Operational Technology
Pages
Page 17 of 37
Principle 7: Ensure all connectivity is logged and monitored
Even with all possible precautions in place, there remains a risk that your system could be compromised. Monitoring is your last line of defence when designing secure connectivity.
It is critical that your organisation makes compromise detection easier by implementing comprehensive logging and monitoring throughout your OT environment. These logs will help your organisation establish a baseline of ‘normal’ activity, allowing operators or detection systems to identify abnormalities faster.
The end-goal of logging should not just be to collect logs. Instead, you should understand how attackers may seek to exploit your systems though identifying weak points . Then design monitoring and alerting to help identify potential attacks. This can help guide what logging or packet captures you need to support these monitoring and alerting rules. Within OT environments, specific considerations should be made regarding how logging addresses:
Unauthorised activity
Changes to OT environments are managed through strict controls, including detailed planning, change logs, and advance notifications. During maintenance, monitoring rules may be temporarily disabled to reduce false positives. Keeping your SOC informed ensures alerts for maintenance data flows are re-enabled outside planned windows. Work management tools can support this visibility. However, business processes should verify maintenance actions are legitimate to prevent attackers from exploiting this system to hide malicious activities.
Anomaly detection
This refers to the process of identifying patterns or activities that deviate significantly from normal or expected behaviour within a system or network. This approach can be especially advantageous in OT systems, where there are relatively static, repetitive processes characterised by consistent command structures. However, it is critical that anomaly detection does not replace the implementation of technical controls designed to disable or block unused command sets, services, or ports.
Break-glass
Break-glass access, where typical security controls are bypassed for safety incidents, is intended solely for emergency situations and should not be used as a standard remote access method. It is critical that any attempt to use a break-glass account triggers the highest criticality alarm within your Security Operations Centre (SOC).
Data flow monitoring
Continuous monitoring of data flows within and between network segments is crucial to enable you to validate segmentation policies, and identify early signs of compromise or misconfiguration in your controls.
Further reading This is an area that there is already extensive guidance on logging produced by the NCSC and the wider topic of building a security operations centre (SOC) For monitoring of external facing systems, our External Attack Surface Management (EASM) buyers guide outlines the features you should look for in these tools. Manufacturers have a role to play in ensuring that standard logging and forensic features are robust and ‘secure by default’, so that network defenders can more easily detect malicious activity and investigate following an intrusion. The NCSC has produced guidance on digital forensics and protective monitoring specifications for producers of network devices and appliances to aid in assessing these characteristics. |


