Dams Sector Roadmap to Secure Control Systems - Association of ...
Goal 5 - Secure-By-Design .......................................................................... 26
Challenges ................................................................................... 26
Milestones ................................................................................... 26
4. Roadmap Implementation ......................................................................... 29
Implementation Challenges. ......................................................................... 29
Outreach,Training, and Education Needs .......................................................... 30
Information Sharing ........................................................................... 30
Implementation Framework ......................................................................... 30
Socialization ................................................................................. 30
Implementation Activities ....................................................................... 30
Outputs And Impacts ........................................................................... 32
An Ongoing Process ........................................................................... 32
Roles And Responsibilities. .......................................................................... 32
Guiding And Aligning Existing Efforts ................................................................. 33
5. References ....................................................................................... 35
6. Acronyms ....................................................................................... 37
Appendix A: Glossary/Definition of Terms. .............................................................. 39
Appendix B: National Policy Guidance on Cyber Control System Security ................................... 41
Appendix C: Industrial Control System Details ........................................................... 43
Importance of Industrial Control Systems in the Dams Sector .............................................. 43
Industrial Control Systems ...................................................................... 43
Securing Industrial Control Systems in the Dams Sector. .................................................. 49
Identification of Critical Functions & Operations Dependent on Industrial Control Systems ................. 49
Identification and Screening of Critical Cyber Elements ............................................... 49
Identification of Common Cyber Access Points ...................................................... 49
Interconnections .............................................................................. 50
Identification of Access Points ................................................................... 50
Assessing Risks of Critical Cyber Elements. ............................................................. 51
Threat Considerations .......................................................................... 51
Consequence Assessment. ....................................................................... 52
Vulnerability Analysis. .......................................................................... 53
Approaches for Prioritizing Critical Cyber Elements. ................................................. 53
Summary of Sector Challenges and Development ....................................................... 53
Cost/Benefit Analysis .......................................................................... 53
Consequence Mitigation Approaches .............................................................. 53
Research & Development Needs and Considerations ................................................. 54
viii
Dams Sector Roadmap to Secure Control Systems