Operational Technology
Pages
Page 36 of 37
Principle 8. Log and audit within the RF network
Logging and auditing of events and errors can help to identify suspicious activity. This enables early warning of potential compromise and the basis for subsequent analysis should a security event occur.
Whilst effective logging will not in itself provide greater security to the network, it allows for other security mechanisms to be put into action should malicious activity be discovered (as part of an incident response process).
Logging across the network should be centralised and presented in such a way to allow for easy analysis by security personnel. This may include the use of appropriate data storage and dashboard technology. If logs are to be used in a security context it is important that they are transmitted and stored in a secure way to ensure the integrity of the logging information. Logs must be attributable to known RF assets to support effective investigation and incident response.
Replay attacks often cause radio packet errors through collision, especially when radio channel occupancy is kept high. If frame collision is monitored, then this can serve as early warning to a potential network attack.
Logging and auditing can also support the effective operation of a network in addition to security, ensuring that radio links are healthy and being efficiently utilised.
Design patterns and methods for logging and centralised storage/retrieval can be found across the enterprise IT environment and should be looked to as an example for solutions to implement.
As part of developing monitoring rules or use-cases, threat modelling should be used to inform logging and audit requirements, to ensure that events which could indicate risk propagation to downstream systems and assets are captured and prioritised.
Refer to Logging and monitoring and Building a Security Operations Centre (SOC) for further guidance.