IT Security for Industrial Control Systems Joe Falco, Keith Stouffer, Albert Wavering, Frederick Proctor Intelligent Systems Division National Institute of Standards and Technology (NIST) Gaithersburg, MD Email: (
[email protected],
[email protected],
[email protected],
[email protected]) In coordination with the Process Control Security Requirements Forum (PCSRF) (http://www.isd.mel.nist.gov/projects/processcontrol/) Abstract The National Institute of Standards and Technology (NIST) is working to improve the information technology (IT) security of networked digital control systems used in industrial applications. This effort is being carried out through the Process Control Security Requirements Forum (PCSRF), an industry group organized under the National Information Assurance Program (NIAP). The PCSRF is working with security professionals to assess the vulnerabilities and establish appropriate strategies for the development of policies to reduce IT security risk within the U.S. process controls industry. The outcome of this work will be the development and dissemination of best practices and ultimately Common Criteria, ISO/IEC 15408 based security specifications that will be used in the procurement, development, and retrofit of industrial control systems. In support of this work this paper addresses the computer control systems used within process control industries, their similarities, and network architectures. A generic set of networking system architectures for industrial process control systems is presented. The vulnerabilities associated with these systems and the IT threats these systems are exposed to are also presented along with a discussion of the Common Criteria and its intended use for these efforts. The current status as well as future efforts of the PCSRF are also discussed.