need to be physically present to exploit the system.

An effective understanding of the communications each of your assets require is critical to being able to design and articulate your networks zones and conduits as described in IEC 62443-3-2. Having this documented will enable your organisation to implement effective network controls such as network segmentation. 

At a minimum, you should be able to answer the following 5 questions for each asset in your architecture:

  1. What does the asset need to communicate with to perform its function?
  2. What communication protocols are required, and how are they secured?
  3. What architectural security controls are currently implemented in the OT system?
  4. What are the network constraints in your OT environment?
  5. Would a compromise allow an attacker to bypass existing controls?

Summary

You should have a maintained record of all necessary connections each asset has with other systems, devices, or services. This record should justify the need for each connection and document wider system or third party dependencies. Techniques such as DFDs are used to capture this information.


Summary

For each asset you should have documented in use protocols, along with their corresponding TCP/UDP ports. This documentation should be used for configuring ingress and egress filters on firewalls. Additionally, a thorough audit of these protocols should have been conducted to ensure compliance with security standards, incorporating necessary encryption and integrity mechanisms.


Summary

You should understand your existing architectural security controls and what protections they provide to the asset and the wider system. Network security controls should be designed to limit the ability for a  compromised system impacting your wider OT network. The potential resulting impact from a compromise within the context of applied controls should be well understood and documented for effective risk management.


Summary

The technical factors that may limit the implementation of cyber security controls in OT networks should be thoroughly documented. By identifying these constraints, organisations can make informed, risk-based decisions regarding future security enhancements. Effectively managing these limitations is essential to mitigate additional risks being exposed. 


Summary

Your organisation should have a comprehensive understanding of the potential impacts of compromised external connectivity into the OT network. Where security compromises have been made, mitigating controls should be in place to limit the potential impact.

Published

Reviewed

Version

1.0