Operational Technology
Pages
Page 8 of 37
Principle 5: Understand and document third-party risks to your OT system
Many OT systems are managed or maintained by third parties, such as manufacturers, integrators, or managed service providers (MSPs). When these groups have access to your environment, they add risks that require additional consideration, as you don’t have direct control over the security of the delivered system.
The NCSC has produced supply chain security guidance on how to effectively manage these risks. IEC 62443-4-1 (secure product development lifecycle requirements) and IEC 62443-2-4 (security program requirements for IACS service providers) provides some additional advice specific to industrial automation and control systems.
At a minimum, you should be able to answer the following 3 questions for third parties connecting to the network:
1. What entities are involved in the external connection?
For each external connection, your organisation should have a detailed understanding of the entities the route is designed for. These are likely to fall into 3 trust levels:
Equal trust
Information sharing routes with other critical national infrastructure (CNI) organisations that operate within the same threat model, and where you have assurance over the technical controls they have implemented.
Partial trust
Connectivity to enterprise networks, where communications are within your organisation are able to assure the technical controls in place.
Low trust
Connectivity to external networks from third-party organisations such as vendors, integrators or managed service providers. This is where you have limited controls over the technical controls implemented.
The trust level of the network will dictate the kind of controls required to both protect your OT data and systems.
When evaluating the entities involved you should ensure they are following the 'browse-down' model, where high-trust systems administer systems of lower trust. No low-trust system should be able to administer systems of a higher trust. Where this appears to be required (such as a third-party providing administration) you need to have documented processes for establishing trust in their systems through validating their security controls are in line with your organisations standards.
Summary
Your organisation should have a detailed understanding of each external connection and its corresponding trust level, ensuring that these levels dictate the necessary security controls for protecting OT data and systems. You must verify compliance with the "Browse-Down" model, where high trust systems manage lower trust systems, and have processes in place to validate the security controls of third-party administration systems against your organisational standards.
2. What are the contractual requirements imposed by the third party?
It is common for third parties to add connectivity requirements to their contracts. This can allow a third party to set the expectations for how they expect to be able to access your environment. This can limit your ability to implement technical controls.
For example, a third party may require 24/7 remote access that would prevent your deployment of a ‘just-in-time’ administration model. Where possible, requirements that limit your ability to deploy technical controls should be removed. You should work with the third party to understand why they require levels of access, and where existing remote access process may be suitable. This will aid in preventing duplicate remote access methods being developed.
Where requirements cannot be removed, compensating controls should be in place to audit and monitor third party actions. You should ensure all other assets in your system are protected from this third-party access, through network segmentation and access controls. A third-party should only be able to access specified assets, and not any other elements of your system.
Regulated CNI sectors may have additional requirements where you may be mandated to supply data to specified third parties. This requirement imposed on the availability of this external connectivity will need to be factored into your isolation plans. Where the connectivity is always persistent the use of technologies that provide a continuous level of separation should be considered. This could include physical data diodes or the use of cross domain solutions (CDS).
Summary
Your organisation should have a documented and detailed understanding of how contractual or regulatory requirements from third parties impact your ability to apply security controls. This documentation should include any compensating controls in place that enable you to manage this risk.
3. Are the third party installing any out of band access?
If a third party is installing equipment within your environment you should ensure you understand the functionality and features of the assets being deployed. This should focus on out of band communication channels, both for asset-to-asset communications, as well as external communications. If deployed systems have connectivity into your wider network and you are unaware of installed out-of- band channels, you could be carrying substantial unmanaged risk.
Out of band communication channels include but are not limited to:
- 4G modems within devices, facilitating the third party unconstrained remote access to the system and potentially your wider environment. The third party should be encouraged to use an existing remote access mechanism to remove the risk of shadow IT in your environment.
- Other wireless technologies such as Bluetooth or Wi-Fi for configuration. In this case, you should understand if this functionality will remain enabled once the asset is deployed and how the connectivity will be hardened.
- Use of removable media to deploy configurations to devices. The product may support zero touch provisioning via removable media. In this case, you should understand what sensitive data is included within this configuration, how the organisation is protecting this data and how removable media risks are being managed on site.
Note: The use of removable media should be restricted to approved items, as removable media introduces an additional attack vector through which a threat actor can enter the environment. For example, a threat actor could use malicious USB device to emulates a trusted Human Interface Device (HID), such as a keyboard, to perform keystroke injection attacks. Once connected, the device can rapidly deliver pre-programmed keystrokes to execute commands, install malware, or alter system configurations. The UK's Industrial Control Systems Community of Interest has published guidance on the management of removable media within OT environments. |
Summary
Your organisation should have an established process to assess any new assets being installed by third-parties and to document any risks these assets may present to the wider system. Out of band management should be removed where feasible to remove these risks. Where this is not possible, you should have a clear documented understanding of the technical controls put in place by the third party to harden the access.


